DORA Podcast Series

Welcome to our new podcast series, where we hope to help you navigate the requirements of the Digital Operational Resilience Act (DORA)

14 November 2024

Publication

Episode 1: Lessons from the Crowdstrike outage: what would happen under DORA

In this episode, our partners Hinal Patel, Sophie Sheldon (London), and Camille Saettel (Luxembourg) explore the necessary actions companies must undertake following a Crowdstrike-style IT outage under DORA, effective 17 January 2025. They will guide listeners through the process, from initial response strategies and regulatory notifications to mitigation efforts and post-incident analysis. Tune in as our team dissects DORA's requirements, providing key insights and advice for financial institutions dealing with IT disruptions in the digital era.

Episode 2: RTS on classification of major incidents under DORA

In this episode, partner Derek Lawlor provides a summary of the final draft RTS on classification of major incidents and significant cyber threats.

Episode 3: RTS specifying policy on ICT services supporting critical or important functions

In this episode, partner Hinal Patel provides a summary of the final draft RTS specifying the policy on ICT services supporting critical or important functions.

Episode 4: RTS on ICT Risk Management Frameworks

In this episode, partner Eric Le Quellenec provides a summary of the final draft RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework.

Episode 5: RTS on subcontracting ICT services supporting critical or important functions

In this episode, partner Cathrine Foldberg Møller and associate Maya Coumes provide a summary of the final draft RTS on subcontracting ICT services supporting critical or important functions.

Episode 6: RTS on Threat-Led Penetration Testing (TLPT)

In this episode, partners Derek Lawlor and Sophie Sheldon provide a summary of the final draft RTS on Threat-Led Penetration Testing (TLPT), including some key principles when thinking about the robust requirements set by DORA.

Episode 7 – RTS on major incident reporting under DORA

In this episode, partners Christopher Götz and Jaap Templeman discuss the final report on the RTS for major incident reporting, detailing the content and timelines for notifications and reports of major ICT-related incidents.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.