Financial Firms Rework Multi-Cloud Networks for DORA Crypto Shift
The European Union’s Digital Operational Resilience Act, or DORA, creates a common framework for managing information and communications technology risk across banks, insurers and investment firms while tightening oversight of critical third-party providers. The rules matter for multi-cloud operators because keys, certificates and encrypted connections are spread across vendors and regions. A poorly managed cryptographic upgrade can disrupt critical services, turning a security project into a compliance and business-continuity failure.
DORA entered into force on Jan. 16, 2023, and became applicable on Jan. 17, 2025. The migration challenge has sharpened since the US National Institute of Standards and Technology issued three post-quantum standards — FIPS 203, 204 and 205 — on Aug. 13, 2024. The latest architecture guidance calls for mapping cryptographic dependencies, supporting hybrid algorithms, staging deployments and maintaining cross-cloud failover and rollback capacity so encryption can change without interrupting regulated services. No transaction value is associated with the development.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.