96% of EMEA financial services organisations believe they need to improve their resilience to meet DORA requirements

96% of EMEA financial services organisations believe they need to improve their resilience to meet DORA requirements

New Veeam survey uncovers top compliance challenges and the urgent need for holistic data resilience, six months after the DORA deadline.

Six months after the EU’s Digital Operational Resilience Act (DORA) came into effect, a new Censuswide survey commissioned by Veeam Software, the global leader in data resilience by market share, reveals that 96% of EMEA financial services organisations still feel their current level of data resilience falls short.

The survey, which gathered insights from senior IT decision-makers at financial services companies in the UK, France, Germany and the Netherlands, underscores the ongoing challenges faced by the sector as it adapts to DORA – a framework introduced by the EU in January 2025 to strengthen the financial industry’s defences against cyberthreats and ICT disruptions.

While DORA has been embedded as a strategic priority across the financial sector, many organisations are still navigating the path to full compliance. The survey found that 94% of organisations now rank DORA higher in their priorities than they did in the month before the deadline, with 40% calling it a current “top digital resilience priority.” Half of respondents said DORA requirements have been integrated into broader resilience programmes, while 39% reported it remains a central focus.

The unintended consequences of DORA

Even with 94% of organisations clear on the steps they need to take, many are facing unforeseen challenges:

  • 41% report increased stress and pressure on IT and security teams
  • 37% are dealing with higher costs passed on by ICT vendors
  • 22% believe the volume of digital regulation is becoming a barrier to innovation or competition
  • 20% have yet to secure the necessary budget to meet DORA requirements

“It’s promising to see that most organisations have embraced and feel confident about meeting DORA’s requirements,” said Edwin Weijdema, Field CTO EMEA at Veeam. “Achieving compliance is an important first step in ensuring your organisation is resilient but given today’s complex threat landscape there’s more to do. New Veeam research shows that many financial institutions still see a gap in their overall resilience and face challenges in securing the necessary budget, even as DORA grows in strategic importance. The journey to operational resilience is ongoing, and it’s clear that prioritising data resilience remains critical for organisations’ long-term success.”

DORA: Still a work in progress

Despite the prioritisation, many organisations are still working to meet key DORA requirements:

  • 24% have not established recovery and continuity testing
  • 24% have not implemented incident reporting
  • 24% have not identified a DORA implementation lead
  • 23% have not conducted digital operational resilience testing
  • 21% have not ensured backup integrity and secure data recovery

The most challenging DORA requirement? Third-party risk oversight, with 34% of organisations citing it as the hardest to implement – despite only 20% yet to do so. There are many possible reasons for this, from the limited visibility many organisations have into their third-party operations to the sheer scale of third-party networks.

Andre Troskie, Field CISO EMEA at Veeam, said: “It’s interesting to see that third-party oversight has emerged as a particular pain point for organisations. Over a third named it the most challenging to implement, and many called for additional guidance on establishing it in the first place. An often-overlooked facet of data resilience, it’s promising to see that organisations are interrogating their defences to this degree – which is exactly what it was designed to do. Of course, meeting the requirements is key, but DORA was also about getting organisations to assess their resilience holistically – and in that aspect, it seems to be succeeding.”

Additionally, 22% of organisations felt that DORA’s design could have been improved to aid compliance, with calls for simplification, clarification and more detailed third-party risk guidance.

Supporting the journey to resilience

In response to the growing need for structured resilience strategies, Veeam and McKinsey earlier this year introduced the industry’s first Data Resilience Maturity Model (DRMM). Built on extensive research and insights from over 500 IT, security and operations leaders, the Veeam DRMM has been validated through real-world customer outcomes. This framework enables organisations to assess their data resilience using a cross-functional approach that integrates IT, security and compliance into a unified strategy.

It provides a clear roadmap for enhancing resilience and achieving compliance with regulations such as DORA.

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive