Testing the limit: banks still struggling with DORA compliance

James Johnston

Roughly six months after the European Union’s Digital Operational Resilience Act (DORA) came into effect, many financial institutions are still scrambling to achieve compliance.

For software testing and quality assurance teams, this delay highlights a more profound challenge in managing application security and operational risk across complex IT environments.

“It’s no surprise to me that financial services organisations missed the 17 January 2025 deadline to be in compliance with the European Union’s Digital Operational Resilience Act (DORA),” stated James Johnston, since July 2023 the vice president of EMEA at Java runtime specialist Azul.

“I personally have not met a CIO or CISO who thought this deadline was realistic,” London-based Johnston said.

That sentiment is backed by industry data. Recent research from Orange Cyberdefense found that 43% of financial sector respondents admitted they would not be compliant by the deadline.

Meanwhile, another recent survey from Clear Junction showed that 86% of financial services organisations were still not fully compliant. Skillcast’s DORA readiness report painted an even starker picture, revealing “huge variation in the resilience of these institutions’ IT infrastructures.”

The banking and lending subsector was identified as the least prepared, while the financial transaction processing subsector emerged as the most vulnerable to cyber threats.

According to Johnston, one reason for this widespread lack of readiness is the inherent complexity and volatility of today’s cybersecurity landscape.

“Cyber security strategies are always dealing with moving targets,” he explained. “Today, an organisation could feel secure and in compliance with DORA, but tomorrow the vulnerability landscape could change.”

Firms in the dark

Johnston also noted that some financial firms are still unclear about what DORA compliance fully entails.

This instability creates a moving target not just for CISOs, but for testing and QA leaders responsible for validating the resilience of systems on an ongoing basis.

“Many companies are still unsure what measures they need to take to establish DORA compliance, and it requires a significant amount of vigilance across IT infrastructures to understand your exposure.”

This includes reviewing not only front-end applications and codebases, but also dependencies and runtime environments, particularly in Java, which remains foundational across the sector.

Johnston said Azul’s own 2025 State of Java Survey & Report revealed that 41% of respondents encounter “critical production security issues within their Java ecosystems on a weekly or daily basis.”

Despite the time that has passed since the infamous Log4j vulnerability, 49% of respondents are still experiencing “security weaknesses in production from the remote code execution vulnerability.”

This persistence of known risks speaks to a deeper concern: that many organisations are relying on outdated, unsupported, or inconsistently maintained Java environments, often without a clear understanding of the implications.

Johnston cautioned that “not ensuring your core systems are supported is highly risky, particularly as it exposes you to non-compliance with regulations like DORA.”


“I personally have not met one CIO or CISO who thought the DORA deadline was realistic.”

– James Johnston

Unsupported OpenJDK distributions are a particular point of concern, he continued, as these can result in unpatched vulnerabilities, degraded performance, and an inability to provide the security updates and critical patch updates required to remain compliant.

Johnston noted that relying on such distributions can cause incidents to go “unreported and unnoticed,” undermining both security assurance and regulatory reporting obligations.

Even basic tasks like penetration testing and threat modelling can become unreliable if conducted using Java versions that don’t reflect live production environments.

Third-party risk is another blind spot. Johnston stresses that financial institutions must ensure “their Java footprint, and that of their third-party providers or services, complies with DORA regulations.”

In addition, organisations that lack up-to-date Java environments may find themselves isolated from wider threat intelligence networks.

“Using unsupported OpenJDK distributions may result in a lack of awareness about updates and security patches,” Johnston explained, warning that such systems can “become a weak link in the information sharing chain.”

Despite the complexity, Johnston views DORA as an opportunity for positive change within financial IT and software quality disciplines.

He argued that investments in detection tools and post-breach response preparedness can not only reduce the cost of incidents but also strengthen long-term digital resilience.

“By ensuring a secure Java distribution, promptly addressing vulnerabilities, and continuously monitoring their Java environment,” he noted.

“Companies can make a large portion of their IT assets DORA-compliant and strengthen their resilience against cyberattacks.”


THIS MONTH


NEW EVENT


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY



REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW