Cybersecurity1 min readSample article
DORA, one year on: where insurers still fall short
Most insurers now have a DORA programme. Fewer can show that their critical suppliers, their tests and their incident reporting actually work together.
Trivick editorial team
The Digital Operational Resilience Act has applied since January 2025. The policies are written and the registers of ICT suppliers are filled in. The harder part is proving that it all holds up on a bad day.
Three gaps we keep finding
- Supplier registers that list contracts, but not which business services depend on them
- Resilience tests that stay inside IT and never involve the business or the suppliers
- Incident classification that works on paper but takes too long under pressure
Where to start
Pick your two most important business services and trace them end to end: systems, data, people and suppliers. Test that chain, not the individual parts. It shows the gaps faster than any questionnaire.
A register tells you who your suppliers are. A test tells you whether you can live without them for a day.