Articles blogs and podcasts

DORA cybersecurity Compliance Impact on Fintech CSP’s: What You Need to Know
EU’s DORA (Digital Operational Resilience Act) is a pivotal EU regulation designed to address ICT (Information Communication Technology) cybersecurity risk in EU FSIs (Financial Services Institutions). Most CSPs fall into the ICT category. DORA rules were finalized in January 2024 and go into effect January 2025. This compelling article tells fintech CSPs what they need to know to prepare for DORA.

The SEC added new cybersecurity rules to its existing reporting requirements for public companies. The rules went into effect December 2023 and require public companies to report cybersecurity incidents to the SEC in a timely fashion. Firms also need to report on their cybersecurity capabilities to the SEC on an annual basis. The rules were put into place so investors can take a firm’s cybersecurity profile into account when making investment decisions.
Legacy LIBOR Extension: It Ain’t Over ’Til It’s Over
It ain’t over ’til it’s over,” said baseball coach Yogi Berra in August 1973 regarding the chances of his fifth-place Mets winning the National League pennant. The same phrase can be applied to legacy LIBOR transition in light of the 2021 IBA LIBOR extension announcement.


SEC imposes hard hitting rules on alts firms
Last November the SEC voted to approve amendments to the Investment Advisors Act of 1940. The amendments represent five new rules to mitigate fraud and improve the transparency and impartiality by which the alts industry (private equity, hedge, real estate) deal with their investors.

One year after DORA came into force, what has actually changed? In this follow-up episode of Reimagining Cyber, Rob Aragao welcomes back Dominic Brown of Graves Light Consulting to assess how the regulation is functioning in practice — now an operational reality for EU and global financial institutions. They examine DORA as systemic risk regulation rather than mere compliance, the governance and third-party risk gaps exposed in year one, escalating supervisory scrutiny, the impact of Level 2 standards and TIBER-EU testing, and why year two marks a shift from preparation to proof — where resilience must work in practice, not just on paper.

I was a guest on the Re Imagining Cyber podcast talking about DORA (EU Digital Operational Resilience ACT). DORA addresses cyber threats to the EU financial system, emphasizing risk management, incident response, and third-party oversight. In the podcast I compare DORA to US regulations and advise organizations on how to build risk management strategies to enhance cyber resilience before the 2025 deadline.
Give it a listen!

Why Banks Are Using Document Management Solutions to Manage Subpoenas
Financial institutions are turning to SaaS platforms they’re already using to save time, money and mitigate legal risk in the subpoena response process.

libor transition
This brief article discusses how banks are using Intralinks secure document collaboration to facilitate LIBOR transition.