DORA was initially read as a banking regulation. In practice, its broader effect falls on technology companies that provide services to financial entities, because the obligations reach them contractually even though the regulation does not mention them.

Who it affects

Directly, a wide range of financial entities: banks, insurers, managers, payment entities, crypto-asset service providers and, among others, the brokers themselves. Indirectly, to any ICT service provider of those entities, which receives the requirements transferred to the service provision contract.

The five blocks of obligations

ICT risk management with board involvement, notification of serious incidents, digital operational resilience testing, third-party risk management with an agreement registry, and information-sharing mechanisms on threats. The third-party block generates the most administrative work, as it requires maintaining a structured registry of all ICT agreements and being able to identify which support essential functions.

The contractual clauses that now need to be negotiated

Complete service description, performance levels, data processing location, rights of access and inspection, cooperation obligations in the event of incidents, and orderly exit strategies. For the technology provider, this means accepting audits and continuity commitments that their previous contract probably did not contemplate, with the consequent increase in their own exposure.

What to look for in the insurance

In the financial entity, that the cyber insurance covers the interruption caused by an ICT provider, which is exactly the scenario DORA aims to prevent. In the technology provider, that their professional liability covers the breach of service levels and contractual penalties, as the new contracts incorporate them with amounts much higher than those usual until now.

Compartir