Turn resilience requirements into testable operations
By the end, explain the diagram in your own words, solve the case and justify the correction.
Prerequisites : Security, scaling and governance
Level 2 · Intermediate →Reading path · 24 / 35 · Intermediate
DORA is the EU framework for digital operational resilience in the financial sector, applicable from 17 January 2025.
The essentials
DORA is the EU framework for digital operational resilience in the financial sector, applicable from 17 January 2025. It covers ICT risk management, incident reporting, resilience testing and third-party risk requirements for entities within its scope, including specified crypto-asset firms.
How it works
Its purpose is broader than cybersecurity prevention. Organisations need to withstand, respond to and recover from disruption. Map important services to systems and providers, establish recovery objectives, maintain incident classification processes and manage contractual and concentration risks. A backup is useful only if restoration works.
What to watch
For a custody service, examine the signing platform, cloud infrastructure, blockchain-node access and internal ledgers together. An outage in one dependency can interrupt withdrawals even when the blockchain is functioning. Determine the exact entity’s scope and applicable technical requirements before treating a general control checklist as compliance evidence.
Understand the details
Operational resilience concerns maintaining and restoring critical services through ICT disruption. An assessment begins with the functions the organization must deliver, then maps applications, infrastructure, people and external dependencies supporting them. A blockchain’s continued production of blocks does not mean a firm’s own withdrawal, reconciliation or customer service remains available.
Boundaries and common mistakes
Document incident detection, decision responsibility, communication and recovery evidence. Third-party reliance should include concentration and exit considerations, not just a service-level promise. Applicability and specific reporting duties depend on the regulated entity and relevant rules, so a generic checklist cannot substitute for that assessment.
The mechanism at a glance
- Critical service
- Dependency map
- Incident and recovery test
- Evidence of restored service
Apply the lesson to a case
A firm uses one cloud provider for its wallet policy service, monitoring and backups. Simulate a regional outage. List the critical functions affected and the evidence needed before declaring recovery complete.
The site may be reachable while signing, approvals or reconciliation remain unavailable or inconsistent. Recovery should validate the complete service and resolve in-flight instructions safely. Record measured recovery results and remaining dependencies rather than equating a green homepage check with operational resilience.
Prepare a correction note
Describe the passage and the proposed correction. This creates a local note for you to share; it sends nothing. Do not include personal or confidential information.