Continuity, Recovery & Resilience under DORA
DORA does not promise incidents will never happen. It requires financial entities to keep delivering through them: that is operational resilience, and business continuity is its engine.
Three terms, clearly separated
| Term | Meaning |
|---|---|
| Business continuity (BC) | Keeping critical functions running, or restoring them fast, through any disruption. |
| Disaster recovery (DR) | The ICT-specific recovery of systems, data and infrastructure after a disruption. |
| Operational resilience | The overarching DORA goal: absorb, adapt and recover from any ICT disruption. |
DR is a subset of BC; BC is the operational core of resilience. A continuity plan that ignores ICT recovery is incomplete; a DR plan with no business framing is just a server runbook.
Where DORA places continuity
ICT business continuity sits inside Pillar 1: the ICT risk management framework. Art. 11 and Art. 12 require response and recovery, an ICT business continuity policy, backup and restoration procedures, and (crucially) that all of it is tested.
Why DORA raised the bar
Continuity planning is not new, banks and insurers have had BC plans for decades. What DORA changes is the rigour: continuity must be specific to critical or important functions, the recovery objectives must be defined and defensible, the plans must be tested on a programme rather than written and shelved, and the management body is accountable for all of it. A continuity capability that would have passed a 2015 audit will not necessarily satisfy a DORA supervisor.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate, with lifetime access.
Secure payment via Stripe · full refund within 14 days if under 20% of the course has been accessed.