Why CIOs must place DORA at the centre of their data centre strategy


Like many regulatory changes, DORA, the Digital Operational Resilience Act, has fundamentally changed how technology and financial services leaders think about critical technology infrastructure and disaster recovery. 

Implemented by the EU in January 2025, it’s a topic of conversation that comes up time and again when I meet with customers and prospects at our European locations, including DC North here in Croatia. Understandably, IT leaders want to know what it entails, how to make sure they are compliant, and importantly, what it means for their data centre strategy. 

My simplified answer usually starts with this: DORA is essentially asking not whether you have a backup and data recovery plan, but whether you can prove your plan is both in place and working. In practice this means whether you can maintain essential business functions during a cyber-attack or system outage. It fundamentally changes the way CIOs need to think about disruption from “how do I protect the business” to, “disruption is likely, how can we become resilient and recover quickly”. It also changes the importance of backup and data resilience from a tick box exercise somewhere in the IT department, to a board level issue with very real financial and legal implications. 

My advice to any CIO at a bank, insurer, investment firm, payments provider or any of the roughly twenty categories of financial entity DORA names, is that DORA is a compliance requirement that needs to be addressed comprehensively and urgently as a business continuity issue. Perhaps more importantly however, and by the nature of how the regulation is designed, it should be placed at the heart of your data centre strategy, as a way of ensuring and maintaining digital sovereignty and control long term. 

It’s an area that is getting increased attention across the EU region. Geopolitical tensions and sophisticated cyber threats are putting more pressure on critical financial institutions to maintain technological control and reduce vendor lock-in with providers that may be subject to laws outside of the region. Asking questions such as, “where does our data legally sit, and under whose jurisdiction, not just which country”, is a good starting point for CIOs to begin addressing both DORA compliance, and digital sovereignty when evaluating current or prospective CTPPs (Critical Third-Party Providers). 

When it comes to data centre strategy, most companies want to understand how to ensure a prospective partner will reduce risk rather than add to it. It’s an important point and one that I am personally being asked more often. 

The honest answer is that it depends on what’s in the contract, and what the audit trail shows.

In the contract, CIOs should look for clear service levels, audit rights, defined cooperation obligations during an incident and a tested exit path. A provider without a genuine exit plan isn’t reducing your risk, it’s simply becoming a lock-in liability that DORA expects you to have already priced in. Similarly, when it comes to auditing, it is evidence not assurance that CIOs should request. A good example of this is making sure your provider can share physical restore logs, not just theoretical ones.  

I also recommend asking whether the provider’s parent entity is reachable under a foreign jurisdiction’s laws, regardless of where the servers physically sit. It’s a build on the question I posed earlier, but an important once given residency and sovereignty are not the same. A natural follow on is then to check who governs access to the backup environment itself, after all, immutability protects data from alteration, but it doesn’t answer who holds the keys.

A partner that can answer these questions without hesitation is reducing your exposure, whereas one that can’t is adding to it, however reassuring the sales conversation sounds.

Since DORA came into effect 18-months ago, it’s clear that it has been designed to reward organisations that treat their infrastructure partners as part of their compliance and business continuity strategy, rather than a line item outside it (as has traditionally been done).

For those worried about whether they are compliant or aren’t sure how to get started, there are a few initial steps you can take to make sure you are on the right footing. These include: 

  1. Scope it properly Confirm exactly which parts of your estate fall under DORA, and whether any also cross into NIS2 territory. Work with both your legal and compliance teams to ensure clarity and alignment on this, before looking at your infrastructure layer.
  2. Test what you already have Run a full restore under real conditions, not a discussion-based walkthrough. The gap between your stated return-to-operations and your actual recovery time is one of the most useful data points you can generate.
  3. Revisit where your recovery data lives Residency isn’t sovereignty. If your provider’s parent company is legally reachable under foreign law, that’s a question worth resolving now, deliberately, rather than inheriting the answer from a decision made years before DORA existed.

With any regulatory changes, we know there is a lot to learn and understand. We’ve written a deep-dive guide that you can check out here. It includes a detailed overview of both DORA and NIS2 regulations along with practical advice on how to become compliant, which you can find here.

Is your disaster recovery strategy ready for DORA?

Explore how DORA and NIS2 are reshaping backup and disaster recovery for regulated organisations.
Read the full guide

Stay ahead of the curve with Ilkari

Sign up to the latest news, cutting-edge insight, product updates and exclusive announcements – delivered straight ot your inbox.