The Dutch Authority for the Financial Markets has assessed ICT recovery arrangements at large institutional asset managers, finding that they are broadly prepared for major outages but need stronger links between critical functions, recovery objectives, external provider dependencies and testing. Key processes, recovery plans and testing programs are generally in place, but gaps in their alignment could hinder the timely restoration of services during severe disruptions. The assessment identifies four priorities under the broader digital resilience expectations established by DORA. Asset managers should classify critical functions consistently across their organizations, set recovery objectives for those functions rather than only for systems or applications, align contractual requirements for ICT providers with internal recovery objectives, and test recovery measures against varied extreme scenarios. These should include cyberattacks, prolonged system outages and failures involving external ICT providers.
Dutch Authority for the Financial Markets identifies four priorities to strengthen asset managers’ ICT recovery
The Dutch Authority for the Financial Markets found that large institutional asset managers have the foundations for ICT recovery in place but need better alignment across critical functions, recovery objectives, providers and testing. It identified four priorities covering consistent classification, function-level recovery objectives, provider agreements and testing against extreme disruption scenarios.