Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

DORA and third-party ICT risk: what financial teams must change


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: DORA creates a single EU cyber resilience framework for financial entities and their critical third-party ICT providers, with 24-hour, 72-hour, and 30-day incident reporting expectations plus mandatory resilience testing, according to Expel. The practical shift is from ad hoc security oversight to documented, auditable operational resilience across the supplier chain.

NHIMG editorial — based on content published by Expel: DORA compliance, third-party ICT risk, and operational resilience

By the numbers:

Questions worth separating out

Q: What breaks when third-party access is not lifecycle managed?

A: Access outlives accountability.

Q: Why does DORA make access governance a resilience issue?

A: DORA ties operational resilience to the ability to withstand, respond to, and recover from ICT disruptions.

Q: How do financial firms know whether identity controls are strong enough for DORA?

A: Look for evidence, not policy language.

Practitioner guidance

  • Map DORA obligations to identity control owners Assign specific owners for access governance, privileged access, supplier identity oversight, incident evidence, and reporting timelines so each DORA pillar has a named operational accountable party.
  • Inventory third-party identities and remote access paths Build a complete register of supplier accounts, API tokens, support channels, and admin access, then require offboarding and monitoring evidence for every one of them.
  • Centralise identity telemetry for incident reporting Ensure directory logs, privileged session records, cloud auth events, and SaaS access logs can be queried together so the 24-hour and 72-hour reporting windows are achievable.

What's in the full article

Expel's full analysis covers the operational detail this post intentionally leaves for the source:

  • The regulation’s full list of affected financial entities and third-party ICT providers, including the supply-chain scope that determines who must comply
  • The 24-hour, 72-hour, and 30-day incident reporting timelines in context, including what each report must contain
  • The five DORA pillars with the practical cyber and governance obligations mapped to each one
  • The article’s discussion of contractual supplements and how a third-party provider aligns to DORA requirements

👉 Read Expel's analysis of DORA compliance, third-party ICT risk, and incident reporting →

DORA and third-party ICT risk: what financial teams must change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

DORA pushes identity governance into resilience governance. The regulation is not just about cyber controls in the abstract. It makes access visibility, incident traceability, and third-party accountability part of a financial entity’s resilience posture. For identity teams, that means IAM, PAM, and supplier access controls are now evidence-bearing controls, not just operational hygiene.

A question worth separating out:

Q: Who is accountable when supplier access is abused in a breach?

A: Accountability sits with the organisation that granted the access and with the supplier governance process that failed to constrain it. If a third-party platform can be abused to expose customer data, then access scope, offboarding, and monitoring were not aligned to the relationship. IAM and third-party risk teams should review supplier access as a lifecycle control, not a one-time approval.

👉 Read our full editorial: DORA turns third-party cyber risk into a compliance requirement



   
ReplyQuote
Share: