Business Continuity Testing and Operational Resilience under DORA

Business Continuity Testing e Resilienza Operativa secondo DORA

The Digital Operational Resilience Act (DORA) introduces a new approach to cybersecurity, shifting the focus from mere perimeter protection to the ability to maintain operations even in the event of incidents. DORA business continuity testing is thus transformed into a structured validation process involving governance, processes, and third-party providers. Delegated Regulation (EU) 2024/1774 describes the criteria under which tests must ensure the compliance of recovery systems with regulatory standards.

Continuity and resilience in DORA

DORA requires financial entities to integrate an ICT business continuity policy into their risk management framework. Business continuity testing under DORA verifies both the validity of response plans and the actual ability to sustain business viability until critical operations are restored.

How to define disruption scenarios

Business continuity tests must be based on severe but plausible disruption scenarios, as established by the regulation:

  • Direct cyberattacks and data corruption.
  • Unavailability of key personnel or physical locations (offices and data centers).
  • Substantial failures of ICT assets or communication infrastructure.
  • Insolvency or failure of critical ICT providers.
  • Extreme external events, such as natural disasters, pandemics, or prolonged power grid outages.

Recovery, failover, backup, and communication testing

  • Backup and restore: Data recovery procedures must be tested at least annually.
  • Technological switchovers: It is necessary to test failover to redundant systems or secondary sites, demonstrating the ability to function in such a mode before returning to normal.
  • Crisis communication: Tests must challenge crisis communication plans, verifying the readiness of information flows to stakeholders and authorities.
  • Critical infrastructure: For CCPs and CSDs, testing must mandatorily include a secondary site with a distinct geographical risk profile.

RTO/RPO: how to interpret them correctly

The regulation clearly distinguishes between recovery requirements:

  • Recovery Time Objective (RTO): For critical functions of CCPs, CSDs, and trading venues, a maximum RTO of 2 hours is imposed. For other entities, the RTO is determined by the Business Impact Analysis (BIA).
  • Recovery Point Objective (RPO): Represents the maximum tolerable data loss; for trading venues, it must be near zero.
  • Registration: Every function supporting critical processes must have its RTO and RPO detailed in the Register of Information.

Dependencies on providers and shared services

DORA highlights the role of the supply chain in operational resilience. Continuity testing must include services provided by third-party ICT providers, with the contractual obligation for providers to participate in security and resilience tests. An assessment of political or jurisdictional risks is also required if the provider manages data in third countries.

FAQ

  • Does DORA always require annual continuity testing?
  • ICT business continuity plans must be tested at least once a year or following significant changes in the infrastructure.
  • Is there a single RTO for all entities?
  • Only market infrastructures (CCPs, CSDs, Trading Venues) must comply with the 2-hour limit. For other entities, the RTO is established internally via the BIA, with justification commensurate with the risk.
  • How can one demonstrate that the plan is realistic?
  • It is necessary to document test results, analyze shortcomings, and present a report to the management body with the corrective actions taken.

Validate your resilience: request the design of a DORA-compliant business continuity testing program to ensure your RTOs and RPOs are realistic and verified.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!