Stronger together: Leveraging DORA for true digital resilience in finance

Insights

24/04/2025

In today’s financial landscape, resilience isn’t optional - it’s essential. On January 17, 2025, the European Union took a significant step to improve the digital resilience of financial institutions by implementing the Digital Operational Resilience Act (DORA). This regulation marks a transformative effort to strengthen financial organisations against increasing cyber threats and technological disruptions.

Why DORA matters to your business
Central to DORA is the commitment to protect consumer interests and stabilise the financial system by boosting the security and operational resilience of these institutions. Its primary goals include: 

  • Customer protection: Enhancing the reliability and security of financial services to protect consumer and investor interests. 
  • Operational resilience: Boosting the ability of financial entities to predict, withstand, and recover from disruptions. 
  • Standardised practices: Establishing standards across the sector for risk management, incident reporting, and resilience testing. 
  • Regulatory oversight: Strengthening EU-wide oversight and coordination to ensure compliance with digital resilience requirements. 
Beyond compliance: Embedding real security
While DORA requires comprehensive standards for risk management, incident reporting, and resilience testing, the true challenge for financial organisations, particularly in the Life and Pensions sector, is not just to comply but to genuinely protect themselves and their customers against cyber threats. 

Legal and compliance frameworks often trap organisations in a checkbox mentality, where metrics management is given priority over practical security measures. This focus on compliance metrics can lead to misguided behaviours and, ironically, a lesser secure environment. As organisations strive to meet regulatory standards, the real work should focus on implementing practical and impactful security measures rather than merely achieving compliance on paper.

“I see DORA as a strategic enabler. It pushes us to go beyond the baseline and innovate in our cybersecurity measures, ensuring we comply with the law and lead the industry in resilience and trust", says Mattias Ekenstedt, Compliance Manager, Lumera. 

Collaboration: The cornerstone of resilience
As always, extensive regulatory frameworks like DORA pose significant challenges and need a well-defined collaborative approach to ensure success for all parties involved. Our experiences from similar regulations are that risk-based regulatory frameworks often pose a challenge for organisations, especially from a legal point of view. Another challenge we have experienced is related to the risk-based approach where technical areas are being regulated. DORA for example is inspired by well-established and complex information security frameworks where it often takes years to implement an operational model that suits the context and pre-requisites. 

Collaboration is key on all levels. Working together over the whole supply chain, both strategically and operationally, and helping each other with establishing good security measures and controls. The psychology of these kind of regulations often comes with increased stress levels where it is extra important to collaborate and assisting each other in focusing on the bigger picture.

Implementing DORA: A path to genuine resilience
Implementing DORA is an opportunity for genuine resilience and enhanced market position. This involves substantial investment in technology and training. However, to truly leverage these investments, a collaborative approach is essential. By combining knowledge and resources, a resilient operational framework that extends beyond compliance can be developed, setting a new standard throughout the supply chain. 

Regional rollout and Lumera’s strategic role
The implementation of DORA varies across regions, with Sweden, Norway, the Netherlands, and non-EU countries like the UK adapting to meet local conditions while ensuring compliance. Lumera's commitment to security is demonstrated through frameworks like ISO 27001 and ISAE 3402, emphasising a proactive rather than reactive approach to cybersecurity. Through the Lumera Alliance model, we encourage a collaborative environment focused on relevant outcomes. 

From regulation to resilience: Let’s move forward together
The Digital Operational Resilience Act (DORA) marks a critical evolution in how financial institutions handle digital threats. More than a compliance checklist, DORA serves as a catalyst for genuine resilience, encouraging a shift towards actionable and collaborative security measures. For Lumera and our clients, it offers both challenges and substantial opportunities to enhance operational security. 

By embracing DORA’s principles and integrating them into our Lumera Alliance model, we nurture a proactive cybersecurity environment. This united effort meets regulatory demands and enhances our resilience, ensuring robust and trusted financial services. As we advance, our unified efforts will transform these regulatory challenges into strategic advantages, reinforcing the industry's stability and trust.

Related content

Stay informed – and stay ahead

Keep up to date with the latest insights, advice and opinions from across the industry.

Complete the form to receive relevant insights, event invites and industry news.