Compliance
DORA is a resilience test, not a compliance checkbox
Merrow Research Team · 14 May 2026
What actually changes operationally for UK-serving financial firms under DORA, beyond the paperwork.
Most compliance frameworks reward good documentation. DORA is unusual in that it's explicitly designed to test whether the documentation reflects reality — through mandated resilience testing, not just an audit of policy documents.
For UK-serving financial firms with EU exposure, the operational shift that tends to get underestimated is around third-party risk: DORA extends scrutiny to critical ICT third parties in a way that makes vendor management a resilience question, not just a procurement one.
The firms we've seen handle this well treated it as an opportunity to actually test their incident response process end to end, rather than a paperwork exercise to complete once and file away.
Related reading
Detection Engineering
Alert volume is not a security metric
Why the number of alerts a platform generates tells you almost nothing about whether your organisation is actually safer.
Elena Marsh · 2 Jun 2026
Incident Response
The first 90 minutes of a ransomware event
A breakdown of the decisions that determine containment scope, drawn from anonymised patterns across Merrow's retainer caseload.
Tomás Reyes · 22 Apr 2026