EU’s new DORA law means your board is now responsible for digital resilience

News

3 minutes

EU’s new DORA law means your board is now responsible for digital resilience

First published in The Sunday Independent 12.05.2024: EU’s new Dora regulations means your board is now responsible for digital resilience | Irish Independent

The digital transformation of the economy has brought opportunities and challenges for businesses across all sectors. From cloud computing to artificial intelligence, fintech to e-commerce, the digital landscape is constantly evolving and creating new possibilities for innovation and growth. This also means businesses need to be more resilient and prepared for the potential risks and threats that are inherent in digital platforms. Cyberattacks, data breaches, system failures, and service disruptions are just some examples of the digital operational risks that can affect business performance, function, reputation, and customer trust. That’s why the EU introduced the Digital Operational Resilience Act (Dora), a new regulation to strengthen the defences of the financial sector. Although Dora came into force in January 2022, businesses have until January 2025 to achieve compliance, with obligations being imposed on most financial entities operating within the EU, along with significant obligations being put on their third-party service providers – regardless of their location. Between now and then, it’s incumbent on boardrooms to make sure their businesses are compliant with Dora, or they risk significant penalties. Dora establishes a common set of rules and standards for managing, testing, reporting, and mitigating digital operational risk, as well as for monitoring the use of third-party service providers – essentially any important IT service that are outsourced. For businesses, this means a regulatory framework will be in place that embodies best practices for digital operations in how to use third-party service providers safely and effectively. Dora requires complete buy-in from all parts of a business or financial institution – and one challenge IT departments have traditionally faced is getting ‘real’ management buy-in. But Dora emphasises the importance of board-level engagement and the mandatory requirement that the board ‘own’ the responsibility of ensuring the business is resilient – or else risk huge fines for non-compliance.

Companies found to be in violation can face fines of up to 2pc of total annual worldwide turnover – or, in the case of an individual, a maximum fine of €1m. Financial entities that fail to report major Information and communications technology-related (ICT) incidents or significant cyber threats, as required under Dora, may also face fines. Third-party ICT service providers designated as “critical” by the European Supervisory Authorities (ESAs) may face fines of up to €5m or, in the case of an individual, a maximum of €500,000 for non-compliance. In July, the ESAs will set out its second lot of technical standards with which businesses and financial institutions need to be compliant by January 2025. Dora requires financial entities establish a sound digital operational resilience framework, with policies, procedures, tools, and governance arrangements for identifying, assessing, managing, monitoring, and reporting digital operational risk. This helps them have a clear overview of their digital risk profile and to implement measures to prevent, detect, and respond to digital incidents. It introduces a harmonised reporting mechanism for digital incidents, enabling communication between financial entities, authorities, and customers, enhancing transparency and accountability for financial institutions to minimise the impact and escalation of digital incidents.

One of the key aspects of Dora is that it requires the board of directors of financial entities to ‘own’ the responsibility of ensuring their business is Dora compliant and that they have a sound and effective framework in place. This means the board must be actively involved in the design, implementation, and oversight of the framework. The directors must have adequate knowledge, skills, and resources to fulfil their responsibilities, and must receive regular reports on the digital resilience of the organisation and its third-party service providers. Board-level engagement is crucial for ensuring compliance with Dora, as it demonstrates the leadership and commitment of the organisation to digital operational resilience and to the protection of its customers. It also ensures the organisation has a clear and consistent vision and direction for its digital operations and that it can effectively manage and mitigate digital risks and challenges. Board-level engagement fosters a culture of digital operational resilience within the organisation and promotes the awareness and involvement of all staff and stakeholders. While the frameworks, processes, testing and all of the digital resilience obligations under Dora make good business sense, the act makes this a legal obligation – and holds your board of management responsible.

Related Blogs

                            Array
(
    [ID] => 126193
    [id] => 126193
    [title] => Azure Partner of the Year 2025
    [filename] => SON6714-22-scaled.jpg
    [filesize] => 872056
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-scaled.jpg
    [link] => https://ergotechnologygroup.com/insights/news/ergo-named-microsoft-ireland-azure-partner-of-the-year/attachment/son6714-22/
    [alt] => Group of professionals standing together on a staircase in a modern office setting, representing Ergo named Microsoft Ireland Azure Partner of the Year
    [author] => 18
    [description] => 
    [caption] => Kevin Greene, Ergo, with Liam Byrne, Alliance Lead, Ergo, Clare Hills, Partner Lead for Microsoft, Yvonne Meijerhof, Ergo, Colm Henn, Ergo, Daria Maenkov, Marketing Manager Ergo, Simon Sharkey, Snr Partner Development Manager, Microsoft, and  Steve Blanche, Chief Technical Officer, Ergo.
    [name] => son6714-22
    [status] => inherit
    [uploaded_to] => 126192
    [date] => 2025-12-03 14:34:05
    [modified] => 2026-01-05 11:46:35
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 2560
    [height] => 1711
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-300x200.jpg
            [medium-width] => 300
            [medium-height] => 200
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-768x513.jpg
            [medium_large-width] => 768
            [medium_large-height] => 513
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-1024x684.jpg
            [large-width] => 1024
            [large-height] => 684
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-1536x1026.jpg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1026
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/12/SON6714-22-2048x1368.jpg
            [2048x2048-width] => 2048
            [2048x2048-height] => 1368
        )

)
1
                            
Group of professionals standing together on a staircase in a modern office setting, representing Ergo named Microsoft Ireland Azure Partner of the Year

News

Ergo named Microsoft Ireland Azure Partner of the Year

                            Array
(
    [ID] => 120978
    [id] => 120978
    [title] => DCU Access to the Workplace - Banner-min
    [filename] => DCU-Access-to-the-Workplace-Banner-min.jpg
    [filesize] => 151135
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min.jpg
    [link] => https://ergotechnologygroup.com/insights/news/dcu-access-to-the-workplace-programme/attachment/dcu-access-to-the-workplace-banner-min/
    [alt] => Ergo & DCU access to the workplace programme
    [author] => 18
    [description] => 
    [caption] => 
    [name] => dcu-access-to-the-workplace-banner-min
    [status] => inherit
    [uploaded_to] => 120959
    [date] => 2025-10-22 13:48:39
    [modified] => 2025-10-22 13:49:07
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1379
    [height] => 927
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min-300x202.jpg
            [medium-width] => 300
            [medium-height] => 202
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min-768x516.jpg
            [medium_large-width] => 768
            [medium_large-height] => 516
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min-1024x688.jpg
            [large-width] => 1024
            [large-height] => 688
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min.jpg
            [1536x1536-width] => 1379
            [1536x1536-height] => 927
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/10/DCU-Access-to-the-Workplace-Banner-min.jpg
            [2048x2048-width] => 1379
            [2048x2048-height] => 927
        )

)
1
                            
Ergo & DCU access to the workplace programme

News

Opening Doors: Ergo and DCU’s Access to the Workplace Programme

                            Array
(
    [ID] => 119312
    [id] => 119312
    [title] => Best Managed Companies
    [filename] => Best-Managed-Companies.jpg
    [filesize] => 203021
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies.jpg
    [link] => https://ergotechnologygroup.com/insights/news/deloitte-best-managed-company-award/attachment/best-managed-companies/
    [alt] => Group celebrating Deloitte Best Managed Companies Platinum Winner 2025 award, standing in front of an event backdrop showcasing the achievement.
    [author] => 18
    [description] => 
    [caption] => 
    [name] => best-managed-companies
    [status] => inherit
    [uploaded_to] => 119311
    [date] => 2025-09-29 20:03:12
    [modified] => 2026-01-06 09:47:56
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1284
    [height] => 848
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies-300x198.jpg
            [medium-width] => 300
            [medium-height] => 198
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies-768x507.jpg
            [medium_large-width] => 768
            [medium_large-height] => 507
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies-1024x676.jpg
            [large-width] => 1024
            [large-height] => 676
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies.jpg
            [1536x1536-width] => 1284
            [1536x1536-height] => 848
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/09/Best-Managed-Companies.jpg
            [2048x2048-width] => 1284
            [2048x2048-height] => 848
        )

)
1
                            
Group celebrating Deloitte Best Managed Companies Platinum Winner 2025 award, standing in front of an event backdrop showcasing the achievement.

News

We’ve done it again – 15 Years as one of Ireland’s Best Managed Companies

                            Array
(
    [ID] => 115804
    [id] => 115804
    [title] => SiteBanner
    [filename] => SiteBanner-1.png
    [filesize] => 363111
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1.png
    [link] => https://ergotechnologygroup.com/insights/news/ergo-achieves-servicenow-partner-status/attachment/sitebanner-4/
    [alt] => Two colleagues collaborating at a desk beside a computer monitor, representing the announcement Ergo Achieves ServiceNow Partner Status with the ServiceNow logo displayed.
    [author] => 18
    [description] => 
    [caption] => 
    [name] => sitebanner-4
    [status] => inherit
    [uploaded_to] => 115777
    [date] => 2025-08-25 14:32:53
    [modified] => 2026-01-07 14:26:18
    [menu_order] => 0
    [mime_type] => image/png
    [type] => image
    [subtype] => png
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 690
    [height] => 383
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1-150x150.png
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1-300x167.png
            [medium-width] => 300
            [medium-height] => 167
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1.png
            [medium_large-width] => 690
            [medium_large-height] => 383
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1.png
            [large-width] => 690
            [large-height] => 383
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1.png
            [1536x1536-width] => 690
            [1536x1536-height] => 383
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/SiteBanner-1.png
            [2048x2048-width] => 690
            [2048x2048-height] => 383
        )

)
1
                            
Two colleagues collaborating at a desk beside a computer monitor, representing the announcement Ergo Achieves ServiceNow Partner Status with the ServiceNow logo displayed.

News

Ergo achieves ServiceNow Partner status

                            Array
(
    [ID] => 115775
    [id] => 115775
    [title] => Press Release 1
    [filename] => Press-Release-1.jpg
    [filesize] => 755585
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1.jpg
    [link] => https://ergotechnologygroup.com/insights/news/ergo-announced-as-title-sponsor-of-clontarf-rugby-club/attachment/press-release-1/
    [alt] => Group of Clontarf Rugby Club players and representatives standing on the pitch holding a rugby ball with Ergo CEO Paul McCann, illustrating the announcement Ergo Announced as Title Sponsor of Clontarf Rugby Club.
    [author] => 18
    [description] => 
    [caption] => 
    [name] => press-release-1
    [status] => inherit
    [uploaded_to] => 115774
    [date] => 2025-08-25 10:13:48
    [modified] => 2026-01-07 14:28:00
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1920
    [height] => 1280
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1-150x150.jpg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1-300x200.jpg
            [medium-width] => 300
            [medium-height] => 200
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1-768x512.jpg
            [medium_large-width] => 768
            [medium_large-height] => 512
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1-1024x683.jpg
            [large-width] => 1024
            [large-height] => 683
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1-1536x1024.jpg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1024
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/08/Press-Release-1.jpg
            [2048x2048-width] => 1920
            [2048x2048-height] => 1280
        )

)
1
                            
Group of Clontarf Rugby Club players and representatives standing on the pitch holding a rugby ball with Ergo CEO Paul McCann, illustrating the announcement Ergo Announced as Title Sponsor of Clontarf Rugby Club.

News

Ergo Announced as Title Sponsor of Clontarf Rugby Club

                            Array
(
    [ID] => 112793
    [id] => 112793
    [title] => original-27B8482D-998E-407D-90E7-683F1E4005B1
    [filename] => original-27B8482D-998E-407D-90E7-683F1E4005B1.jpeg
    [filesize] => 290073
    [url] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1.jpeg
    [link] => https://ergotechnologygroup.com/insights/news/ergo-achieves-gold-partnership-status-with-veeam/attachment/original-27b8482d-998e-407d-90e7-683f1e4005b1/
    [alt] => Ergo team gathered beside an Ergo and Veeam banner celebrating Ergo Achieving Gold Partnership Status with Veeam in a modern office setting.
    [author] => 18
    [description] => 
    [caption] => 
    [name] => original-27b8482d-998e-407d-90e7-683f1e4005b1
    [status] => inherit
    [uploaded_to] => 112792
    [date] => 2025-07-29 15:47:47
    [modified] => 2026-01-08 12:34:43
    [menu_order] => 0
    [mime_type] => image/jpeg
    [type] => image
    [subtype] => jpeg
    [icon] => https://ergotechnologygroup.com/wp-includes/images/media/default.png
    [width] => 1600
    [height] => 1200
    [sizes] => Array
        (
            [thumbnail] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1-150x150.jpeg
            [thumbnail-width] => 150
            [thumbnail-height] => 150
            [medium] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1-300x225.jpeg
            [medium-width] => 300
            [medium-height] => 225
            [medium_large] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1-768x576.jpeg
            [medium_large-width] => 768
            [medium_large-height] => 576
            [large] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1-1024x768.jpeg
            [large-width] => 1024
            [large-height] => 768
            [1536x1536] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1-1536x1152.jpeg
            [1536x1536-width] => 1536
            [1536x1536-height] => 1152
            [2048x2048] => https://ergotechnologygroup.com/wp-content/uploads/2025/07/original-27B8482D-998E-407D-90E7-683F1E4005B1.jpeg
            [2048x2048-width] => 1600
            [2048x2048-height] => 1200
        )

)
1
                            
Ergo team gathered beside an Ergo and Veeam banner celebrating Ergo Achieving Gold Partnership Status with Veeam in a modern office setting.

News

Ergo Achieves Gold Partnership Status with Veeam