{"id":123024,"date":"2025-07-17T15:27:29","date_gmt":"2025-07-17T14:27:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=123024"},"modified":"2025-07-17T15:27:31","modified_gmt":"2025-07-17T14:27:31","slug":"96-of-emea-financial-services-organisations-believe-they-need-to-improve-their-resilience-to-meet-dora-requirements","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2025\/07\/17\/96-of-emea-financial-services-organisations-believe-they-need-to-improve-their-resilience-to-meet-dora-requirements\/","title":{"rendered":"96% of EMEA financial services organisations believe they need to improve their resilience to meet DORA requirements"},"content":{"rendered":"\n<p><em>New Veeam survey uncovers top compliance challenges and the urgent need for holistic data resilience, six months after the DORA deadline.<\/em><\/p>\n\n\n\n<p>Six months after the EU\u2019s Digital Operational Resilience Act (DORA) came into effect, a new Censuswide survey commissioned by Veeam Software, the global leader in data resilience by market share, reveals that 96% of EMEA financial services organisations still feel their current level of data resilience falls short.<\/p>\n\n\n\n<p>The survey, which gathered insights from senior IT decision-makers at financial services companies in the UK, France, Germany and the Netherlands, underscores the ongoing challenges faced by the sector as it adapts to DORA \u2013 a framework introduced by the EU in January 2025 to strengthen the financial industry\u2019s defences against cyberthreats and ICT disruptions.<\/p>\n\n\n\n<p>While DORA has been embedded as a strategic priority across the financial sector, many organisations are still navigating the path to full compliance. The survey found that 94% of organisations now rank DORA higher in their priorities than they did in the month before the deadline, with 40% calling it a current \u201ctop digital resilience priority.\u201d Half of respondents said DORA requirements have been integrated into broader resilience programmes, while 39% reported it remains a central focus.<\/p>\n\n\n\n<p><strong>The unintended consequences of DORA<\/strong><\/p>\n\n\n\n<p>Even with 94% of organisations clear on the steps they need to take, many are facing unforeseen challenges:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>41% report increased stress and pressure on IT and security teams<\/li>\n\n\n\n<li>37% are dealing with higher costs passed on by ICT vendors<\/li>\n\n\n\n<li>22% believe the volume of digital regulation is becoming a barrier to innovation or competition<\/li>\n\n\n\n<li>20% have yet to secure the necessary budget to meet DORA requirements<\/li>\n<\/ul>\n\n\n\n<p>\u201cIt\u2019s promising to see that most organisations have embraced and feel confident about meeting DORA\u2019s requirements,\u201d said Edwin Weijdema, Field CTO EMEA at Veeam. \u201cAchieving compliance is an important first step in ensuring your organisation is resilient but given today\u2019s complex threat landscape there\u2019s more to do. New Veeam research shows that many financial institutions still see a gap in their overall resilience and face challenges in securing the necessary budget, even as DORA grows in strategic importance. The journey to operational resilience is ongoing, and it\u2019s clear that prioritising data resilience remains critical for organisations&#8217; long-term success.\u201d<\/p>\n\n\n\n<p><strong>DORA: Still a work in progress<\/strong><\/p>\n\n\n\n<p>Despite the prioritisation, many organisations are still working to meet key DORA requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>24% have not established recovery and continuity testing<\/li>\n\n\n\n<li>24% have not implemented incident reporting<\/li>\n\n\n\n<li>24% have not identified a DORA implementation lead<\/li>\n\n\n\n<li>23% have not conducted digital operational resilience testing<\/li>\n\n\n\n<li>21% have not ensured backup integrity and secure data recovery<\/li>\n<\/ul>\n\n\n\n<p>The most challenging DORA requirement? Third-party risk oversight, with 34% of organisations citing it as the hardest to implement \u2013 despite only 20% yet to do so. There are many possible reasons for this, from the limited visibility many organisations have into their third-party operations to the sheer scale of third-party networks.<\/p>\n\n\n\n<p>Andre Troskie, Field CISO EMEA at Veeam, said: \u201cIt\u2019s interesting to see that third-party oversight has emerged as a particular pain point for organisations. Over a third named it the most challenging to implement, and many called for additional guidance on establishing it in the first place. An often-overlooked facet of data resilience, it\u2019s promising to see that organisations are interrogating their defences to this degree \u2013 which is exactly what it was designed to do. Of course, meeting the requirements is key, but DORA was also about getting organisations to assess their resilience holistically \u2013 and in that aspect, it seems to be succeeding.\u201d<\/p>\n\n\n\n<p>Additionally, 22% of organisations felt that DORA\u2019s design could have been improved to aid compliance, with calls for simplification, clarification and more detailed third-party risk guidance.<\/p>\n\n\n\n<p><strong>Supporting the journey to resilience<\/strong><\/p>\n\n\n\n<p>In response to the growing need for structured resilience strategies, Veeam and McKinsey earlier this year introduced the industry\u2019s first Data Resilience Maturity Model (DRMM). Built on extensive research and insights from over 500 IT, security and operations leaders, the Veeam DRMM has been validated through real-world customer outcomes. This framework enables organisations to assess their data resilience using a cross-functional approach that integrates IT, security and compliance into a unified strategy.<\/p>\n\n\n\n<p>It provides a clear roadmap for enhancing resilience and achieving compliance with regulations such as DORA.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Veeam survey uncovers top compliance challenges and the urgent need for holistic data resilience, six months after the DORA deadline. Six months after the EU\u2019s Digital Operational Resilience Act (DORA) came into effect, a new Censuswide survey commissioned by Veeam Software, the global leader in data resilience by market share, reveals that 96% of [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":122083,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16061,15994,54,13],"tags":[2424,1530,12032,20001,20000,19660,19999,560,20002,5009,20003,19790,712],"class_list":["post-123024","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-europe","category-middle-east","category-research","category-top-stories","tag-backup-and-recovery","tag-cybersecurity","tag-data-resilience","tag-digital-operational-resilience-act","tag-digital-regulation","tag-dora","tag-eu-compliance","tag-financial-services","tag-ict-resilience","tag-mckinsey","tag-operational-risk","tag-third-party-risk","tag-veeam"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=123024"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123024\/revisions"}],"predecessor-version":[{"id":123025,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123024\/revisions\/123025"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/122083"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=123024"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=123024"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=123024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}