Research for Orange Cyberdefense has found that 43% of the UK’s financial services organizations are expected to miss the Digital Operational Resilience Act (DORA) deadline when the European Union’s regulation takes effect on January 17th. 20% expect to not be fully compliant for at least a further four months.
While DORA applies to financial entities and critical third-party service providers operating within the EU, if a UK-based financial entity operates in the EU (e.g., through branches, subsidiaries, or cross-border services), it must comply with DORA requirements for its EU activities.
The research, conducted by Censuswide using a survey of 200 UK CISOs and senior security decision-makers, reveals that the majority of senior security professionals see the value in the EU’s efforts to strengthen the financial sector’s resilience against digital threats. Nearly 9 in 10 (88%) believe that DORA will be beneficial, and even more (96%) say it will significantly enhance overall resilience across the EU and the EU business ecosystem.
Despite this positive sentiment, several barriers to compliance persist. The challenges described by security professionals are varied, emphasising that these barriers are organization-specific, rather than broader issues with the compliance process. These include a lack of prioritisation from the wider organization (28%), a short timeline to becoming compliant (25%), a lack of skills/knowledge (24%), and a lack of visibility over supply chain/third-party partners (23%). To overcome these challenges, the vast majority (97%) of respondents either employ (78%) or plan to employ (19%) external support to help their business become compliant with DORA.
Compliance budgets
Typically, budgetary constraints have been a significant hurdle for cybersecurity teams to overcome. However, 84% of respondents felt that their organization had made more than enough budget available to become compliant with DORA. This marks a departure from the norm, with limited budgets and the turbulent economic situation often cited as problematic by senior cybersecurity professionals.
To meet compliance requirements, 78% of respondents reallocated the budget from other business areas, and 48% reallocated staff members from other projects. Although budgetary constraints aren’t currently ranked highly as a barrier to compliance, 66% of CISOs and senior security decision-makers believe that DORA will significantly increase cybersecurity costs in the long term.
About the study
Censuswide conducted this research on behalf of Orange Cyberdefense up to January 2nd, 2025. The survey included 200 CISOs and senior security decision-makers from financial services companies with more than 1,000 employees in the UK.






