Gavin Williams’ Post

View profile for Gavin Williams, graphic

Technology Transformation Leader

Useful read from Tim Wright below. What is interesting is that DORA is not a fundamentally onerous piece of policy. It's a good guidance for organisations to help themselves check if they are managing risk and operational continuity well. One area which seems to get a little more (disproportional?) visibility, not necessarily from the article but in general, is the idea of vendor concentration risk for cloud. If the Broadcom acquisition of Vmware has shown us anything, it's that we may focus too much on the e.g. 7% risk in a hyperscaler CSP, but not enough on the e.g. 52% risk on smaller software platforms, or even e.g. 41% risk on older mainframe platforms where few of the people working in the company today were even alive when the systems were coded.

View organization page for Fladgate LLP, graphic

9,822 followers

A new era of Digital Operational Resilience for Financial Services approaches, what should financial services firms and their ICT providers do now? Until now, EU firms have lacked clear regulatory guidance on how to effectively evaluate and mitigate ICT risk, leading to inconsistent approaches, and unpredictable and uneven supervision amongst regulators. To address these challenges, the EU has introduced the Digital Operational Resilience Act (DORA), a comprehensive regulatory framework aimed at strengthening the digital resilience of the EU’s financial sector. Partner Tim Wright breaks down the key pillars of DORA and the main considerations for financial services firms and their ITC providers. You can read the full piece here: https://lnkd.in/eMzE9g4n 

  • No alternative text description for this image
Tim Wright

IT, Digital, AI, Outsourcing and Commercial Lawyer

2w

Thanks for sharing Gavin

To view or add a comment, sign in

Explore topics