DORA
Digital Operational Resilience Act
Regulated financial entities must withstand, respond to and recover from ICT disruption — and prove it.
Typical exposure
Most critical workloads sit with US hyperscalers and processors, with no concentration register and no tested exit.
What it requires
- Full audit rights and contractual control over outsourced ICT
- Active management of concentration risk across providers
- Demonstrably sovereign incident response and data recovery
- A tested exit strategy for every critical provider