Glossary

Digital operational resilience

Digital operational resilience is, under the DORA regulation, a financial entity's ability to build, assure and review its operational integrity and reliability in the face of ICT disruptions, including those originating from its ICT third-party providers.

The five DORA pillars

The regulation structures the requirement in five blocks: ICT risk governance and management, major incident reporting, resilience testing (including threat-led penetration testing for the most significant entities), ICT third-party risk management, and information sharing on cyber threats.

The fourth block shifts the most work onto TPRM: register of contractual arrangements, mandatory clauses, documented exit strategy for critical functions, prior analysis of concentration risk.

Difference with a plain continuity plan

A continuity plan answers "how do we restart after an outage". Operational resilience additionally requires demonstrating through testing that the arrangement works, and covering the outsourced delivery chain, not just the internal information system. Full obligations on the DORA page.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account