Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • ChatGPT’s New Ads Could Catch Thousands of Small Businesses Out
  • If OpenAI Can’t Control Its Own AI, Can Your Business Control Yours?
  • Innerva Puts Its People First with Transition to Employee Ownership
  • Energy experts warn businesses not to overlook upcoming MHHS reforms
  • ILLEGAL WORKING: Warning to SMEs using subcontractors
  • Extended Heatwaves Present a ‘Hot’ Opportunity for UK Ecommerce Brands
  • Business welcomes rates relief but calls for wider support for SMEs
  • Businesses welcome AI Cabinet role but urge government to turn ambition into action
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
  • Travel
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Finance»Rethinking resilience in the age of DORA
Risk Ledger

Rethinking resilience in the age of DORA

0
Posted By sme-admin on November 27, 2025 Finance

By Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger

Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger
Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger

When the Digital Operational Resilience Act (DORA) was introduced, much of the initial focus naturally centred on compliance. Financial institutions moved quickly to align internal processes and governance frameworks with the new rules, ensuring they met regulatory expectations. But DORA was never just about ticking boxes. At its core, it represents a shift in mindset, from safeguarding individual firms to protecting the stability of the entire financial ecosystem. Regulators are seeking to uncover and address the systemic risks that arise from deep interconnections and shared dependencies across the sector. True resilience will come not from isolated compliance efforts, but from collective visibility, collaboration and trust across the whole industry.  

The next phase of resilience

Harmonising rules and building on existing practices to strengthen individual firms’ operational resilience are an important, yet only one aspect of DORA. The regulation is not merely an updated compliance checklist; regulators are seeking to achieve a far more profound objective: identifying and tackling systemic concentration risks to the entire financial ecosystem. The lack of Union-level rules and national mandates had previously meant financial supervisors struggled to acquire a good understanding of ICT third-party dependencies and monitor risks arising from their concentration.

DORA’s ultimate aim is to gather extensive, granular information—including details on service level agreements—from financial entities regarding their third, fourth, and subsequent parties. This comprehensive data is intended to enable regulators to map the extended supply chain ecosystem of the wider financial sector and better understand intricate dependencies. Ultimately, this allows them to identify systemic risks, single points of failure, and security bottlenecks that affect the sector as a whole.

This bird’s-eye view is essential because an incident at a single, widely-used service provider can have a wide-reaching impact on many organisations simultaneously—a systemic risk event. For example, a DDoS attack on a payment processor could disrupt payment processing for numerous financial firms. Furthermore, a security breach further down the supply chain, such as a ransomware attack at a fourth-party SaaS provider, can simultaneously disrupt multiple suppliers which in turn provide services to one or more financial entities. The lack of visibility into such existing dependencies in extended supply chains hinders effective preparedness for potential risk scenarios.

From audits to active supplier collaboration

This holistic, sectoral approach is crucial to truly bolster operational resilience, not just for the entire financial sector but, by extension, for individual firms. The lack of visibility into supply chain dependencies beyond third-parties is a critical weakness. This is where enhanced collaboration—both with suppliers and industry peers— becomes essential.

While leveraging existing TPRM processes to identify concentration risks is a starting point, focusing solely on one-to-one client-supplier relationships is incomplete. A crucial element is building a more collaborative, less adversarial relationship with suppliers’ security teams. A “collaborate, don’t audit” approach acknowledges that both financial entities and their suppliers share the objective of avoiding and responding well to incidents. Good relationships with suppliers help financial firms gain more accurate information, improve security defences, and deal with incidents more effectively.

Enhancing supply chain visibility to strengthen resilience

To gain the necessary visibility into fourth-, fifth-, and nth-party risks, firms must understand these downstream interactions and dependencies, particularly for critical services. Understanding these deeper supply chain connections is vital to securing the weakest link and informing decisions.

Systemic concentration risks can only be effectively identified through a comprehensive analysis of the supply chains across the entire sector; however, this is impossible for individual firms to achieve alone. This is where peer collaboration provides unique benefits. Through enhanced collaboration and the sharing of granular data—such as on suppliers, control assessments, and criticality ratings—between TPRM teams, a comprehensive mapping of risks across the broader financial services sector can emerge. This allows financial institutions to gain a deeper understanding of supplier relationships and assess the wide-scale operational impact of a disruption at a critical ICT third party. They can then collaboratively triage, prioritise, and develop targeted mitigation strategies for these risks.

Like the established sharing of threat intelligence, enhanced peer collaboration around supplier intelligence would allow TPRM teams to identify potential risks they were previously unaware of, gaining enhanced visibility into both individual and systemic risks. This collective effort to map the supply chain goes above and beyond what DORA may explicitly require, but would directly enhance an organisation’s own operational resilience and aid regulators in their ultimate aim of identifying systemic risks facing the entire sector.

As the financial sector moves beyond compliance checklists toward true operational resilience, DORA offers a catalyst for a more connected and transparent ecosystem. The regulation’s intent reaches far beyond risk mitigation; it encourages a shared responsibility model where visibility, collaboration and trust between firms, suppliers and regulators become standard practice. Building this collective resilience will not only safeguard against systemic shocks but also foster a stronger, more agile financial sector that can continue to evolve with technological and market change.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Energy experts warn businesses not to overlook upcoming MHHS reforms

Business welcomes rates relief but calls for wider support for SMEs

Balance sheets & big dreams – how young entrepreneurs are building their financial confidence

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
Porsch Reading – Find Your Perfect Business Partner
Mastermind9
Events Calendar
    November 26, 2026 10:00 am

    South West Expo Swindon

    October 14, 2026 10:00 am

    Thames Valley Expo Reading

  • Marketing
August 4, 2026

ChatGPT’s New Ads Could Catch Thousands of Small Businesses Out

July 22, 2026

71% of independent tradesmen have a dead website

  • Finance
July 31, 2026

Energy experts warn businesses not to overlook upcoming MHHS reforms

July 30, 2026

Business welcomes rates relief but calls for wider support for SMEs

  • People
July 24, 2026

Finance Expert Joins One Of London’s Leading Chambers To Support Local Businesses 

July 24, 2026

Westspring It Strengthens Team With Three Key Appointments To Support Continued Growth

  • Health & Safety
July 21, 2026

Loo Of The Year Awards Named Finalist In Prestigious European Industry Awards

July 14, 2026

Terror Attack Prevention: Swindon Health And Safety Expert On Martyn’s Law

  • Events
June 29, 2026

Great British Expos Postpones South West Expo Due to Extreme Heat Forecast

June 16, 2026

Why Every SME Needs an AI Strategy — Not Just AI Tools

  • Community
June 19, 2026

Founders charity dinner set to raise funds for epilepsy care

June 17, 2026

Award-Winning Charity Launches New Initiative To Connect Local Organisations

  • Food & Drink
June 23, 2026

How To Market A Restaurant

June 23, 2026

From Corporate Comfort to Cultural Opportunity: The Bunta Beer Journey

  • Books
June 2, 2026

Build a Business So Good You’d Be Mad to Sell It

January 21, 2026

The CEO Mirage: Exposing the hidden traps that take smart leaders down

The Newsletter

Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

Sign Up
About

SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

Join Our Mailing List

Receive the latest news and updates from SMEToday.
Read our Latest Newsletter:


Sign Up
X (Twitter) YouTube LinkedIn
Categories
  • Books
  • Business
  • Community & Charity
  • Education and Training
  • Environment
  • Events
  • Features
  • Finance
  • Food and Drink
  • Health & Safety
  • HR & Recruitment
  • In Profile
  • Legal
  • Marketing
  • News
  • People
  • Property & Development
  • Sponsored Content
  • Technology
  • Transport, Travel & Tourism
  • Wellbeing & Mental Health
Magazine Information
  • About SME Today
  • Editorial Submission Guidelines
  • Advertising
  • Privacy
  • Contact
Copyright © 2025 SME Today.
  • About SME Today
  • Editorial Submission Guidelines
  • Advertising
  • Privacy
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Subscribe Now!

Sign up for a FREE subscription and receive the latest news, features and updates from SMEToday:

I am interested in:
 

Thank you for subscribing to SME Today! We're thrilled to have you join our community. To complete your subscription, please check your email and click on the confirmation link. If you don’t see the email in your inbox, be sure to check your spam or junk folder. We look forward to sharing exciting news, updates, and exclusive content with you!

Join our mailing list to receive the latest news and updates from SMEToday
Read our Latest Newsletter: