How Salt Communications Supports Compliance with DORA Regulations

As financial institutions prepare to comply with the Digital Operational Resilience Act (DORA), finding the right technology partners is essential to ensure adherence to the regulation’s stringent requirements. Salt Communications provides secure communication solutions tailored to meet the specific mandates outlined in DORA and the accompanying RTS (Regulatory Technical Standards) on ICT risk management.

Salt’s Marketing Manager Nicole Heron, sat with Paul C Dwyer from the ICTTF to discuss where the overlap is between Salt’s current capabilities and the DORA Regulatory requirements.

This is a summary of that discussion:

1. Secure Messaging

DORA Requirement: ICT risk management framework, ICT operations security, ICT and information security awareness and training.

Value Proposition: The Salt Communications App offers private, real-time messaging and group chat with end-to-end encryption, ensuring that sensitive communications remain secure and inaccessible to unauthorised users. By safeguarding internal communications, Salt supports the ICT operations security mandates within DORA and contributes to the broader ICT risk management framework.

2. Secure Voice Calls

DORA Requirement: ICT risk management framework, ICT operations security.

Value Proposition: With secure encrypted one-to-one and conference calling, Salt ensures that financial institutions’ voice communications are protected from interception and eavesdropping. This feature enhances the overall ICT risk management framework by ensuring critical communications remain available, even when all other systems are under attack or unavailable.

3. Encrypted File Transfer

DORA Requirement: ICT risk management framework, encryption and cryptography, ICT operations security.

Value Proposition: Salt’s encrypted file transfer capabilities allow for the secure transmission of confidential documents, images, videos and data. This ensures compliance with DORA’s encryption and cryptography requirements by protecting the integrity and confidentiality of data in transit, thus addressing critical aspects of ICT operations security.

4. Data Retention Control Feature

DORA Requirement: ICT risk management framework, ICT operations security.

Value Proposition: The message burn feature, which allows users to manually or automatically delete sensitive messages from all devices, helps mitigate the risk of data breaches and unauthorised access. This feature enhances ICT operations security, reducing the risk of information leakage and helping financial institutions manage sensitive data more securely. It is possible to retain a secure copy of messages, when required, for regulatory purposes.

5. Message Broadcasting

DORA Requirement: ICT risk management framework, ICT-related incident detection and response, communication strategy for ICT-related incidents.

Value Proposition: Salt’s message broadcasting feature enables institutions to disseminate live alerts, messages, images, and documents to large groups during ICT-related incidents, playing a crucial role in effective incident response and communication. It helps institutions meet the requirements of DORA’s Article 14, which focuses on incident detection, management, and response, ensuring teams are quickly informed during disruptions. Urgent messages on Salt are never missed, even overriding silent or “do not disturb” settings when necessary. Salt will also integrate with third-party systems to automatically trigger alerts when an issue is detected, thus improving response efficiency.

6. Screenshot Protection

DORA Requirement: ICT risk management framework, ICT operations security.

Value Proposition: The screenshot protection feature restricts users from capturing sensitive communications via screenshots. In cases where a screenshot is taken, Salt notifies the relevant users, adding another layer of protection against unauthorised data capture. This feature aligns with DORA’s ICT operations security requirements, ensuring that confidential communications remain private and protected.

Specific Alignment with DORA and RTS Documents

The Salt Communications App provides a comprehensive suite of features that map directly to the specific controls mandated by DORA and the associated RTS on ICT risk management:

– ICT Risk Management Framework: Salt Communications strengthens financial institutions’ ICT risk management frameworks by securing communication channels, preventing data leaks, and enhancing control over sensitive communications (Articles 5-16).

– ICT Operations Security: Features like secure messaging, encrypted voice calls, and screenshot protection ensure that institutions’ communication systems adhere to DORA’s ICT operations security requirements (Articles 5-16).

– Encryption and Cryptography: By facilitating encrypted file transfers, Salt ensures compliance with DORA’s encryption and cryptography mandates, safeguarding the confidentiality and integrity of data both in transit and at rest (Articles 5-16).

– Incident Detection and Response: The app’s message broadcasting feature supports Article 14 of DORA by enabling institutions to quickly and securely communicate during ICT-related incidents, improving response times 

Salt Communications and DORA RTS Compliance

The Digital Operational Resilience Act (DORA) establishes comprehensive requirements to enhance the digital operational resilience of financial entities within the European Union. The accompanying Regulatory Technical Standards (RTS) provide detailed specifications to operationalize these requirements. Salt Communications offers secure communication solutions that align with several mandates outlined in the RTS, thereby facilitating compliance with DORA.

1. ICT Risk Management Framework

RTS Mandate: Financial entities are required to implement robust ICT risk management frameworks that ensure the security and resilience of their ICT systems. 

Salt Communications’ Contribution: Salt’s encrypted messaging and voice call features provide secure channels for internal and external communications, mitigating risks associated with data breaches and unauthorized access. By integrating Salt’s solutions, financial institutions can enhance their ICT risk management frameworks, ensuring that sensitive information remains confidential and secure.

2. ICT Operations Security

RTS Mandate: Entities must establish security measures to protect ICT systems and data from cyber threats and ensure operational continuity. 

Salt Communications’ Contribution: Salt’s secure messaging, voice calls, and encrypted file transfer capabilities ensure that all forms of communication are protected against interception and unauthorized access. Features like message burn and screenshot protection further enhance data security by preventing unauthorized retention and sharing of sensitive information. These functionalities support the RTS requirements for ICT operations security by safeguarding communication channels.

3. Incident Detection and Response

RTS Mandate: Financial entities are required to establish mechanisms for detecting, managing, and reporting ICT-related incidents promptly. 

Salt Communications’ Contribution: Salt’s message broadcasting feature enables institutions to disseminate live alerts and critical information swiftly during ICT-related incidents. This capability facilitates effective incident response and communication, ensuring that all relevant parties are informed in a timely manner, thereby aligning with the RTS mandates on incident detection and response.

4. ICT Third-Party Risk Management

RTS Mandate: Entities must manage risks associated with ICT third-party service providers, ensuring that these providers adhere to security standards. 

Salt Communications’ Contribution: By offering a secure communication platform, Salt enables financial institutions to maintain control over their data and communications, even when interacting with third-party service providers. This control is crucial for managing third-party risks and ensuring that all communications comply with the institution’s security policies and the RTS requirements.

In summary, Salt Communications’ solutions provide financial institutions with the tools necessary to meet specific mandates outlined in the RTS under DORA. By securing communication channels, enhancing incident response capabilities, and managing third-party risks, Salt supports institutions in achieving compliance with DORA’s comprehensive digital operational resilience requirements.

Strategic Integration into ICT Risk Management Frameworks

Salt Communications’ secure communication solutions align with the strategic goals of ICT risk management frameworks by enhancing control, confidentiality, and availability of communication channels, which are critical to an organisation’s resilience against cyber threats.

Key Strategic Contributions:

  • Alignment with Governance Policies: Salt’s encrypted messaging and secure voice calls ensure that internal and external communications are protected in compliance with DORA mandates, fostering trust and reliability within the organisation.
  • Support for Regulatory Reporting: Features like secure message broadcasting and data retention controls streamline communication during regulatory audits, incident reporting, and stakeholder updates.
  • Risk Mitigation and Resilience Planning: By securing communication channels, Salt supports the development of robust risk mitigation strategies and continuity planning.

Hypothetical Scenario: Secure Incident Response During a Cyberattack

Imagine a European bank, “ACMECORP Bank”, that is targeted by a sophisticated cyberattack. The attack disrupts the bank’s online banking services and potentially exposes sensitive customer data. Under DORA, ACMECORP Bank is obligated to respond quickly and effectively to this incident.

Here’s how Salt Communications’ tools, as a secure communication platform, could help ACMECORP Bank meet DORA requirements:

  • Secure Communication Channels: During the cyberattack, ACMECORP Banks usual communication channels, like email or standard messaging apps, could be compromised. Salt Communications provides a highly resilient Secure Communication Channel, ensuring the secure flow of information amongst the incident response team, senior management, and even third-party ICT providers. This secure channel allows for real-time coordination without the risk of data breaches or interference from the attackers.
  • Guaranteed Message Delivery and Acknowledgment: With features that override do not disturb and silent settings on user devices, Salt ensures that critical messages reach their intended recipients immediately. This is crucial for coordinating a rapid and effective response to a critical incident. The system can also provide confirmation that messages have been received and read, ensuring accountability and timely action.
  • Secure Collaboration with Third-Party Providers: ACMECORP Bank’s likely relies on third-party ICT providers for various services. Salt Communications facilitates secure communication with these providers, crucial for DORA compliance in third-party risk management. This enables the bank to coordinate incident response efforts with its providers while maintaining data security and confidentiality.
  • Incident Reporting and Documentation: Salt’s platform could integrate with ACMECORP Bank’s incident reporting system. All communications related to the incident would be securely logged and time-stamped, creating a comprehensive audit trail. This documentation is essential for demonstrating compliance with DORA’s incident reporting requirements.

By using Salt Communications’ tools, ACMECORP Bank can:

  • Maintain operational continuity during the cyberattack, mitigating the impact on customers and financial markets.
  • Respond to the incident rapidly and effectively, minimizing data loss and potential financial damage.
  • Comply with DORA’s stringent incident reporting requirements, avoiding potential penalties.

Overall, Salt Communications’ solutions help financial institutions like ACMECORP Bank strengthen their digital operational resilience and enhance compliance with the DORA framework.

“In the era of digital operational resilience, secure communication solutions like those offered by Salt Communications are indispensable for organisations striving to meet the stringent requirements of DORA while safeguarding their critical assets and data integrity.”

— Paul C Dwyer, Founder and President, ICTTF

Salt Communications is here to help you navigate the challenges of regulatory compliance and protect your organisation’s critical information assets. As financial institutions prepare for the upcoming DORA regulations, the Salt team is ready to assist. Contact us at info@saltcommunications.com.

About Salt Communications:

Salt Communications is a multi-award winning cyber security company providing a fully enterprise-managed software solution giving absolute privacy in mobile communications. It is easy to deploy and uses multi-layered encryption techniques to meet the highest of security standards. Salt Communications offers ‘Peace of Mind’ for Organisations who value their privacy, by giving them complete control and secure communications, to protect their trusted relationships and stay safe. Salt Communications is headquartered in Belfast, N. Ireland, for more information visit Salt Communications.   

About ICTTF:

The ICTTF – International Cyber Threat Task Force was established in 2010, as a not for profit initiative promoting the ecosystem of an International independent non-partisan cyber security community.

Over that decade, they have consistently innovated on how best to achieve our mission. From online community portals, apps, local membership chapters and international events we strive to work with our thousands of members from around the world.

References:

https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-first-set-rules-under-dora-ict-and-third-party

Share This Post

Explore More