AFM, the Dutch Authority for the Financial Markets, has issued ‘Getting ready for DORA: Testing of the digital operational Resilience’, a guide which focuses on ICT testing regimes.
To ensure effective digital operational resilience it is important that ICT systems, tools, and processes are regularly tested to expose any vulnerabilities and deficiencies. Regular testing also provides assurance that operational resilience plans and strategies will actually work during an incident.
Articles 24 through 27 (Chapter IV) of the DORA Regulation describe the requirements for testing of digital operational resilience and regulated organizations will need to develop tests, practices, methodologies, and tools for compliance.
In addition, a number of organizations will be designated to conduct advanced testing by means of threat-led penetration testing (TLPT) once every three years. The guide looks at expectations in this area.






