Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
Hameed Shuja4 min read
Julie DiMauro2 min read
Hameed Shuja3 min read
EU DORA RTS - third party contractual arrangements - Art 8
DORA Article 30(2)-(3) outlines the minimum elements that must be included in any contractual arrangements on the use of ICT services:
The policy needs to specify that the contractual arrangements must include:
The final responsibility for inspection, audit and testing rests with the financial entity who can employ the following in order to carry these out:
The financial entity cannot only rely on third party certification or reports supplied by the ICT third-party service provider and these can only be used if the financial entity:
Any material changes to these arrangements must be:
By all parties
Your DORA questions answered – Business resilience more broadly
This fifth of a series of articles covering a practical session organised by Ashurst focuses on business resilience questions connected to DORA.
Thomas Hyrkiel3 min read
Your DORA questions answered – CIFs
This third of a series of six articles covering a practical session organised by Ashurst focuses on critical or important functions.
Thomas Hyrkiel4 min read
Your DORA questions answered – Extraterritoriality and interaction with existing rules
This last of a series of six articles covering a practical session organised by Ashurst focuses on how DORA will interact with existing rules as well as its extraterritorial effects.
Thomas Hyrkiel3 min read
Technology
Your DORA questions answered – Business resilience more broadly
Technology
Your DORA questions answered – CIFs
Technology
Your DORA questions answered – Extraterritoriality and interaction with existing rules
In this second part of our discussion with Lafond, he refers to internal threats, side-channel attacks, vendor risks and having a well-equipped incident response plan and team.
Julie DiMauro10 min read
With DORA now in effect, the EU’s financial sector is entering a new phase of operational resilience obligations, where firms must shift from preparation to action.
Nathaniel Lalone | Katten, Ciara McBrien | Katten5 min read
The absence of a transitional period presents a challenge for firms and third parties.
Thomas Hyrkiel2 min read
Experts from Morgan Stanley, BNY, Nomura and First Abu Dhabi Bank discussed this key issue at the leading compliance industry event.
Alex Viall4 min read
Regulatory preparedness, resilience and evolving challenges among the topics covered in an insightful and data-rich document.
Thomas Hyrkiel3 min read
Developments include: potential standardization of threat-led penetration testing, new oversight director for DORA and ESA's work program.
Nathaniel Lalone | Katten, Ciara McBrien | Katten3 min read
Although non-mandatory and applicable to regulated entities in Germany the practical guidance offers helpful insight into key aspects of the new regime.
Thomas Hyrkiel1 min read
Increasing reliance on digital platforms and a growing threat from bad actors means regulators are giving more attention to cybersecurity compliance.
Further Reading