A year of DORA, and the dependency most firms still cannot map

January 15, 2026

The European Union’s Digital Operational Resilience Act has applied since 17 January 2025, so financial entities in scope have now lived with it for close to a year. It reaches beyond those entities to the technology providers they depend on, including providers established outside the European Union.

The requirement that has produced the most work is also the least glamorous. Firms must maintain a register of information covering their contractual arrangements for information and communication technology services, which sounds like an administrative exercise and turns out to be a mapping exercise most organizations had never completed.

A supplier list is not a dependency map

Procurement records answer the question of who the organization pays. Operational resilience depends on a different question, which is what stops working if a given provider stops working, and the two lists overlap far less than people expect.

The gap shows up most clearly in concentration. Four contracts with four vendors can rest on one underlying platform, and nothing in the contracts discloses it, because each vendor is describing its own service rather than its own dependencies. An organization can hold a well-managed supplier portfolio and a single undocumented point of failure at the same time.

This is the value of the register even to organizations the regulation does not cover. It forces the enquiry that nobody schedules, and the answer is frequently uncomfortable enough to justify the effort on its own.

The worked example

On 19 July 2024 a routine update from a single security vendor took more than eight million Windows machines out of service. Airlines stopped flying, hospitals reverted to paper, and payment systems failed, in organizations that had no contractual relationship with each other and no obvious commonality.

Nothing about that incident was an attack, which is the part worth holding onto. The disruption came from a supplier doing what it did every week, and it demonstrated that the resilience question and the security question are not the same question.

A yacht heeling hard in rough open water under a storm sky

Procurement records answer who the organization pays. Resilience depends on what stops working if a given provider does, and the two lists overlap less than most boards expect.

Exit plans that have never been tested

Most organizations hold documented exit arrangements for their material providers, and most of those documents were written to satisfy a checklist rather than to be used. They describe an orderly transition over a period of months, which is a reasonable description of a commercial separation and an unhelpful one for a provider that has become unavailable this morning.

A useful exit plan answers narrower questions. Where does the data physically sit, in what format, and who has tested restoring it somewhere else? What is the minimum viable version of the service, and how long does standing it up actually take when measured rather than estimated?

Those measurements are the substance of business continuity work. An organization that has performed them holds a number it can give a board, and an organization that has not holds a document.

Where to start if the register does not apply to you

  1. List the services that stop the business if they stop, working from the operations outward rather than from the contract file.
  2. For each, identify the provider, then identify what that provider itself depends on, which is the step that surfaces concentration.
  3. Establish the recovery time by testing it once, since an estimate and a measurement differ by more than most people assume.
  4. Record who decides to invoke an alternative, because that decision is usually the slowest part of the response.
A suspension bridge and waterfront under a dark orange smoke-filled sky

The July 2024 outage was not an attack. A routine update from one supplier took more than eight million machines out of service, in organizations with no relationship to one another.

Operational technology is the harder half

Where an organization runs physical processes, the dependency question extends into equipment that was installed to last decades and was never designed to be patched. The systems are less visible than the corporate estate, they are frequently maintained by the vendor rather than by internal staff, and the consequences of an interruption are physical rather than administrative.

A security and safety assessment covering those environments asks different questions from a corporate technology review, and the two are often commissioned by different people who do not compare their findings.

Our Book of the Month shelf has Countdown to Zero Day, which remains the clearest published account of what it means when code reaches machinery, and it is worth reading by anyone responsible for a plant rather than an office.

The question for a board

Name the third party whose failure would stop the organization trading tomorrow morning. Where two directors would name different providers, the mapping has not been done, and the register requirement exists precisely because that was the common position.

The second question is how long recovery would take, expressed as a tested number rather than a target. That figure determines what an incident costs, and it is the one most likely to be wrong in the direction that matters.


Falcone International

Bring us a question like this one

We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.

Talk to usSee what we do

Discover more Insights from Falcone International

“Never Split the Difference” offers an inside look into the world of high-stakes hostage negotiations, translated into tactics for personal and business use. Chris Voss, a former FBI negotiator, shares strategies that center around empathy, active listening, and tactical mirroring to sway outcomes. This book is an essential guide for anyone aiming to improve their negotiation skills and interpersonal effectiveness.

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories