Skip to content
Digital, Innovation, Payments

From compliance to resilience: what DORA is teaching us

Published on 05 October 2026

Recent coverage in the Lëtzebuerger Journal and Paperjam has highlighted how Luxembourg’s financial sector is moving from implementing DORA to making operational resilience part of day-to-day business. The first lessons are emerging: resilience is increasingly an ecosystem challenge, and cooperation can help achieve demanding regulatory objectives without unnecessary duplication.

Summary

    Recent articles in the Lëtzebuerger Journal and Paperjam have highlighted a new phase in the implementation of the Digital Operational Resilience Act (DORA). Eighteen months after the regulation entered into application, the focus is gradually shifting from understanding and implementing new requirements to integrating them into everyday operations.

    Speaking to the Lëtzebuerger Journal, Ananda Kautz, Member of the Management Board of the ABBL, described this transition: after considerable work on governance, testing programmes and mapping technological dependencies, financial institutions are increasingly focused on embedding DORA into their processes.

    Beyond implementation, however, the experience accumulated so far is beginning to reveal broader lessons about what operational resilience actually meansn, and how it can be strengthened.

    Resilience does not mean zero incidents

    One of those lessons is that the number of reported ICT incidents should not be mistaken for a measure of failure.

    As Ananda Kautz explained to the Lëtzebuerger Journal, the purpose of DORA is precisely to ensure that incidents are detected and reported.

    The figures also challenge a common perception of digital resilience. According to CSSF data cited by Delano, 81% of reported incidents in Luxembourg were not the result of malicious activity. Service-provider failures, problems arising from IT changes and human error all feature prominently.

    The European picture points in the same direction. Data quoted by the Lëtzebuerger Journal shows that system failures accounted for 51% of major ICT-related incidents across the EU, compared with 10% attributed to cybersecurity. Two thirds of major incidents resulted in either no disruption or only minor disruption for customers and transactions.

    Operational resilience therefore goes well beyond cybersecurity. It is about ensuring continuity when technology, processes, infrastructure or external providers fail.

    81%

    of reported incidents in Luxembourg were not the result of malicious activity. Service-provider failures, problems arising from IT changes and human error all feature prominently.

    A resilient bank is not one that never experiences a major incident, but one that is able to detect and contain it, restore its activities and learn from what happened.

    Ananda Kautz

    Member of the Management Board of the ABBL

    Resilience is an ecosystem challenge

    This is particularly important when looking at third-party dependencies.

    More than a quarter of the ICT incidents analysed in Luxembourg originated with service providers. As Ananda Kautz noted, this demonstrates the need for cooperation: financial institutions remain responsible for their resilience, but they are not necessarily the source of all the incidents affecting them.

    Third-party concentration risk is not a new concern. It was already identified during the preparation of DORA. What the first period of implementation is now providing is a much clearer picture of how these dependencies materialise in practice.

    DORA is helping financial institutions better understand and map these dependencies. But it is also raising a practical question: when several institutions depend on the same provider and need to assess largely the same risks and controls, does this necessarily require each of them to perform the same exercise separately?

    From regulatory obligation to collective solution

    The mutualised ICT audit coordinated by the ABBL involving six financial institutions and LuxTrust provides one possible answer.

    Rather than conducting several separate audits of the same provider covering largely similar areas, the participating institutions developed a common set of requirements and carried out a mutualised audit process. Each institution subsequently received its own report.

    The approach reduces duplication and costs for financial institutions, limits the operational burden on the provider and allows expertise to be pooled around a common audit scope. The CSSF told the Lëtzebuerger Journal that it had no objection to such an approach, provided that each participating entity ensures that the audit covers its individual needs and follows up individually on any necessary actions.

    Mutualisation does not mean less control, nor does it dilute individual responsibility. What can be mutualised is the process, not the responsibility of each institution to understand and manage its own risks.

    The detailed findings of the audit remain confidential, as they would for individual ICT audits, particularly as they may contain sensitive information about IT systems, security measures and controls. The initiative itself, however, has been public from the outset: the ABBL and LuxTrust presented the approach in June.

    And the approach is not unique. As highlighted by both recent media reports, Finance & Technology Luxembourg is developing a standardised supplier due-diligence questionnaire to avoid service providers having to provide largely identical information in multiple formats. Different initiatives, but the same underlying logic: where requirements overlap, cooperation and standardisation can reduce unnecessary work without weakening oversight.

    A practical lesson for smarter regulation

    The experience of DORA therefore carries a broader lesson.

    Simplification should not mean lowering standards. It should mean finding the most effective way of achieving regulatory objectives while removing complexity and duplication that do not contribute to better outcomes.

    This is also at the heart of the ABBL’s wider advocacy for a more proportionate, coherent and risk-based European regulatory framework. Europe does not have to choose between resilience and competitiveness. Effective regulation should support both.

    Sometimes this will require better rules. Sometimes greater standardisation. And sometimes, as the LuxTrust audit demonstrates, it will mean institutions working together rather than carrying out the same exercise several times in parallel.

    The participating institutions have already indicated their willingness to explore similar approaches with other shared providers.

    That may ultimately be one of DORA’s most useful lessons: in an increasingly interconnected financial system, resilience cannot always be built institution by institution. Where risks and dependencies are shared, cooperation can help deliver stronger oversight, greater efficiency and a more resilient financial ecosystem.

    Ananda Kautz

    Ananda Kautz

    Member of the Management Board of the ABBL

    Published on 05 October 2026