Listen to this Post

A Wake-Up Call for
Six months after the EU’s Digital Operational Resilience Act (DORA) came into force, a staggering majority of financial institutions across Europe are still struggling to meet its stringent requirements. While the regulation aims to enhance cybersecurity and operational resilience, many firms find themselves under intense pressure—facing soaring costs, unclear guidelines, and the looming threat of hefty fines. Despite the urgency, compliance remains elusive for most, revealing a troubling disconnect between regulation and real-world implementation.
Financial Sector Falling Behind on DORA
Research conducted by Veeam has revealed that a massive 96% of financial services organizations in Europe admit their current data resilience strategies fall short of DORA compliance. DORA, which officially came into effect on January 17, 2025, is designed to ensure the digital resilience of EU financial institutions including banks, insurers, investment firms, and their third-party IT providers. However, six months into enforcement, financial institutions are far from ready.
Several barriers are slowing compliance efforts. Nearly 41% of companies reported increased stress and workload for IT and security teams, while 37% are dealing with rising costs—much of it passed on by third-party technology providers. Alarmingly, 20% of organizations still haven’t secured the necessary budget to comply with the regulation.
One of the main friction points is third-party risk oversight. Around 34% of organizations named it the most difficult DORA requirement, mainly due to the complexity and scale of third-party networks within the financial industry. As a result, 20% have not yet implemented any DORA-compliant framework for managing third-party risk.
Other essential compliance actions remain incomplete across the board. Roughly a quarter of organizations are still working on:
Recovery and continuity testing
Incident response protocols
Appointing a dedicated DORA compliance lead
Data backup integrity checks
Full-scale digital resilience testing
Despite these struggles, DORA has rapidly climbed the list of executive priorities. According to the study, 94% of organizations now rank DORA compliance higher than they did prior to the law’s enforcement. Half of all respondents said DORA requirements have now been integrated into broader resilience strategies, with 40% labeling it their top digital resilience priority.
Veeam’s Field CISO for EMEA, Andre Troskie, emphasized that DORA isn’t just about compliance, but about fostering a culture of end-to-end resilience across organizations—a goal which many firms seem to be embracing, albeit slowly.
The Veeam study surveyed 404 senior IT executives and heads of compliance across major European financial centers including the UK, France, Germany, and the Netherlands. Given the penalties—up to 2% of global turnover or €10 million for firms, and daily fines for third-party vendors—the stakes for falling behind on DORA are dangerously high.
What Undercode Say:
Compliance Crisis Brewing in the Shadows
The DORA regulation was never expected to be easy—but the depth of unpreparedness revealed by this report is staggering. With 96% of institutions still lagging behind, it’s clear that the industry underestimated both the complexity and the urgency of DORA’s demands.
Third-Party Risk: The Achilles Heel
The biggest barrier to compliance appears to be third-party risk management, and this is no surprise. Financial institutions have long relied on sprawling networks of vendors, each introducing its own set of vulnerabilities. But DORA’s expectations are uncompromising—every link in the digital supply chain must meet strict resilience criteria. Many organizations are now realizing that auditing, monitoring, and securing these partners is a monumental task.
Human and Financial Strain
The regulatory burden is exacting a significant toll. With 41% of IT and security teams reporting heightened stress, and over a third of firms citing increased vendor costs, the operational impact is real. Add to this the 20% of organizations that haven’t even allocated the necessary budget, and it becomes evident that financial readiness is as much an obstacle as technical readiness.
Partial Integration, Full Exposure
While many companies have begun incorporating DORA into broader resilience strategies, the fact that so many foundational tasks remain incomplete exposes them to both regulatory penalties and operational failure. The piecemeal approach to compliance is dangerous in a landscape where even a single breach can have cascading consequences.
Cultural Shift Needed, Not Just Compliance
Veeam’s Andre Troskie points out a critical truth: DORA is not just a checklist. It’s a call for a holistic shift in how financial institutions think about resilience. This involves leadership buy-in, cross-department collaboration, and a long-term investment mindset—not just tactical fixes to avoid penalties.
Regulatory Iron Fist
DORA doesn’t mince words on enforcement. With penalties reaching up to 2% of global turnover—or daily fines for vendors—it’s one of the most financially punitive cybersecurity laws globally. Non-compliance isn’t just a bureaucratic failure; it’s a fiscal risk that boards can no longer afford to ignore.
The Time Bomb of Delay
Each month of non-compliance increases the danger, both legally and operationally. With the threat landscape evolving rapidly, especially in terms of ransomware and supply chain attacks, institutions that delay implementation are effectively walking a tightrope without a safety net.
Strategic Gaps Still Persist
The survey reveals that even fundamental components—like appointing a DORA implementation lead—are still missing in nearly a quarter of firms. That speaks to a troubling lack of ownership and strategic focus. Without clear leadership, organizations risk fragmented, ineffective execution.
🔍 Fact Checker Results:
✅ DORA became enforceable on January 17, 2025
✅ Non-compliance can lead to fines up to €10 million or 2% of global turnover
❌ 96% of firms claim full compliance — actually, 96% admit they are not yet compliant
📊 Prediction:
Given the current rate of DORA implementation, full industry-wide compliance is unlikely before mid-2026. Expect regulatory crackdowns to begin by Q1 2026, especially targeting firms that have not even secured budgets. Third-party vendors will become a regulatory flashpoint, forcing many financial institutions to renegotiate contracts or drop risky partners altogether. The focus will shift from “compliance planning” to “audit survival.” ⏳💣
References:
Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




