New research commissioned by Orange Cyberdefense shows that 92% of UK financial services institutions think that a UK equivalent to DORA would help ensure digital resilience.
The survey, conducted by Censuswide with 200 UK CISOs and senior security decision-makers, also reveals that most financial services firms must reevaluate how they assess third-party risk. Nearly six in 10 (58%) large UK financial services firms suffered at least one third-party supply chain attack in 2024, with 23% being targeted three or more times.
Just under half (44%) of financial services institutions only assess third-party risk during the initial supplier onboarding stage, while a similar proportion (41%) perform periodic risk assessments. Crucially, just 14% follow the gold standard of continuously assessing risk and using dedicated third-party risk management tools.
The impact of these different approaches on digital resilience is clear. In 2024, 68% of those who only assessed risk during the onboarding phase suffered a supply chain attack, dropping to 57% for those who periodically assessed and 32% for those who assessed continuously and employed risk management technologies. These data points indicate a clear cause-and-effect relationship: the more frequently organizations assess risk, the less frequently they suffer supply chain attacks. What then needs to change to encourage more financial services organizations to employ more robust risk assessment practices?
Regulation for digital resilience
In the last few years, the EU has introduced a host of new cybersecurity regulations, including the Cyber Resilience Act, EU AI Act, Network and Information Systems Directive 2 (NIS2), and, most recently, the Digital Operational Resilience Act (DORA).
Despite the compliance difficulties that new regulations often pose for businesses, most UK FS cybersecurity professionals (74%) say the EU’s security posture and policies rank better than many other economic regions. Subsequently, as highlighted above, 92% of respondents to the survey would like the UK to adopt a country-wide regulation similar to DORA to ensure digital resilience in the financial sector.
In fact, many UK cybersec professionals are concerned that, following Brexit, gaps are emerging between the UK and the European Union on cybersecurity regulation:
- Over three-quarters (77%) perceive a gap between the effectiveness of regulatory deterrents
- Similarly, 74% are concerned that confidence in UK regulation is dropping
- 72% worry that UK regulation is becoming less comprehensive
- 76% are concerned that UK authorities (e.g. government and regulatory bodies) aren’t providing enough support and guidance.
Despite concerns that the UK could struggle to keep pace with the EU on regulation, senior cybersecurity professionals are currently taking an optimistic stance. Over half (55%) are encouraged, excited, confident or optimistic about the current state of UK cybersecurity regulation.






