DORA Digital Operational Resilience Testing for Financial Entities

Testing di Resilienza Operativa Digitale DORA per Entità Finanziarie

Regulation (EU) 2022/2554, known as DORA (Digital Operational Resilience Act), imposes a harmonized framework for digital operational resilience on European financial entities. The regulation does not exclusively require Red Teaming tests like TLPTs, but rather a structured series of testing and monitoring activities that involve all ICT systems and tools.

Digital operational resilience testing in DORA

Digital operational resilience testing is the fourth pillar of DORA and ensures that financial entities are capable of withstanding, responding to, and recovering from ICT threats and disruptions. The framework provides uniform criteria for the security of networks and information systems, applicable to over 20 different types of financial entities within the EU. The stated goal is the prevention and mitigation of cyber threats through constant validation of defenses.

Basic testing and TLPT: differences and scope

DORA distinguishes between routine checks and advanced tests:

  • Basic testing (Articles 24 and 25): Mandatory for almost all financial entities. These involve broad checks on ICT tools and systems. They represent the minimum requirement for assessing the robustness of defenses.
  • TLPT (Threat-Led Penetration Testing – Article 26): Advanced tests, based on intelligence and designed to simulate tactics used by real malicious actors. They are mandatory only for entities considered systemically important or with specific risk profiles, and they must be performed on real, live production systems.

The checks required by Article 25

Article 25 of DORA lists the types of tests that must make up the financial entities’ verification program:

  • Source code review: Source code revisions with both static and dynamic tests.
  • Security testing for exposed systems: Security tests dedicated to applications and systems accessible via the internet.
  • Vulnerability assessment: A transparent structure for the identification, management, and resolution of vulnerabilities.
  • Software package testing: Security checks prior to the implementation of new software packages.
  • Impact and compatibility analysis: Tests that ensure new ICT systems do not introduce vulnerabilities into existing processes.

Responsibilities, approach, and tester requirements

Financial entities must adopt a risk-based view, calibrating the resources used according to the criticality of ICT assets and business processes. Tests must be conducted by functions other than those responsible for the development or operation of the systems. Testers, whether internal or external, must demonstrate suitability, reputation, and certified technical skills. For TLPTs, it is mandatory to use threat intelligence providers that are independent of the bank or financial group.

Required frequency for critical systems

  • Vulnerability scanning: For ICT assets supporting critical or important functions, vulnerability scanning must be performed at least weekly.
  • Business Continuity Plans: ICT business continuity plans must be tested at least once a year or in the event of significant changes.
  • General review: At least once a year, the adequacy of the testing program must be verified against updates to the business strategy.
  • TLPT: Advanced tests must normally be performed every three years, unless otherwise indicated by the competent authority.

Connection between testing, remediation, and governance

The testing program requires financial entities to integrate resilience verification into their governance system. Test results must be documented and analyzed to detect and correct deficiencies through remediation plans that specify actions, responsibilities, and implementation timelines. The management body retains ultimate responsibility for the oversight and approval of tests and risk mitigation plans.

FAQ on DORA and security testing

  • Does DORA always require penetration testing?
  • DORA requires all financial entities to conduct security tests that include checks similar to penetration tests, particularly in the management of vulnerabilities and the security of exposed systems. Advanced penetration testing (TLPT), however, is reserved only for major entities.
  • Does DORA always require TLPT?
  • TLPT is mandatory exclusively for financial entities that are mature from an ICT perspective and have a systemic impact, while authorities may exclude those for whom it is not justified by their risk profile.
  • How often should critical systems be tested?
  • Systems supporting critical functions must undergo vulnerability scanning at least once a week, while general resilience and business continuity tests must be performed at least annually.

Ensure your compliance: request an initial assessment of your DORA testing program to correctly define the verification perimeter for your critical systems.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!