Intelligent Fin.tech Issue 27 | Page 31

C A S H I N G
I N

C A S H I N G

I N

AUTOMATED TESTING WILL BRIDGE THE CRITICAL GAP BETWEEN TEST AND EXPEDITED AUTOMATED REMEDIATION .
way we look at testing . Many financial services currently approach security testing as a reactive , periodic and check-box activity . That is the first thing that will have to change if we want to tackle DORA compliance . Instead , in the constantly evolving and complexifying landscapes of modern IT , testing will have to become a pro-active , continuous and automated task . This will effectively allow financial services sectors to continuously understand if they remain in compliance and how they fall out of it , while accommodating the constant change inherent in modern IT networks .
Furthermore – and this is key – it will provide clear documentation that a particular network is taking the necessary steps to comply – not just that it is testing regularly but that its results are aligning to expected compliance goals .
Some may try to do this manually . They will fail . To keep up with the shifting sands of threats , compliance obligations and technological evolution – this process must be as continuous and quick as the pace of change . Automated testing will bridge the critical gap between test and expedited automated remediation . � so it may cross in and out of multiple territorially located regulatory regimes and sectoral compliance obligations , DORA included . Violation of any one of these will likely come with some form of penalty – financial or otherwise .
It ’ s a startling amount of complexity that financial services have to deal with . That headache-inducing workload obviously falls upon stressed and overworked compliance departments who not only have to ensure compliance over a mountain of metrics but clearly document how they ’ re doing so . Many are even attempting to do so using largely manual processes and while that ’ s a herculean effort – against a backdrop of mounting regulatory complexity – no longer viable .
Away from manual reactivity and towards pro-active automated compliance
DORA and other regulations will actually require a wholesale change in the
www . intelligentfin . tech
31