Close Menu
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing & Mental Health
  • Marketing
  • HR & Recruitment
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
X (Twitter) LinkedIn YouTube
Trending
  • UK SMEs Need AI Workflow Tests, Not More Tool Licences
  • The £5,000 cabin bag: Why travellers are carrying more value than ever before
  • Entries extended for the awards putting solo female founders on a stage of their own
  • AI Training Masterclass Ad
  • CM Brand — More Than Just Merchandise
  • Why authorised rates are payments’ next data battleground
  • Independent British Author Reaches No.1 on Amazon & Donates Profits to Charity
  • Small Food & Drink Business Owner Gripes
X (Twitter) LinkedIn YouTube
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • News
  • Home
  • In Profile
  • Finance
  • Legal
  • Technology
  • Events
  • Features
  • Wellbeing
  • Marketing
  • HR & Recruitment
  • Travel
SME Today
  • About
  • Advertise
  • Events Calendar
  • Business Wall
  • Subscribe
  • Contact
  • 0843 289 4634
  • Twitter
  • LinkedIn
  • YouTube
  • RSS
You are at:Home»Finance»Rethinking resilience in the age of DORA
Risk Ledger

Rethinking resilience in the age of DORA

0
Posted By sme-admin on November 27, 2025 Finance

By Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger

Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger
Justin Kuruvilla, Chief Cyber Security Strategist at Risk Ledger

When the Digital Operational Resilience Act (DORA) was introduced, much of the initial focus naturally centred on compliance. Financial institutions moved quickly to align internal processes and governance frameworks with the new rules, ensuring they met regulatory expectations. But DORA was never just about ticking boxes. At its core, it represents a shift in mindset, from safeguarding individual firms to protecting the stability of the entire financial ecosystem. Regulators are seeking to uncover and address the systemic risks that arise from deep interconnections and shared dependencies across the sector. True resilience will come not from isolated compliance efforts, but from collective visibility, collaboration and trust across the whole industry.  

The next phase of resilience

Harmonising rules and building on existing practices to strengthen individual firms’ operational resilience are an important, yet only one aspect of DORA. The regulation is not merely an updated compliance checklist; regulators are seeking to achieve a far more profound objective: identifying and tackling systemic concentration risks to the entire financial ecosystem. The lack of Union-level rules and national mandates had previously meant financial supervisors struggled to acquire a good understanding of ICT third-party dependencies and monitor risks arising from their concentration.

DORA’s ultimate aim is to gather extensive, granular information—including details on service level agreements—from financial entities regarding their third, fourth, and subsequent parties. This comprehensive data is intended to enable regulators to map the extended supply chain ecosystem of the wider financial sector and better understand intricate dependencies. Ultimately, this allows them to identify systemic risks, single points of failure, and security bottlenecks that affect the sector as a whole.

This bird’s-eye view is essential because an incident at a single, widely-used service provider can have a wide-reaching impact on many organisations simultaneously—a systemic risk event. For example, a DDoS attack on a payment processor could disrupt payment processing for numerous financial firms. Furthermore, a security breach further down the supply chain, such as a ransomware attack at a fourth-party SaaS provider, can simultaneously disrupt multiple suppliers which in turn provide services to one or more financial entities. The lack of visibility into such existing dependencies in extended supply chains hinders effective preparedness for potential risk scenarios.

From audits to active supplier collaboration

This holistic, sectoral approach is crucial to truly bolster operational resilience, not just for the entire financial sector but, by extension, for individual firms. The lack of visibility into supply chain dependencies beyond third-parties is a critical weakness. This is where enhanced collaboration—both with suppliers and industry peers— becomes essential.

While leveraging existing TPRM processes to identify concentration risks is a starting point, focusing solely on one-to-one client-supplier relationships is incomplete. A crucial element is building a more collaborative, less adversarial relationship with suppliers’ security teams. A “collaborate, don’t audit” approach acknowledges that both financial entities and their suppliers share the objective of avoiding and responding well to incidents. Good relationships with suppliers help financial firms gain more accurate information, improve security defences, and deal with incidents more effectively.

Enhancing supply chain visibility to strengthen resilience

To gain the necessary visibility into fourth-, fifth-, and nth-party risks, firms must understand these downstream interactions and dependencies, particularly for critical services. Understanding these deeper supply chain connections is vital to securing the weakest link and informing decisions.

Systemic concentration risks can only be effectively identified through a comprehensive analysis of the supply chains across the entire sector; however, this is impossible for individual firms to achieve alone. This is where peer collaboration provides unique benefits. Through enhanced collaboration and the sharing of granular data—such as on suppliers, control assessments, and criticality ratings—between TPRM teams, a comprehensive mapping of risks across the broader financial services sector can emerge. This allows financial institutions to gain a deeper understanding of supplier relationships and assess the wide-scale operational impact of a disruption at a critical ICT third party. They can then collaboratively triage, prioritise, and develop targeted mitigation strategies for these risks.

Like the established sharing of threat intelligence, enhanced peer collaboration around supplier intelligence would allow TPRM teams to identify potential risks they were previously unaware of, gaining enhanced visibility into both individual and systemic risks. This collective effort to map the supply chain goes above and beyond what DORA may explicitly require, but would directly enhance an organisation’s own operational resilience and aid regulators in their ultimate aim of identifying systemic risks facing the entire sector.

As the financial sector moves beyond compliance checklists toward true operational resilience, DORA offers a catalyst for a more connected and transparent ecosystem. The regulation’s intent reaches far beyond risk mitigation; it encourages a shared responsibility model where visibility, collaboration and trust between firms, suppliers and regulators become standard practice. Building this collective resilience will not only safeguard against systemic shocks but also foster a stronger, more agile financial sector that can continue to evolve with technological and market change.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The £5,000 cabin bag: Why travellers are carrying more value than ever before

Why authorised rates are payments’ next data battleground

Water Efficiency Lab 2 launches to prevent, predict, pinpoint and fix customer side leakage

Comments are closed.

Follow SME Today on Linkedin and share all the topics you find interesting
Porsch Reading – Find Your Perfect Business Partner
Mastermind9
Events Calendar
    November 26, 2026 10:00 am

    South West Expo Swindon

    October 14, 2026 10:00 am

    Thames Valley Expo Reading

  • Marketing
August 10, 2026

The Power of Strategic PR – Strategy, Storytelling, and Scale

August 7, 2026

New referral platform aims to solve agencies’ lead generation problem

  • Finance
August 14, 2026

The £5,000 cabin bag: Why travellers are carrying more value than ever before

August 13, 2026

Why authorised rates are payments’ next data battleground

  • People
August 10, 2026

Lloyds appoints Fiamma Morton as Managing Director for SME banking across the UK

July 24, 2026

Finance Expert Joins One Of London’s Leading Chambers To Support Local Businesses 

  • Health & Safety
July 21, 2026

Loo Of The Year Awards Named Finalist In Prestigious European Industry Awards

July 14, 2026

Terror Attack Prevention: Swindon Health And Safety Expert On Martyn’s Law

  • Events
August 13, 2026

Entries extended for the awards putting solo female founders on a stage of their own

June 29, 2026

Great British Expos Postpones South West Expo Due to Extreme Heat Forecast

  • Community
August 13, 2026

Independent British Author Reaches No.1 on Amazon & Donates Profits to Charity

June 19, 2026

Founders charity dinner set to raise funds for epilepsy care

  • Food & Drink
August 12, 2026

Small Food & Drink Business Owner Gripes

June 23, 2026

How To Market A Restaurant

  • Books
August 13, 2026

Independent British Author Reaches No.1 on Amazon & Donates Profits to Charity

June 2, 2026

Build a Business So Good You’d Be Mad to Sell It

The Newsletter

Join our mailing list for the best SME stories, handpicked and delivered direct to your inbox every two weeks!

Sign Up
About

SME Today is published by the same team who deliver The Great British Expos’. We have been organising various corporate events for the last 10 years, with a strong track record of producing well managed and attended business events across the UK.

Join Our Mailing List

Receive the latest news and updates from SMEToday.
Read our Latest Newsletter:


Sign Up
X (Twitter) YouTube LinkedIn
Categories
  • App Ads
  • Books
  • Business
  • Community & Charity
  • Education and Training
  • Environment
  • Events
  • Features
  • Finance
  • Food and Drink
  • Health & Safety
  • HR & Recruitment
  • In Profile
  • Legal
  • Marketing
  • News
  • People
  • Property & Development
  • Sponsored Content
  • Technology
  • Transport, Travel & Tourism
  • Wellbeing & Mental Health
Magazine Information
  • About SME Today
  • Editorial Submission Guidelines
  • Advertising
  • Privacy
  • Contact
  • Editorial Complaints Policy
Copyright © 2025 SME Today.
  • About SME Today
  • Editorial Submission Guidelines
  • Advertising
  • Privacy
  • Contact
  • Editorial Complaints Policy

Type above and press Enter to search. Press Esc to cancel.

Subscribe Now!

Sign up for a FREE subscription and receive the latest news, features and updates from SMEToday:

I am interested in:
 

Thank you for subscribing to SME Today! We're thrilled to have you join our community. To complete your subscription, please check your email and click on the confirmation link. If you don’t see the email in your inbox, be sure to check your spam or junk folder. We look forward to sharing exciting news, updates, and exclusive content with you!

Join our mailing list to receive the latest news and updates from SMEToday
Read our Latest Newsletter: