Finanssivalvonta

Application of DORA has started – FIN-FSA to focus on the management of ICT risks and cyber-threats in its supervision

Share

The objective of DORA (Digital Operational Resilience Act) is to improve consumers’ data security and the continuity of services. It brings about significant reforms in the operational resilience of the financial sector and covers almost all entities supervised by the FIN-FSA.

The Regulation of the European Parliament on digital operational resilience for the financial sector entered into force on 17 January 2023 and applies from 17 January 2025. DORA (Digital Operational Reliability Act) applies extensively to financial market participants in the EU, such as banks, insurance companies, investment firms and ICT companies providing services to them. In its supervision, the FIN-FSA will focus on the management of supervised entities’ ICT and information security risks, the ICT incident reporting process and the supervision of ICT providers’ risk management. 

– DORA introduces uniform and transparent rules for the financial sector which are necessary to ensure that institutions in the sector can effectively identify, address and prevent various digital threats. In the current global situation, these threats are very real, states Samu Kurri, Head of Department.

All entities within the scope of application of the Regulation will have a new requirement to report annual costs caused by ICT-related incidents. The Regulation also enables the voluntary exchange of information on cyber threats between supervised entities and the reporting of cyber threats to the supervisory authority. Furthermore, supervised entities are obliged to submit a register of ICT contracts to the FIN-FSA on an annual basis. 

The FIN-FSA has obliged the most significant supervised entities to perform threat-led penetration tests at regular intervals. 

– For instance significant banks, the stock exchange and the central securities depository are directly compelled by DORA to perform these threat-led data security tests. However, we have also obliged smaller banks and insurance-sector participants to engage in these tests in Finland. By doing so, we foster the achievement of cyber security in the financial sector on an extensive scale, says Kurri.

In Finland, DORA applies to over 400 supervised entities. There is no transitional period for the application of the Regulation, which means that the requirements must be complied with from 17 January 2025.

See also

Regulation on the digital operational resilience of the financial sector – DORA (in Finnish)

For further information, please contact

Samu Kurri, Head of Department. Requests for interviews are coordinated by FIN-FSA Communications, tel. +358 9 183 5030 (weekdays 9.00–16.00). 

Keywords

Contacts

Media phone service number

can be contacted on weekdays 9–16, except on Holy Thursday and New Year’s Eve on 9–13.

Tel:+358 9 183 5030

Finanssivalvonta, or the Financial Supervisory Authority (FIN-FSA), is the authority for supervision of Finland’s financial and insurance sectors. The entities supervised by the authority include banks, insurance and pension companies as well as other companies operating in the insurance sector, investment firms, fund management companies and the Helsinki Stock Exchange. We foster financial stability and confidence in the financial markets and enhance protection for customers, investors and the insured.

Alternative languages

Subscribe to releases from Finanssivalvonta

Subscribe to all the latest releases from Finanssivalvonta by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Finanssivalvonta

Regleringen av kryptotillgångstjänster skärptes i och med MiCA-förordningen – konsumenterna bör fortfarande vara vaksamma3.4.2025 10:00:00 EEST | Pressmeddelande

EU:s förordning om marknader för kryptotillgångar (MiCA) tillämpas nu fullt ut, vilket skärper regleringen av kryptotillgångstjänster och harmoniserar marknadsföringen. Övergångsperioden i Finland hör till de kortaste i Europa. Konsumenterna bör fortfarande vara på sin vakt när de köper tjänster, eftersom MiCA-förordningen inte avlägsnar alla risker som hänför sig till kryptotillgångar. Finansinspektionen behandlade aktuella tillsynsteman på sin presskonferens på torsdagen.

Kryptovarapalveluiden sääntely kiristyi MiCA-asetuksen myötä – kuluttajien edelleen syytä olla tarkkana3.4.2025 10:00:00 EEST | Tiedote

EU:n kryptovaramarkkinoita koskevan asetuksen (MiCA) täysimääräinen soveltaminen on alkanut, mikä tiukentaa kryptovarapalveluiden sääntelyä ja yhtenäistää markkinoita. Suomessa siirtymäaika on yksi lyhyimmistä Euroopassa. Kuluttajien on edelleen syytä olla tarkkana palveluita hankkiessaan, sillä MiCA-asetus ei poista kaikkia kryptovaroihin liittyviä riskejä. Finanssivalvonta kävi läpi ajankohtaisia valvontateemoja lehdistötilaisuudessaan torstaina.

Requirements for crypto-asset services have tightened with the MiCA Regulation – consumers still need to be careful3.4.2025 10:00:00 EEST | Press release

The full application of the EU Regulation on Markets in Crypto-Assets (MiCA) has begun, tightening regulation of crypto-asset services and harmonising the market. Finland has one of the shortest transitional periods in Europe. Consumers still need to be careful when purchasing services, as the MiCA Regulation does not eliminate all the risks associated with crypto-assets. The Financial Supervisory Authority (FIN-FSA) reviewed topical supervisory themes at its press conference on Thursday.

Muistutuskutsu: Finanssivalvonnan lehdistötilaisuus torstaina 3.4. finanssisektorin tilasta ja riskeistä – erityisteemoina kiinteistöriskit, rahastosektori sekä kryptovarapalveluiden valvonta1.4.2025 08:50:00 EEST | Kutsu

Kutsumme median edustajat ajankohtaistilaisuuteen, jossa käsittelemme erityisesti kiinteistösektorin riskien näkymistä valvonnassa, rahastosektorin tilannetta sekä alkavaa kryptovarapalveluiden valvontaa. Tilaisuudessa käydään läpi myös finanssisektorin taloudellista tilaa ja riskejä eri valvontasektoreilla.

Kutsu medialle: Finanssivalvonnan lehdistötilaisuus torstaina 3.4. finanssisektorin tilasta ja riskeistä – erityisteemoina kiinteistöriskit, rahastosektori sekä kryptovarapalveluiden valvonta27.3.2025 10:00:00 EET | Kutsu

Kutsumme median edustajat ajankohtaistilaisuuteen, jossa käsittelemme erityisesti kiinteistösektorin riskien näkymistä valvonnassa, rahastosektorin tilannetta sekä alkavaa kryptovarapalveluiden valvontaa. Tilaisuudessa käydään läpi myös finanssisektorin taloudellista tilaa ja riskejä eri valvontasektoreilla.

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye