Continuity, Recovery & Resilience under DORA
DORA does not promise incidents will never happen. It requires financial entities to keep delivering through them — that is operational resilience, and business continuity is its engine.
Three terms, clearly separated
| Term | Meaning |
|---|---|
| Business continuity (BC) | Keeping critical functions running — or restoring them fast — through any disruption. |
| Disaster recovery (DR) | The ICT-specific recovery of systems, data and infrastructure after a disruption. |
| Operational resilience | The overarching DORA goal — absorb, adapt and recover from any ICT disruption. |
DR is a subset of BC; BC is the operational core of resilience. A continuity plan that ignores ICT recovery is incomplete; a DR plan with no business framing is just a server runbook.
Where DORA places continuity
ICT business continuity sits inside Pillar 1 — the ICT risk management framework. Art. 11 and Art. 12 require response and recovery, an ICT business continuity policy, backup and restoration procedures, and — crucially — that all of it is tested.
Why DORA raised the bar
Continuity planning is not new — banks and insurers have had BC plans for decades. What DORA changes is the rigour: continuity must be specific to critical or important functions, the recovery objectives must be defined and defensible, the plans must be tested on a programme rather than written and shelved, and the management body is accountable for all of it. A continuity capability that would have passed a 2015 audit will not necessarily satisfy a DORA supervisor.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.