Faced with Dora, the financial sector searches for routine
By Camille Frati, Lex Kleren Switch to French for original article
Now that Dora – the European regulation on digital resilience – has come into force, the financial sector seems to have completed the bulk of the work. It is now focusing on integrating Dora's requirements into its day-to-day operations as seamlessly as possible. And that is no mean feat.
No mobile network, no internet, no access to the 112 emergency number: for nearly eight hours on 23 July 2025, several thousand Post customers – including businesses – were left without any means of communication. The major outage was caused, as revealed a few days later, by a DDoS (distributed denial-of-service) cyberattack, and aimed at disrupting the operation of the infrastructure rather than stealing data.
The day after this major outage, the Financial Sector Supervisory Commission (CSSF) issued a scathing statement. "Following recent events that have attracted the attention of the public and the media, the CSSF wishes to remind all supervised entities of their obligation to report any ICT-related incident in accordance with the applicable provisions set out in CSSF Circular 25/893 and/or CSSF Circular 24/847", stated the regulator. "Supervised entities are strongly advised to review the applicable provisions carefully in order to fully understand their notification obligations."
You want more? Get access now.
-
One-year subscription€185.00/year
-
Monthly subscription€18.50/month
-
Zukunftsabo for subscribers under the age of 26€120.00/year
Already have an account?
Log in