Since January 17, 2025, the European regulation DORA (Digital Operational Resilience Act) has officially entered into force. Its ambition is clear: to strengthen the operational resilience of the financial sector against cyber threats. And this time, it is no longer just about technical security, but a profound transformation of practices, tools… and relations with service providers.
So, what does this new text really change? And above all, what are the concrete consequences for financial institutions and their technology partners like QuickSign?
A look back at our very first webinar of the year, where lawyers, cybersecurity experts, and auditors brought their perspectives together.
DORA: something new? Not really. A turning point? Definitely.
At first glance, DORA does not reinvent the wheel. Managing risks related to cybersecurity, outsourcing, or business continuity is already well known to CIOs and CISOs. The EBA had set milestones as early as 2019, French law had introduced the concept of outsourced essential service providers (PSEE), and certifications like ISO 27001 are widely adopted.
But with DORA, it is no longer a simple recommendation. It is a strong, cross-cutting, and auditable regulatory requirement that imposes robust operational governance, far beyond tools.
As Armel Trotin, founder of the firm LSTI, summarizes:
“It is no longer just a question of security, but of resilience: anticipating, absorbing, reacting, and restarting quickly.”
What DORA concretely imposes (and why it is structural)
Accompanied by the LSTI firm, the QuickSign team closely analyzed the major pillars of the DORA regulation. Each pillar directly impacts financial services… and by extension, their providers.
- First pillar: Third-party risk management.DORA significantly expands the scope of responsibility. Institutions must now manage their entire outsourcing chain, including their subcontractors’ subcontractors. This involves reinforced contractual clauses, due diligence processes, reversibility logic, and increased vigilance regarding conflicts of interest.
- Second requirement: IT incident management.Financial institutions must be able to detect, classify, notify, and resolve a critical incident in under 4 hours. At QuickSign, this logic is already integrated into industrial governance: real-time monitoring, proactive client communication, regular crisis exercises…
- Third component: Resilience testing.DORA pushes industry players to evaluate their ability to withstand a crisis — whether an external attack, an internal malfunction, or a series of human errors. This involves deploying penetration tests, phishing campaigns, configuration audits, or even red team exercises.
- Finally, DORA imposes integrated governance.The various requirements must not be addressed in silos, but within a global management framework. At QuickSign, this approach relies on ISO 27001 foundations, which structure our overall cyber governance — in line with the GDPR and eIDAS components also concerned.
DORA: a constraint or a strategic lever?
Achieving DORA compliance is a challenge, for sure. But it is also a major opportunity to professionalize security, strengthen the relationship of trust between providers and financial institutions, and demonstrate fine-grained risk control.
As Ahmed Boussadia, CISO at QuickSign, points out:
“DORA is a challenge. But also a tremendous opportunity to industrialize security.”
Want to know more ? Watch the video :
Written by Nicolas G.