The Digital Operational Resilience Act (DORA) represents a decisive turning point for the financial sector: the goal is no longer just to prevent cyberattacks, but to ensure the continuity of services even in the event of incidents or failures. Operational resilience thus becomes the central parameter, to be validated through a testing program defined in Article 25, which goes far beyond ordinary technical checks and requires advanced resilience tests: scenario-based tests, end-to-end tests, and performance tests.
Why DORA goes beyond vulnerability testing
Traditional tests, such as vulnerability assessments or penetration tests (pentests), are often limited to analyzing individual systems or isolated environments. DORA, however, requires validating the financial entity’s ability to withstand and respond to real ICT disruptions. The objective is not just to detect a single software flaw, but to ensure that critical or important functions (CIFs) remain operational even in the presence of vulnerabilities or incidents at third-party providers.
Scenario-based tests on severe but plausible events
The scenario-based tests provided for by DORA involve simulating disruptions based on severe but realistic scenarios. Financial entities must identify various exposure scenarios for their ICT assets, including:
- Direct cyberattacks: simulations of techniques adopted by real malicious actors.
- Technological switchovers: switching tests from primary ICT infrastructure to redundant capacity, backups, or secondary facilities to verify the timeliness of recovery.
- Critical malfunctions: situations where the quality of a critical function is reduced to an unacceptable level or fails completely.
End-to-end tests on processes and dependencies
End-to-end testing according to DORA involves validating the entire supply chain of a business process, including every relevant dependency. The fundamental points of these tests are:
- Attack path mapping: description of a potential attack from its entry into the systems to the compromise of the final target.
- Involvement of third-party providers: for outsourced critical functions, tests must include the services of ICT providers and sub-providers to verify the resilience of the entire ecosystem.
- Interdependencies: analysis of how the failure of a technological component can have a cascading impact on other functions of the organization.
Performance tests and operational robustness
Within the DORA framework, performance tests do not just measure software speed, but certify operational robustness under stress conditions. Entities are required to:
- Subject ICT systems to extreme stress conditions to identify critical breaking points.
- Manage capacity and performance: identify capacity requirements to prevent shortages that could disrupt services.
- Verify that systems supporting critical functions maintain availability and integrity standards even during load peaks or in the presence of incidents.
How to select scenarios
The selection of scenarios must follow a risk-based approach:
- Business Impact Analysis (BIA): tests must reflect the results of the BIA and asset classification.
- Relevance and plausibility: priority for scenarios with a high probability of occurrence or significant systemic/reputational impact, even if rare.
- Threat Intelligence: scenarios are informed by the most recent cyber threats and lessons learned from historical incidents.
FAQ
- Are they an alternative to pentesting?
- No. These tests complement the security program: while a pentest detects vulnerabilities, scenario-based testing evaluates the response and recovery capacity of the entire organization.
- Should providers be involved?
- Yes. For outsourced critical functions, DORA requires that tests include third-party services and that contracts explicitly provide for the cooperation of providers in security testing.
- How to choose priority scenarios?
- Prioritize scenarios related to functions whose interruption would have the greatest impact on financial stability, continuity of customer services, and the entity’s reputation.
Beyond technical compliance: design your resilience testing plan today to validate the robustness of your end-to-end processes according to DORA criteria.
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
