According to IBM’s 2024 Cost of a Data Breach report, the average financial-industry breach cost USD 6.08 million, nearly 25% above the global average of USD 4.88 million. At the same time, FINMA’s 2024 annual report recorded a 30% year-over-year increase in cyber incident reports from supervised Swiss institutions. For banks, insurers, asset managers, and healthcare organizations, the regulatory and financial stakes of getting cyber risk wrong have never been more concrete.

Most boards have already decided to act. The real work is choosing where to start and in what order.

What Operational Resilience Actually Means for Regulated Firms

Operational resilience is the demonstrated ability to absorb disruption and continue delivering critical services, even when systems fail or get attacked. That definition is narrower and more demanding than disaster recovery, which focuses on restoring systems after the fact.

Regulators have moved from asking “do you have controls?” to asking “can you prove you’d survive?” That shift changes what firms need to document, test, and report. It also changes who’s accountable: resilience now sits at board level, not just with the CISO.

For financial institutions specifically, this means mapping critical business services end-to-end, setting impact tolerances, and testing whether those tolerances hold under realistic stress scenarios.

DORA: The Regulation That Became Enforceable in January 2025

The EU’s Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) became fully applicable on 17 January 2025. There was no general transitional period. Banks, insurers, investment firms, payment institutions, and crypto-asset service providers operating in the EU were expected to be compliant from that date.

DORA’s requirements fall across four areas:

  • ICT risk management: Firms must maintain a documented ICT risk management framework, including asset inventories, protection measures, and recovery plans.
  • Incident reporting: Major ICT incidents trigger a three-stage reporting obligation: initial report, intermediate update, and final report, each within prescribed time windows.
  • Resilience testing: Significant entities must conduct threat-led penetration testing (TLPT) on an ongoing cycle.
  • Third-party oversight: Firms must maintain a Register of Information covering all ICT third-party contractual arrangements. The first annual submission deadline was 30 April 2025, per European Banking Authority guidance.

National competent authorities can impose periodic penalty payments and require remediation plans for firms that fall short.

FINMA’s Expectations: Governance, Detection, and 24-Hour Reporting

Swiss firms supervised by FINMA operate under FINMA Circular 2023/1 (“Operational risks and resilience – banks”), which entered into force on 1 January 2024 with a two-year transitional period for certain operational resilience requirements.

The circular sets out five binding expectations:

  1. Identify threats
  2. Protect ICT assets and data
  3. Detect attacks through systematic monitoring
  4. Respond and contain incidents
  5. Recover operations promptly

Executive boards must arrange regular vulnerability assessments and penetration tests. Compliance with these requirements is mandatory under FINMA’s supervisory mandate.

FINMA’s supervisory notice 03/2024 added a specific cyber incident reporting requirement: supervised institutions must file an initial report within 24 hours of discovering a reportable cyberattack. FINMA’s 2024 risk monitor identified supply-chain and outsourced-service incidents as accounting for nearly a third of all reported cyber incidents, a finding that directly shapes where firms need to focus their controls.

Third-Party and Supply Chain Risk: Where Most Gaps Are

Both DORA and FINMA Circular 2023/1 place third-party risk at the centre of their supervisory frameworks, treating it with the same rigour as internal ICT controls. That prioritisation reflects what incident data shows: FINMA found that roughly a third of reported cyberattacks reached institutions indirectly, through affected third parties.

DORA requires firms to assess the criticality of each ICT provider, include specific contractual clauses covering audit rights, security requirements, and exit provisions, and track sub-outsourcing chains. The Register of Information must capture all of this at entity, sub-consolidated, and consolidated levels.

For many organizations, the practical problem is that their vendor inventory is incomplete, their contracts predate DORA, and their monitoring of provider security posture is informal. Closing those gaps requires structured assessment work: systematic vendor classification, contract remediation, and ongoing monitoring, built to a documented methodology.

The Sectors Carrying the Most Exposure

Banking and insurance face the most prescriptive requirements under DORA and FINMA Circular 2023/1. Asset managers and healthcare organizations face a different but overlapping set of obligations, including data privacy requirements under the Swiss nFADP (which came into force in September 2023) and sector-specific incident notification rules.

Sophos reported that 65% of financial services organizations were hit by ransomware in 2024, with a mean recovery cost of USD 2.58 million per incident. Healthcare organizations face comparable exposure, with the added consequence that patient data breaches trigger mandatory notification to multiple regulators simultaneously.

Across all these sectors, ENISA analyzed 488 publicly reported incidents affecting European finance from January 2023 to June 2024, of which 432 were active cyberattacks. The real danger in those numbers is concentration: a single compromised cloud provider or payroll processor can affect dozens of regulated firms at once, multiplying the impact of any individual breach.

What a Structured Cyber Risk Advisory Engagement Covers

A well-scoped cyber risk and resilience advisory engagement typically runs in three phases, each building on the last.

Risk assessment comes first. This maps the firm’s critical services, ICT assets, and third-party dependencies against its actual threat profile. The output is a prioritized view of where the firm is genuinely exposed versus where controls are already adequate – grounded in evidence, ready to present to the board.

Gap analysis follows. This compares the current state against the applicable regulatory framework, whether that’s DORA, FINMA Circular 2023/1, NIST CSF, ISO 27001, or CIS Controls. The output is a remediation roadmap with effort estimates and sequencing, specific to the firm’s risk profile and regulatory obligations.

Implementation support is where most programs stall without external help. This covers policy and procedure development, control design and testing, third-party contract remediation, incident response plan development, and preparation for TLPT or regulatory examination. For firms seeking independent assurance, engagements can include ISAE 3000 or SOC 2 readiness work.

A genuine resilience program is measured by one question: what happens when your core banking system goes down at 2 a.m. on a Friday? Firms that can answer that question with documented, tested evidence are the ones that pass regulatory examination.

Common Gaps That Regulatory Examinations Surface

FINMA’s 2024 supervisory findings pointed to recurring weaknesses across supervised institutions:

  • Incomplete asset inventories, particularly for legacy systems and shadow IT
  • Weak detection capabilities, with many firms relying on perimeter controls rather than behavioral monitoring
  • Incident response plans that exist on paper but haven’t been tested under realistic conditions
  • Third-party contracts that lack the audit rights and exit provisions now required under FINMA Circular 2023/1 and DORA

These are the patterns that appear repeatedly in supervisory reviews across the sector. External advisors with sector-specific experience are positioned to find them before the regulator does.

What’s Coming in 2026

DORA’s threat-led penetration testing requirements will move from preparation to active enforcement cycles for significant entities in 2026. The European Supervisory Authorities are also expected to publish updated guidance on the oversight of critical ICT third-party providers, which will tighten concentration risk requirements for firms relying heavily on a small number of cloud or data providers.

In Switzerland, FINMA’s two-year transitional period for the operational resilience components of Circular 2023/1 ends on 1 January 2026. Firms that haven’t yet mapped their critical services, set impact tolerances, and tested their recovery capabilities will face supervisory scrutiny on a compressed timeline.

The firms that will be ready are the ones using 2025 to complete their gap assessments, remediate third-party contracts, and run their first realistic resilience tests – so that 2026 is execution and validation, not catch-up.

Frequently Asked Questions

Does DORA apply to non-EU firms? DORA applies to financial entities operating within the EU, regardless of where they’re headquartered. A Swiss bank with EU branches or subsidiaries needs to assess its DORA obligations for those entities specifically.

What’s the difference between DORA and FINMA Circular 2023/1? DORA is EU law with direct applicability across member states. FINMA Circular 2023/1 is Swiss supervisory guidance with legal force under FINMA’s supervisory mandate. The two frameworks overlap significantly on ICT risk management and third-party oversight, but they’re separate obligations for firms operating in both jurisdictions.

How long does a cyber risk advisory engagement typically take? A risk assessment and gap analysis for a mid-sized financial institution typically takes eight to twelve weeks. Implementation support runs longer, often six to eighteen months depending on the remediation scope and whether the firm is also preparing for independent assurance.

What frameworks do advisors typically use? Engagements generally reference NIST CSF, ISO 27001, COBIT, and CIS Controls alongside the applicable regulatory framework. The goal is to map findings to a framework the firm’s board and regulators both recognize, rather than producing a proprietary scoring system.

When does FINMA’s operational resilience transitional period end? The transitional period for the operational resilience requirements in FINMA Circular 2023/1 ends on 1 January 2026.