The Digital Operational Resilience Act (DORA) has firmly established the concept of digital resilience in the day-to-day operations of many financial institutions, ensuring that it is no longer viewed as an isolated IT issue but as an integral part of operational management. Financial institutions must integrate risk management, incident response processes, testing and third-party management into a consistent framework – and, above all, demonstrate this in their day-to-day operations.
Our benchmark overview shows that the fundamental governance structures are in place in most organisations. The key challenge now lies in operational implementation. Many financial institutions have roles, policies and documented processes in place – but far fewer have evidence that these work under real-world conditions. Our publication shows where the industry actually stands – and where there is still room for improvement.