This webinar focuses on achieving compliance with the EU’s Digital Operational Resilience Act (DORA) using automated security validation. It explains the urgency of DORA timelines and the requirement for financial entities to operationalize cyber resilience, including processes, tooling, and evidence that security controls work in practice. The discussion outlines DORA’s five pillars: ICT risk management, ICT incident reporting, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management, and information sharing. It also highlights that while many institutions may be mature in ICT risk management, they often face gaps in incident management, third-party oversight, and resilience testing capabilities.
The session maps these pillars to continuous validation practices, emphasizing the need for repeatable, production-like testing rather than point-in-time assessments. It discusses validating segmentation, encryption-in-transit, identity and access controls, and SOC detection and response through realistic red, blue, and purple team exercises. The overarching theme is using automation to accelerate DORA compliance by continuously validating controls and providing evidence-backed assurance rather than relying solely on documentation or periodic reviews.