Home / Companies / Evervault / Blog / Post Details
Content Deep Dive

Did DORA’s last update create an encryption loophole?

Blog post from Evervault

Post Details
Company
Date Published
Author
John Hetherton
Word Count
1,622
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Digital Operational Resilience Act (DORA) is a comprehensive set of European Union regulations designed to enhance the security of financial institutions' information and communication technology (ICT) systems, aiming to prevent breaches and safeguard them from cyber threats. Implemented in stages from 2022 to 2024, DORA encompasses various aspects such as testing, information sharing, third-party risk management, and incident response, with a strong emphasis on data encryption. The legislation mandates encryption for data at rest and in transit, and while it recommends encryption for data in use, it acknowledges its current impracticality, allowing for alternative protective measures like trusted execution environments. DORA's broad applicability includes banks, investment firms, crypto companies, and third-party service providers, though some exemptions apply to smaller firms. While some criticize its vagueness, this flexibility allows the legislation to adapt to evolving security practices and technological advancements. The final compliance deadline is set for January 17, 2025, and organizations are encouraged to collaborate with DORA-compliant vendors to meet these standards, thereby avoiding fines and enhancing their cybersecurity posture.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.