Did DORA’s last update create an encryption loophole?
Blog post from Evervault
The Digital Operational Resilience Act (DORA) is a comprehensive set of European Union regulations designed to enhance the security of financial institutions' information and communication technology (ICT) systems, aiming to prevent breaches and safeguard them from cyber threats. Implemented in stages from 2022 to 2024, DORA encompasses various aspects such as testing, information sharing, third-party risk management, and incident response, with a strong emphasis on data encryption. The legislation mandates encryption for data at rest and in transit, and while it recommends encryption for data in use, it acknowledges its current impracticality, allowing for alternative protective measures like trusted execution environments. DORA's broad applicability includes banks, investment firms, crypto companies, and third-party service providers, though some exemptions apply to smaller firms. While some criticize its vagueness, this flexibility allows the legislation to adapt to evolving security practices and technological advancements. The final compliance deadline is set for January 17, 2025, and organizations are encouraged to collaborate with DORA-compliant vendors to meet these standards, thereby avoiding fines and enhancing their cybersecurity posture.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.