Application of DORA has started – FIN-FSA to focus on the management of ICT risks and cyber-threats in its supervision
The objective of DORA (Digital Operational Resilience Act) is to improve consumers’ data security and the continuity of services. It brings about significant reforms in the operational resilience of the financial sector and covers almost all entities supervised by the FIN-FSA.
The Regulation of the European Parliament on digital operational resilience for the financial sector entered into force on 17 January 2023 and applies from 17 January 2025. DORA (Digital Operational Reliability Act) applies extensively to financial market participants in the EU, such as banks, insurance companies, investment firms and ICT companies providing services to them. In its supervision, the FIN-FSA will focus on the management of supervised entities’ ICT and information security risks, the ICT incident reporting process and the supervision of ICT providers’ risk management.
– DORA introduces uniform and transparent rules for the financial sector which are necessary to ensure that institutions in the sector can effectively identify, address and prevent various digital threats. In the current global situation, these threats are very real, states Samu Kurri, Head of Department.
All entities within the scope of application of the Regulation will have a new requirement to report annual costs caused by ICT-related incidents. The Regulation also enables the voluntary exchange of information on cyber threats between supervised entities and the reporting of cyber threats to the supervisory authority. Furthermore, supervised entities are obliged to submit a register of ICT contracts to the FIN-FSA on an annual basis.
The FIN-FSA has obliged the most significant supervised entities to perform threat-led penetration tests at regular intervals.
– For instance significant banks, the stock exchange and the central securities depository are directly compelled by DORA to perform these threat-led data security tests. However, we have also obliged smaller banks and insurance-sector participants to engage in these tests in Finland. By doing so, we foster the achievement of cyber security in the financial sector on an extensive scale, says Kurri.
In Finland, DORA applies to over 400 supervised entities. There is no transitional period for the application of the Regulation, which means that the requirements must be complied with from 17 January 2025.
See also
Regulation on the digital operational resilience of the financial sector – DORA (in Finnish)
For further information, please contact
Samu Kurri, Head of Department. Requests for interviews are coordinated by FIN-FSA Communications, tel. +358 9 183 5030 (weekdays 9.00–16.00).
Keywords
Contacts
Media phone service number
can be contacted on weekdays 9–16, except on Holy Thursday and New Year’s Eve on 9–13.
Finanssivalvonta, or the Financial Supervisory Authority (FIN-FSA), is the authority for supervision of Finland’s financial and insurance sectors. The entities supervised by the authority include banks, insurance and pension companies as well as other companies operating in the insurance sector, investment firms, fund management companies and the Helsinki Stock Exchange. We foster financial stability and confidence in the financial markets and enhance protection for customers, investors and the insured.
Alternative languages
- FIN: Finanssisektorin digitaalista häiriönsietokykyä koskevan asetuksen soveltaminen alkoi – Finanssivalvonta keskittyy valvonnassaan ICT-riskien ja kyberuhkien hallintaan
- SWE: Tillämpningen av förordningen som gäller digital operativ motståndskraft för finanssektorn inleddes – Finansinspektionen fokuserar i sin tillsyn på hanteringen av IKT-relaterade risker och cyberhot
Subscribe to releases from Finanssivalvonta
Subscribe to all the latest releases from Finanssivalvonta by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Finanssivalvonta
Muistutuskutsu medialle: Finanssivalvonnan ja Kyberturvallisuuskeskuksen lehdistötilaisuus torstaina 23.1. – aiheena kyberturvallisuus finanssisektorilla ja sen valvonta21.1.2025 08:30:00 EET | Kutsu
Tervetuloa Finanssivalvonnan ja Traficomin Kyberturvallisuuskeskuksen yhteiseen lehdistötilaisuuteen torstaina 23.1.2025 klo 13. Tilaisuudessa käsitellään ajankohtaisia kyberturvallisuusuhkia ja sitä, miten kyberturvallisuutta valvotaan finanssisektorilla. Juuri voimaan tullut ja satoja toimijoita Suomessa koskeva DORA-asetus tuo myös mukanaan merkittäviä uudistuksia finanssisektorin digitaaliseen toimintavarmuuteen.
Betydande fastighetsrisker in den finansiella sektorn i Finland – starka buffertar skyddar mot riskerna8.1.2025 08:30:00 EET | Pressmeddelande
Läget och utvecklingen i fastighetsbranschen har väsentlig betydelse för det finansiella läget och riskerna i den finansiella sektorn i Finland, då banker, försäkrare och fastighetsfonder har betydande exponeringar mot fastighetssektorn. En svagare utveckling än väntat i omvärlden och fastighetsbranschen skulle således kunna öka kredit-, placerings- och likviditetsriskerna betydligt. De finansiella aktörerna i Finland har dock buffertar mot fastighetsrisker, vilket stärker aktörernas riskhanteringsförmåga.
Merkittävät kiinteistöriskit Suomen finanssisektorilla – vahvat puskurit suojaavat8.1.2025 08:30:00 EET | Tiedote
Kiinteistöalan tilanteella ja kehityksellä on olennainen merkitys Suomen finanssisektorin taloudelliselle tilalle ja riskeille, sillä pankeilla, vakuuttajilla ja kiinteistörahastoilla on merkittäviä altistumia kiinteistösektorille. Toimintaympäristön ja kiinteistöalan ennakoitua heikompi kehitys voisi näin ollen kohottaa merkittävästi luotto-, sijoitus- ja likviditeettiriskejä. Suomen finanssisektorin toimijoilla on kuitenkin puskureita kiinteistöriskien varalta, mikä parantaa toimijoiden riskinkantokykyä.
Significant real estate risks in the Finnish financial sector – mitigated by strong buffers8.1.2025 08:30:00 EET | Press release
The situation and development of the real estate sector has a material impact on the financial position and risks of the Finnish financial sector, since banks, insurers and real estate funds have significant exposures in the real estate sector. Weaker-than-expected development of the operating environment and the real estate sector could therefore significantly increase credit, investment and liquidity risks. However, entities operating in the Finnish financial sector have buffers for real estate risks, which improves their risk-bearing capacity.
Påföljdsavgift för tre fysiska personer för dröjsmål med anmälan om transaktioner utförda av personer i ledande ställning12.12.2024 14:00:00 EET | Pressmeddelande
Finansinspektionen har påfört Ari Lehtoranta, Michael Piccirillo och en närstående till en person i ledande ställning en påföljdsavgift för försummelse att anmäla transaktioner för egen räkning till emittenten och Finansinspektionen inom utsatt tid. Transaktionsanmälan ska göras utan dröjsmål och senast tre arbetsdagar efter transaktionen. Dröjsmålen har samband med Lehtorantas ledande ställning i Orion Oyj och Piccirillos ledande ställning i Bioretec Oy.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom