A new framework for third-party risk in the European Union
Report: DORA and cyber risk
At the start of 2023, the Digital Operational Resilience Act (DORA) came into force in the EU to protect customers and EU financial institutions from systemic cybersecurity risks affecting information and communication technology (ICT).
DORA was introduced as a method of building risk resilience within financial organizations, ensuring that they establish and monitor trust networks among their ICT and their vendors.
This paper from SecurityScorecard highlights the security risks - including third-party - impacting financial entities in the EU today and introduces a verification framework for DORA, covering all major aspects of it to support institutions in their preparation.
You will learn:
- How zero trust can provide the framework to mitigate third-party risk
- The seven steps financial institutions need to follow to prepare for DORA
- How SecurityScorecard can empower your business to stay ahead of potential threats and vulnerabilities.
Download today.
Provided by SecurityScorecard
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
ITPro is a global business technology website providing the latest news, analysis, and business insight for IT decision-makers. Whether it's cyber security, cloud computing, IT infrastructure, or business strategy, we aim to equip leaders with the data they need to make informed IT investments.
For regular updates delivered to your inbox and social feeds, be sure to sign up to our daily newsletter and follow on us LinkedIn and Twitter.
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'News The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
SPECIAL EDITION: What would a Mythos-resilient SOC look like?Sponsored podcast Claude Mythos was judged so effective at detecting vulnerabilities it could be dangerous
-
Hackers are turning up at law firms to gain physical access to machinesNews The FBI is warning companies to look out for fake IT staff
-
UK wants an AI-powered anti-hacking systemNews GCHQ is building a national cyber defence capability powered by AI – though it may take five years
-
GitHub internal repositories exfiltrated via malicious VS Code extensionNews The breach has been claimed by the TeamPCP hacking group, which said it is offering the data for sale
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online