Reimagining Cyber - real world perspectives on cybersecurity · Reimagining Cyber

DORA's First Year: What Happened? - #189

February 18, 2026·20 min·1 clip
Dom Brown says willful DORA noncompliance could cost 1% to 2% of annual sales.
1. Reimagining Cyber revisits DORA, the EU's Digital Operational Resilience Act, after its January 2025 application in financial services. 2. Rob Borrego hosts the episode, and Dominic Brown of Graveslight Consulting returns because he previously explained DORA and now tracks its first year in force. 3. The episode asks what DORA has actually changed after a year of implementation, rather than what DORA is in theory. 4. Brown says DORA is designed to reduce cyber and resilience risk in EU financial services after the rapid digital transformation of the pandemic. 5. He says cyber attacks on European financial services more than doubled during the pandemic, which helped motivate the regulation. 6. Brown describes the scope as broad because DORA covers ICT systems, meaning information communication technology used to deliver ongoing digital or data services. 7. He explains that firms must identify critical or important functions, called CIFs, and the ICT systems that support those functions. 8. Brown distinguishes level one rules from level two implementation standards and says the CIF requirements sit at the center of the level two work. 9. He lists five pillars: ICT risk governance, incident reporting, resilience testing, third-party risk management, and information sharing. 10. Brown says DORA is unusual because it treats ICT risk as a systemic threat to the entire EU financial system, not just to single firms. 11. He notes that DORA reaches third-party ICT vendors and their subcontracting chains, including providers outside the EU such as American technology companies. 12. Brown says firms have been slow to build DORA frameworks because the level-two standards were published only in mid-2025. 13. He says governance maturity is still weak in many firms because boards and senior management have not fully developed ICT risk oversight. 14. Brown says some organizations have cybersecurity and resilience controls on paper that do not work in practice. 15. He says regulators have been patient so far, no one has been penalized, and supervisors are expected to demand more tangible progress in 2026. 16. Brown explains threat-led penetration testing as intelligence-led red team testing that runs end-to-end attack simulations on production systems. 17. He says the test targets the people, processes, and technologies supporting CIFs and can include six months of preparation followed by 12 weeks of live testing. 18. Brown says the process uses a regulator test manager, a firm control team, external threat intelligence, external red team testers, and a blue team defending without advance notice. 19. Brown says year two should bring more active supervision of critical third-party providers, more data-driven oversight, and more attention to contractual exit rights. 20. Brown says firms that ignore DORA risk enforcement, while listeners interested in EU financial regulation, operational resilience, and cyber governance will get the most from the discussion. 11. Brown says fintechs and private equity groups are using DORA-style security and information-gorvernance transparency as a competitive differentiator for investors.

As heard by us

A practical look at how DORA has changed day-to-day cyber resilience work after implementation.

Reimagining Cyber frames DORA as an operating question rather than a headline, focusing on what has shifted a year into implementation. It stays close to the practical work: testing, regulator involvement, remediation, and the way financial firms are being pushed to turn…

Read the full review in PlayNext →

Why you'd press play

See what DORA changed after a year into implementation.

Read the full recommendation in PlayNext →
Listen to the show on