What is DORA and why it applies to insurers
The Digital Operational Resilience Act (DORA) is a European Union regulation that came into effect on January 17, 2025. It covers all financial sector entities — including insurance undertakings, reinsurance undertakings, insurance intermediaries, and institutions for occupational retirement provision.
DORA establishes uniform ICT risk management frameworks across the entire financial sector. For insurers, this means meeting specific requirements across five key pillars: ICT risk management, incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing on cyber threats.
For insurers across Europe, DORA creates a comprehensive regulatory framework requiring a systematic approach to digital resilience that goes beyond previous national requirements and guidelines.
Pillar 1 — ICT risk management
DORA requires insurers to implement comprehensive ICT risk management frameworks. This means identifying all ICT assets supporting critical business functions — from core insurance systems through claims management to customer portals and broker integrations.
The insurer must maintain an up-to-date ICT asset register, regularly conduct risk assessments, and implement appropriate protection measures. Special attention must be paid to systems processing sensitive data — medical data in health insurance, financial data in property policies.
The management body is directly responsible for approving and overseeing ICT risk management frameworks. This means board members must possess adequate knowledge of digital threats or ensure access to competent advisory services.
Pillar 2 — ICT incident reporting
DORA establishes a unified system for reporting major ICT incidents. Insurers must classify incidents according to defined criteria covering: number of affected clients, duration, geographic scope, financial losses, and data impact.
Major incidents must be reported to the competent supervisory authority within strict timeframes: initial notification within 4 hours of incident classification, intermediate report within 72 hours, and final report within one month.
For insurers, this requires implementing automated incident classification systems and escalation processes. SOC systems must be configured so that incidents affecting critical insurance systems are automatically flagged as potentially reportable under DORA.
Pillar 3 — digital operational resilience testing
DORA mandates regular digital resilience testing. All insurers are required to conduct: ICT vulnerability assessments, network security tests, performance tests, scenario-based tests, and source code reviews.
Additionally, insurers designated as significant financial entities must conduct advanced Threat-Led Penetration Testing (TLPT) every three years. TLPT simulates real attack scenarios based on the current threat landscape specific to the insurance sector.
Tests must be conducted by independent parties with appropriate competencies. Test results and remediation plans must be reported to supervisory authorities. For many insurers, this requirement means engaging external cybersecurity partners with sector-specific expertise.
Pillar 4 — ICT third-party risk management
The insurance sector is heavily dependent on ICT providers — from core insurance systems through claims management platforms to cloud and analytics service providers. DORA introduces rigorous requirements for managing this risk.
Insurers must maintain a register of ICT provider agreements, conduct due diligence before signing contracts, implement exit strategies in case of provider changes, and monitor contract performance. Contracts must include security clauses, audit rights, and incident reporting provisions.
Specific requirements apply to critical service providers. If a claims management or core insurance system provider is designated as a critical ICT third-party provider, it becomes subject to additional supervisory requirements from European Supervisory Authorities (ESAs).
Pillar 5 — threat information sharing
DORA encourages financial entities to share information about cyber threats and vulnerabilities. For the insurance sector, this is particularly important because attacks on one insurer often signal a campaign targeting the entire industry.
Insurers can establish threat information sharing arrangements within trusted communities. Sharing encompasses indicators of compromise (IoCs), attacker tactics, techniques, and procedures (TTPs), and lessons learned from incidents.
Industry associations can play a coordinating role in such information exchange. Active participation in threat intelligence sharing significantly elevates the security posture of the entire insurance sector and helps individual companies prepare for emerging threats.
Implementation timeline and penalties
DORA has been in effect since January 17, 2025. Insurers that have not yet adapted their systems and processes face sanctions. Penalties for non-compliance can reach up to 1% of average daily global turnover for each day of violation.
Supervisory authorities have broad powers — from ordering specific remediation actions, through imposing financial penalties, to restricting operations. For insurers, the regulatory risk is real and demands urgent action.
An implementation plan should include: gap analysis of the current state versus DORA requirements, prioritization of gaps, implementation of missing controls and processes, and regular reviews and updates of ICT risk management frameworks.
How nFlo supports insurers with DORA implementation
nFlo offers comprehensive support for DORA implementation in the insurance sector. We conduct gap analyses identifying areas requiring adaptation and design ICT risk management frameworks tailored to insurance-specific needs.
We deliver required digital resilience tests — from vulnerability assessments to advanced TLPT. Our SOC provides 24/7 monitoring with automated incident classification aligned with DORA reporting requirements.
We also support ICT third-party risk management — from provider security audits to contract reviews. With over 500 cybersecurity projects completed, nFlo understands both regulatory requirements and operational realities of the insurance sector.
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
