What is…
Supply Chain Security
IT supply chains are complex today: organizations that outsource cloud backup, backup software, hardware maintenance and monitoring to third-party providers depend on their security, availability and compliance. Supply chain security refers to the structured engagement with this dependency risk.
NIS2 explicitly requires supply chain security measures: assessment of security practices of ICT third-party providers, minimum contractual cybersecurity requirements and risk-based prioritization of critical suppliers. goes further: financial entities must inventory, assess and contractually obligate all critical ICT third-party providers — with clauses on audit rights, availability SLAs, exit strategies and data localization.
A structural risk: according to EU supervisory authority analyses (EBA, ESMA, EIOPA), the top 10 ICT third-party providers in the financial sector hold over 85% of critical contracts. Three quarters of these providers originate from third countries — predominantly the US. This concentration creates systemic risks: a failure at one of the large cloud providers can simultaneously affect dozens of financial institutions.
For backup and storage, this means concretely: anyone storing critical backup data with an external cloud provider must verify whether that provider is a critical ICT third-party provider under , whether the contract contains -compliant clauses and whether data localization (physical server location, provider’s legal framework) is ensured. The transition period for existing contracts runs until 31 December 2026.
DORA
DORA (Digital Operational Resilience Act, EU 2022/2554) is an EU regulation that has applied to all regulated financial market participants since January 2025, setting concrete requirements for ICT risk management, backup systems (Art. 11 and 12), third-party provider management (Art. 28–30) and incident reporting.
DORA
DORA (Digital Operational Resilience Act, EU 2022/2554) is an EU regulation that has applied to all regulated financial market participants since January 2025, setting concrete requirements for ICT risk management, backup systems (Art. 11 and 12), third-party provider management (Art. 28–30) and incident reporting.
DORA
DORA (Digital Operational Resilience Act, EU 2022/2554) is an EU regulation that has applied to all regulated financial market participants since January 2025, setting concrete requirements for ICT risk management, backup systems (Art. 11 and 12), third-party provider management (Art. 28–30) and incident reporting.