🔴 Under active attack? Get connected to an incident response team now — Get Emergency Help →
DORA & ransomware: what EU financial firms must prove now
Risk & Compliance

DORA & ransomware: what EU financial firms must prove now

ERD Research TeamJun 17, 20265 min read

Key takeaways

  • DORA shifts the standard from 'have a policy' to 'prove you can withstand and recover,' with specific testing and reporting duties.
  • Firms need dated evidence — executed resilience tests, a third-party ICT risk register, and reporting processes that meet the timelines.
  • For most mid-sized firms the gap is documentation and rehearsal, not strategy.

From 'have a policy' to 'prove you can recover'

The Digital Operational Resilience Act reshapes how EU financial services firms must approach ransomware readiness — shifting from a 'have a policy' standard to a 'prove you can withstand and recover' standard, with specific testing and reporting obligations. It's less about writing new documents and more about demonstrating, with evidence, that your resilience is real.

What you actually have to demonstrate

In practice, this means firms need documented, regularly executed resilience testing (including scenario-based testing that maps closely to a ransomware event), a formal ICT third-party risk register covering the vendors and providers who could bring an incident to your door, and incident classification and reporting processes that can meet DORA's reporting timelines under real pressure. Each of these has to be evidenced, not asserted.

The gap is evidence, not strategy

For most mid-sized firms, the gap isn't strategy — it's evidence. Regulators want to see tested playbooks and dated records of tabletop exercises, not a resilience policy that has never been rehearsed. If you can produce the incident-response plan but not the record of the last time you exercised it, DORA's standard treats that as the gap it is. The work is to turn intentions into a documented, dated, repeatable trail.

We respect your privacy

We use analytics cookies to understand how visitors use this site and improve our defense resources. No advertising or cross-site tracking. Privacy Policy