Connect with us

Finance

What is the EU’s Digital Operational Resilience Act? DORA, explained

Published

on

Traffic_analyzer | Digitalvision Vectors | Getty Images

Financial services companies and their digital technology suppliers are under intense pressure to achieve compliance with strict new rules from the EU that require them to boost their cyber resilience.

By the start of next year, financial services firms and their technology suppliers will have to make sure that they’re in compliance with a new incoming law from the European Union known as DORA, or the Digital Operational Resilience Act.

CNBC runs through what you need to know about DORA — including what it is, why it matters, and what banks are doing to make sure they’re prepared for it.

What is DORA?

DORA requires banks, insurance companies and investment to strengthen their IT security. The EU regulation also seeks to ensure the financial services industry is resilient in the event of a severe disruption to operations.

Such disruptions could include a ransomware attack that causes a financial company’s computers to shut down, or a DDOS (distributed denial of service) attack that forces a firm’s website to go offline. 

The regulation also seeks to help firms avoid major outage events, such as the historic IT meltdown last month caused by cyber firm CrowdStrike when a simple software update issued by the company forced Microsoft’s Windows operating system to crash. 

Multiple banks, payment firms and investment companies — from JPMorgan Chase and Santander, to Visa and Charles Schwab — were unable to provide service due to the outage. It took these firms several hours to restore service to consumers.

In the future, such an event would fall under the type of service disruption that would face scrutiny under the EU’s incoming rules.

Mike Sleightholme, president of fintech firm Broadridge International, notes that a standout factor of DORA is that it doesn’t just focus on what banks do to ensure resiliency — it also takes a close look at firms’ tech suppliers.

CrowdStrike global outage shows companies aren't ready: Hitachi Vantara

Under DORA, banks will be required to undertake rigorous IT risk management, incident management, classification and reporting, digital operational resilience testing, information and intelligence sharing in relation to cyber threats and vulnerabilities, and measures to manage third-party risks.

Firms will be required to conduct assessments of “concentration risk” related to the outsourcing of critical or important operational functions to external companies.

These IT providers often deliver “critical digital services to customers,” said Joe Vaccaro, general manager of Cisco-owned internet quality monitoring firm ThousandEyes.

“These third-party providers must now be part of the testing and reporting process, meaning financial services companies need to adopt solutions that help them uncover and map these sometimes hidden dependencies with providers,” he told CNBC.

Banks will also have to “expand their ability to assure the delivery and performance of digital experiences across not just the infrastructure they own, but also the one they don’t,” Vaccaro added.

When does the law apply?

DORA entered into force on Jan. 16, 2023, but the rules won’t be enforced by EU member states until Jan. 17, 2025.

The EU has prioritised these reforms because of how the financial sector is increasingly dependent on technology and tech companies to deliver vital services. This has made banks and other financial services providers more vulnerable to cyberattacks and other incidents.

“There’s a lot of focus on third-party risk management” now, Sleightholme told CNBC. “Banks use third-party service providers for important parts of their technology infrastructure.”

“Enhanced recovery time objectives is an important part of it. It really is about security around technology, with a particular focus on cybersecurity recoveries from cyber events,” he added.

Many EU digital policy reforms from the last few years tend to focus on the obligations of companies themselves to make sure their systems and frameworks are robust enough to protect against damaging events like the loss of data to hackers or unauthorized individuals and entities.

The EU’s General Data Protection Regulation, or GDPR, for example, requires companies to ensure the way they process personally identifiable information is done with consent, and that it’s handled with sufficient protections to minimize the potential of such data being exposed in a breach or leak.

DORA will focus more on banks’ digital supply chain — which represents a new, potentially less comfortable legal dynamic for financial firms.

What if a firm fails to comply?

For financial firms that fall foul of the new rules, EU authorities will have the power to levy fines of up to 2% of their annual global revenues.

Individual managers can also be held responsible for breaches. Sanctions on individuals within financial entities could come in as high a 1 million euros ($1.1 million).

For IT providers, regulators can levy fines of as high as 1% of average daily global revenues in the previous business year. Firms can also be fined every day for up to six months until they achieve compliance.

Third-party IT firms deemed “critical” by EU regulators could face fines of up to 5 million euros — or, in the case of an individual manager, a maximum of 500,000 euros.

Seeing complete disconnect between EU and U.S. bank regulation, says analyst

That’s slightly less severe than a law such as GDPR, under which firms can be fined up to 10 million euros ($10.9 million), or 4% of their annual global revenues — whichever is the higher amount.

Carl Leonard, EMEA cybersecurity strategist at security software firm Proofpoint, stresses that criminal sanctions may vary from member state to member state depending on how each EU country applies the rules in their respective markets.

DORA also calls for a “principle of proportionality” when it comes to penalties in response to breaches of the legislation, Leonard added.

That means any response to legal failings would have to balance the time, effort and money firms spend on enhancing their internal processes and security technologies against how critical the service they’re offering is and what data they’re trying to protect.

Are banks and their suppliers ready?

Stephen McDermid, EMEA chief security officer for cybersecurity firm Okta, told CNBC that many financial services firms have prioritized using existing internal operational resilience and third-party risk programs to get into compliance with DORA and “identify any gaps they may have.”

“This is the intention of DORA, to create alignment of many existing governance programs under a single supervisory authority and harmonise them across the EU,” he added.

Fredrik Forslund vice president and general manager of international at data sanitization firm Blancco, warned that though banks and tech vendors have been making progress toward compliance with DORA, there’s still “work to be done.”

On a scale from one to 10 — with a value of one representing noncompliance and 10 representing full compliance — Forslund said, “We’re at 6 and we’re scrambling to get to 7.”

“We know that we have to be at a 10 by January,” he said, adding that “not everyone will be there by January.”

Continue Reading

Finance

Treasury Yields Rise as Fed Cut Expectations Shift

Published

on

Treasury Yields Rise as Fed Cut Expectations Shift

Fixed-income markets recorded significant re-pricing during the week ending July 25, 2026, as a convergence of strong labor market metrics and surging energy costs drove U.S. Treasury yields higher across all maturities. The benchmark 10-year Treasury yield climbed toward 4.70%, reaching its highest point in several months. Institutional bond investors rapidly adjusted portfolio durations as expectations for near-term interest rate cuts by the Federal Reserve faded in response to inflation concerns.

The upward shift in sovereign yields reflects a broader fundamental reassessment of global monetary policy. Earlier in the quarter, money markets had priced in a series of rate reductions designed to support economic activity. However, with initial jobless claims falling to 187,000 and crude oil breaching $100 per barrel, fixed-income traders are pricing in a ‘higher-for-longer’ interest rate environment. The inversion between short-term Treasury bills and long-term bonds narrowed, indicating a shift toward term premium expansion.

Rising Treasury yields present both challenges and opportunities for institutional wealth managers. While commercial lenders and mortgage origination volumes face headwinds from elevated borrowing costs, fixed-income investors are locking in attractive real yields on high-quality sovereign and investment-grade corporate bonds. Institutional debt issuers, conversely, are recalibrating their capital structures, opting for shorter-term refinancing instruments or private credit facilities to avoid committing to elevated long-term coupon rates.

Navigating the current bond market landscape demands strict duration management and credit selection. Wealth advisors recommend maintaining flexible fixed-income allocations, combining short-duration Treasuries with inflation-protected securities (TIPS) to shield capital against potential energy-driven inflation spikes while earning dependable nominal income.

Continue Reading

Finance

Private Credit Expansion Transforms Corporate Loans

Published

on

Private Credit Expansion Transforms Corporate Loans

Private credit markets reached a pivotal milestone during the week ending July 25, 2026, as non-bank direct lending consortiums captured a record share of middle-market corporate debt originations. With commercial banks maintaining conservative credit standards and public bond yields remaining elevated, corporate borrowers are increasingly turning to private fund managers for customized capital solutions. This expansion marks a permanent structural shift in enterprise finance, establishing private credit as a primary pillar of institutional corporate liquidity.

The acceleration of private credit deals is driven by speed, deal certainty, and flexible terms. Unlike traditional syndicated bank loans that require lengthy underwriting, credit rating approvals, and public roadshows, private direct lenders can structure tailored financing packages within days. Middle-market firms facing upcoming debt maturities are utilizing private debt facilities to execute recapitalizations, strategic acquisitions, and growth capital deployments without risking execution delay in public markets.

However, financial regulators and central bank supervisors are scrutinizing the sector’s rapid growth. Supervisory agencies are evaluating potential systemic risks associated with non-bank leverage, valuation transparency, and liquidity mismatches during economic downturns. Despite regulatory interest, major pension funds, insurance firms, and sovereign wealth entities continue to expand capital allocations to private credit funds, attracted by reliable floating-rate yields that outperform public fixed-income benchmarks.

As private credit matures into a dominant asset class, corporate chief financial officers must evaluate non-bank lenders alongside traditional banking relationships. Direct lending partnerships provide valuable balance sheet resilience, enabling companies to secure flexible financing terms even during periods of public market turbulence.

Continue Reading

Finance

Tokenized Debt Shifts How Corporate Manage Short Term Liquidity

Published

on

Tokenized Debt Shifts Corporate Liquidity

The landscape of institutional debt markets is undergoing a profound structural shift on July 21, 2026, as major corporate issuers and commercial banks rapidly accelerate the deployment of tokenized debt instruments. Data published by leading capital market consortiums indicates that primary issuances of digital commercial paper and tokenized corporate bonds have reached record volumes this month. By moving legacy debt origination, underwriting, and secondary distribution onto permissioned distributed ledgers, corporate treasurers are unlocking unprecedented operational flexibility and instantaneous cross-border liquidity.

The adoption of tokenized debt is fundamentally altering how enterprise balance sheets manage short-term liquidity needs. Traditional corporate bond settlement cycles historically required multi-day clearing processes involving numerous intermediaries, custodial entities, and clearinghouses. Through programmable smart contracts on distributed ledgers, issuers can now execute atomic settlement—enabling continuous, 24/7 access to institutional capital pools. This instantaneous clearing mechanism drastically reduces counterparty risk, eliminates costly settlement friction, and allows treasury teams to dynamically optimize working capital in real time.

A major catalyst driving this institutional migration is the establishment of comprehensive digital asset regulatory frameworks across major financial hubs. Clear legal guidelines regarding ledger-based securities ownership have provided institutional compliance officers with the regulatory confidence necessary to transition multi-billion-dollar liquidity facilities onto digital platforms. Furthermore, the integration of automated regulatory reporting directly into token smart contracts simplifies ongoing compliance audits, ensuring that secondary market trades automatically enforce investor accreditation limits and tax withholding requirements.

For chief financial officers and institutional portfolio managers, tokenized debt represents a fundamental evolution in fixed-income strategy. Companies that embrace ledger-based debt structures gain direct access to a broader, global base of digital-native institutional investors while substantially reducing borrowing overhead. As ledger interoperability continues to improve across global exchanges, tokenized debt is poised to become the standard infrastructure for global corporate finance.

Continue Reading

Trending