The requirements created by the European Union’s DORA regulation for financial businesses, as well as the new reality surrounding operational resilience, were highlighted during the panel discussion “DORA: Proving Operational Resilience” at the 6th Cyber Security Conference.
The discussion focused on the need for financial institutions to demonstrate, in practice, their ability to respond to and recover from serious digital disruptions. Particular emphasis was placed on the challenges of integrating processes, while the participants also addressed third-party risk management and increasing regulatory oversight.
The discussion was moderated by Konstantinos Koumidis, President of the ISACA Cyprus Chapter. The speakers were Brian Zarb Adami, CEO of CyberSift; Vaike Metzger, Partner Financial Services and Global (Co-)Lead of Integrated Operational Resilience (IOR) Activities at KPMG AG, Germany; and Christos Meletiou, Head of the Supervision of IT Risk & Cyber Resilience Section at the Central Bank of Cyprus. They presented their views on what lies ahead.
Christos Meletiou stressed that the adoption of the DORA regulation sends a clear message that Europe takes the security of the financial sector extremely seriously, thereby strengthening consumer confidence in the market. He also made it clear to third-party technology providers that, if they wish to offer services to financial institutions in the European Union, they too assume specific responsibilities.
Reviewing the regulation’s progress since 2023, he identified three phases: the initial phase of understanding; the full development of frameworks and reporting requirements during 2024 and early 2025; and the current phase of maturity. He concluded that an organisation may have all the required documentation in place, but the real question today is whether these mechanisms work effectively in practice.
Vaike Metzger noted that the level of maturity in implementing DORA varies significantly depending on the country and sector, with the banking sector consistently ahead. By contrast, insurance companies, asset managers and provident funds started later and are facing greater difficulties. A recent KPMG survey found that only 12% of financial institutions assess their level of maturity as very high.
She explained that many large businesses initially approached the regulation in a fragmented manner, through separate departments. This created problems in aligning risks effectively and making decisions. Two years after the framework was introduced, the market is now moving towards a centralised, integrated first-line function to ensure overall resilience.
Adami described a real-life example involving an organisation where all its policies, procedures, contracts and third-party monitoring appeared perfect on paper. However, the breach was detected 19 days after the attackers had actually gained access. When the ransomware group began sending extortion messages, an entirely different reality emerged from the one reflected in the documentation.
He stressed that most organisations are now theoretically mature, but that the time has come for them to prove the effectiveness of what they have written. During a breach, the critical question is not simply which system has been affected, but which specific business service that system supports. In most cases, when companies come under attack, they do not know which critical function is supported by the compromised system.





