The Regulation on Operational Resilience of Digital Technologies in the Financial Sector: Do Investment Firms Apply DORA?

Mikov&Attorneys

Regulation (EU) 2022/2554 on the operational resilience of digital technologies in the financial sector, adopted on 14 December 2022 by the European Parliament and the Council of the EU (OJ L 333/1 of 27 December 2022), aims to prevent and mitigate the risk of cyber threats in the financial sector. The Regulation, also called the Digital Operational Resilience Act (DORA), introduces a comprehensive framework for ensuring the operational resilience of key systems for the financial sector. DORA has been applicable since 17 January 2025, and measures for its implementation are provided for in Bulgarian legislation by the Markets in Financial Instruments Act, as amended and supplemented, SG 54/2025.

The Regulation on Operational Resilience of Digital Technologies

Who and how should apply DORA?

The organisations subject to DORA are credit institutions, payment institutions, account information service providers, electronic money institutions, investment firms, crypto-asset service providers, central securities depositories. These organizations are expected to perform various actions to comply with the requirements of DORA. Key aspects include:


1. Information and Communication Technology (ICT) Risk Management Framework: Establish and maintain a comprehensive ICT risk management framework; identify, categorise and assess ICT risks; implement protective and preventive measures to mitigate identified risks; regularly review and test the effectiveness of the ICT risk management framework. 

2. Incident Reporting: Establish robust mechanisms for detecting and managing ICT incidents; report significant ICT incidents to the relevant authorities in a timely and effective manner.
 
3. Digital Operational Resilience Testing: conducting regular tests to assess the resilience of ICT systems and processes; conducting vulnerability assessments, scenario-based testing (e.g., system penetration), and establishing a process to identify and mitigate vulnerabilities. 

4. ICT Third-Party Risk Management: managing and monitoring ICT third-party risk, especially when relying on critical third-party ICT service providers; ensuring that contracts with third-party service providers include robust clauses on service levels, data protection, and audit rights; establishing mechanisms to monitor the performance and compliance of third-party service providers.
 

5. Information Sharing: engaging in sharing information on ICT risks and incidents to improve the understanding and management of ICT threats across the sector; participating in information sharing platforms, ensuring the protection of sensitive and confidential information. 

6. Supervision and Compliance: adhering to the supervisory framework established by competent authorities; regularly assessing compliance with DORA and cooperating with audits and inspections by regulatory authorities; implementing corrective actions as requested by regulatory authorities to address deficiencies or issues of non-compliance.

7. Management Body Involvement: ensuring that the organisation’s management body is effectively engaged in the oversight of the ICT risk management framework; requiring regular reports to the management body on ICT risks, incidents and resilience measures. 

8. Resilience and Cybersecurity Testing: implementing a robust cybersecurity strategy to protect against cyber threats; conducting resilience testing, including advanced testing for significant entities, to assess the organization’s ability to respond effectively to and recover from ICT breaches. 

9. Resources and Expertise: ensuring sufficient resources (financial, human, technical) for ICT risk management and operational resilience measures; ensuring that staff are adequately trained and maintain a high level of expertise in ICT risk management and operational resilience.

Liability of an investment Firm for Damages Resulting from Non-Compliance with DORA

Organisations subject to DORA are required to integrate these practices into their operational and risk management strategies to ensure the soundness and resilience of their ICT systems and the wider financial market infrastructure. Compliance with the requirements is monitored by the relevant authorities, and organisations may be subject to audits, assessments and corrective measures if deficiencies are identified. 

However, what happens if an investor suffers damages because an investment firm has not complied its ICT systems in line with DORA? Whether the investment firm will be liable for tort will be decided by the court on our client’s recent case.

The client executed a contract with a Bulgarian investment firm and after several years the firm, on its own initiative, informed the client that there would be a change in its status from Non-Disclosed Introducing Broker of an international group of investment firms to Fully- Disclosed Introducing Broker of the group. Due to the corresponding client migration, the client’s investment account would be on the group’s platform with new temporary username and password. Thus, the client’s financial assets were transferred to a new account, a sub-account of/linked to the Master Account of the Bulgarian firm on the group’s platform in its capacity as an introducing broker, and the client executed a new contract with an international firm from the group. However, the Bulgarian investment firm continued to provide full customer service and technical assistance in connection with the account, for which the client was not notified and did not consent.

And so, until mid-2025 when the client was surprised to discover certain activities in his account: using his personal data stored there (including data on financial assets), orders had been placed and transactions had been made that the client did not know about, did not order anyone to, and did not agree to. Against his will, the client was deprived of the expensive valuable shares of a leading global IT company that he owned and instead found himself being an owner of numerous cheap shares of a Chinese company.

Since the client never wanted, did not perform or instructed a third party to perform the unauthorised orders, intensive correspondence with the investment intermediaries immediately began in order to cancel the unauthorised orders and restore the valuable shares to the account. It turned out that a cyberattack had been carried out, as the main account of the Bulgarian firm in the group’s platform was accessed by an unknown third party and thus the unauthorised orders were made on the client’s account through the main account. Only then did the client realise that the Bulgarian investment firm actually had access to his account through the main account.

After investigation of the account intrusion, it was determined that a master user had made the unauthorized transactions, accessing from an IP address located in Hong Kong using the correct confidential username and password of the Bulgarian firm and the correct two-factor authentication (2FA). A key element of the accounts’ protection offered by the international group is the Secure Login System (SLS) – a login process that prevents access to a client or brokerage account without a physical device, application or SMS code, even if the username and password are known. Therefore, access to the Bulgarian firm’s Master Account was only possible through two security factors: something that only they knew – the password, and something that only they had – a code generated by a physical device, a mobile 2FA application or an SMS message to a phone. If the Bulgarian firm was not in Hong Kong during the disputed trading activity, it is clear that a third party was able to gain access to the Master Account and execute transactions on the client’s account using the confidential login details and unique 2FA device, likely acquired as a result of a phishing attack.

As soon as possible, the client managed to sell the Chinese shares in order to minimise the losses. Ultimately, the client was damaged by nearly EUR 750 000, representing the difference between the price of the IT company’s shares on the day of the cyber-break and the price obtained from the sale of the Chinese shares. The client filed a claim against the Bulgarian investment firm for tort and payment of compensation for the damages suffered.

The liability of the legal entity in this case has a security and guarantee function. It does not arise from the fault of the person who assigns the work but occurs when the person assigned to perform a certain work culpably causes the damage during and in connection with the performance of the work assigned to him. Unlawful conduct within the meaning of Art. 49, in conjunction with Art. 45 of the Bulgarian Obligations and Contracts Act is any action or omission /failure to take a legally required action/, determined by the will of the perpetrator, which violates the general prohibition established in the cited provision not to harm another and infringes the legally protected property or non-property of another person. Since at the date of the cyber-break, the provisions of DORA have been already mandatory and should have been applied by the Bulgarian investment firm, the court must establish whether the following regulatory provisions of DORA were violated:

• Articles 5 and 6 of DORA: an internal governance and control framework has not been established to ensure effective and prudent management of ICT risk in order to achieve a high level of operational resilience of digital technologies; the management body of the investment firm has not defined, approved, exercised oversight over the implementation of all actions in relation to the ICT risk management framework; 

• Articles 7 and 9 of DORA: adequate ICT systems and protocols and ICT-based tools have not been used and maintained to address ICT risk.

The court decision will set a precedent regarding the implementation of DORA in Bulgaria and is thus awaited with great interest.

More to explore