DORA Compliance readiness: Communications is key

The financial sector is almost completely reliant on modern technology for all of its key operations. This clearly makes it highly vulnerable to cyberattacks and means that unintended operational disruptions can have a devastating impact. To focus minds on these risks, the European Union introduced the Digital Operational Resilience Act (DORA) in December 2022, which comes into effect on January 17th 2025. DORA aims, through legislation, to strengthen financial institutions’ ability to withstand, respond to, and recover from digital threats, aiming to create a secure and resilient financial ecosystem across the EU.

What is DORA?

DORA establishes a framework for managing risks related to Information and Communication Technology (ICT) systems, mandating financial institutions to implement strong ICT risk management processes. This ensures that even during severe disruptions, banks, insurers, and other financial services can continue to operate. The regulation focuses on standardising how financial entities manage digital operations, cybersecurity, and third-party service risks.

Key Components of DORA

1. ICT Risk Management: Institutions must implement frameworks to manage ICT-related risks.

2. Third-Party Risk Management: Assess and monitor risks from third-party service providers.

3. Incident Reporting: Institutions must promptly report significant ICT incidents.

4. Resilience Testing: Regular testing for system vulnerabilities is mandatory.

5. Information Sharing: Encourages sharing cyber threat intelligence to improve sector-wide security.

The Impact of DORA

The Digital Operational Resilience Act (DORA) formalises how financial institutions manage and mitigate digital risks. It enforces strict regulations which brings increased accountability across all levels of the organisation, ensuring that institutions are more proactive in identifying, managing, and reporting cyber threats and incidents.

DORA mandates enhanced cybersecurity measures, such as regular risk assessments, advanced data protection protocols, and third-party risk management, to safeguard digital assets and sensitive financial data. Additionally, it requires firms to allocate additional resources—both in terms of technology and human expertise—to ensure full compliance with these standards. 

While this regulatory framework demands upfront investment, it ultimately leads to a more resilient and secure digital infrastructure, helping institutions better withstand cyberattacks, operational disruptions, and technological failures. In turn, this promotes greater trust in the financial sector and improves overall market stability.

Leveraging Salt Communications to meet DORA’s Communications Requirements 

Salt Communications offers secure communication solutions aligned with DORA’s requirements. 

Salt is considered a “safe haven communications system”.  While it can be configured to interact with the major Microsoft services it is sufficiently independent to not rely on the Microsoft environment.  It will remain available if all other services are unavailable and allow key personnel to retain compliant communication in a time of crisis.

Salt Communications offers the following vital capabilities to allow for safe and secure communications at all times:

1. Secure Messaging: Provides end-to-end encrypted messaging to safeguard sensitive communications, aligning with DORA’s ICT risk management and operations security.

2. Secure Live Calls: Encrypted VoIP and conference calling prevent unauthorised interception, supporting digital resilience and risk management.

3. Encrypted File Transfer: Ensures data integrity and confidentiality for sensitive file transfers before, during or when reacting to a crisis.

4. Data retention controls & Compliance Mode: Salt provides data retention controls and a Compliance Mode, enabling organisations to store all messages transmitted through the system in their original encrypted form.

5. Message Broadcasting: Facilitates quick communication via live alerts during ICT incidents, crucial for incident detection and response.  Can be configured to target key teams as a situation is unfolding or can be used company wide after a larger outage (e.g. during a ransomware attack or a catastrophic software update)

6. Screenshot Protection: Increase accountability and prevent unauthorised capture and forwarding of confidential information in order to enhance internal security.

By choosing Salt Communications, financial institutions can meet DORA’s stringent requirements, ensuring robust risk management, secure operations, and effective incident response. Salt’s technology provides a comprehensive solution to help institutions protect sensitive information, mitigate risks, and maintain digital resilience. Simplify DORA compliance with Salt’s secure, customised communication solution.

To learn more about meeting the DORA regulations (effective by January 17th, 2025) or to take advantage of our 30-day free trial, contact us at info@saltcommunications.com to connect with our team.

About Salt Communications:

Salt Communications is a multi-award winning cyber security company providing a fully enterprise-managed software solution giving absolute privacy in mobile communications. It is easy to deploy and uses multi-layered encryption techniques to meet the highest of security standards. Salt Communications offers ‘Peace of Mind’ for Organisations who value their privacy, by giving them complete control and secure communications, to protect their trusted relationships and stay safe. Salt Communications is headquartered in Belfast, N. Ireland, for more information visit Salt Communications.

Share This Post

Explore More