GERMANY Law and Practice Contributed by: Josefine Spengler and Svetlana Ulrici, Annerton
3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Operational resilience in Germany’s financial sector is primarily governed by DORA, which has applied since January 2025. DORA establishes a uniform EU- wide framework for ICT risk management, incident reporting, digital operational resilience testing and the management of ICT third-party risk. It replaces fragmented national approaches with a harmonised regime applicable across the EU. DORA applies directly and does not require national transposition. In Germany, it is enforced by the com - petent financial supervisory authorities – in particular BaFin – in co-ordination with EU supervisory bodies. DORA covers a broad range of supervised financial entities, including: • credit institutions and payment institutions; • investment firms and trading venues; • insurance and reinsurance undertakings; and • asset managers and other regulated financial mar - ket participants. The framework applies irrespective of the size of the institution, although proportionality principles allow requirements to be calibrated based on the entity’s risk profile, complexity and systemic relevance. DORA has a strong extraterritorial effect. Although for - mally addressed to EU-regulated financial entities, its requirements extend to non-EU ICT service providers that support EU financial institutions. Such providers must accept contractual audit, access and co-oper - ation obligations and, if designated as critical, may be subject to direct EU-level oversight. As a result, global technology and cloud providers servicing the EU financial sector must align their security, resilience and incident-handling practices with DORA expecta - tions to remain viable vendors. In practice, DORA operates alongside horizontal cybersecurity frameworks such as NIS2/BSIG, but applies as a lex specialis for financial entities. Finan -
Threat Intelligence and Information Sharing A central state obligation is the collection, analysis and dissemination of cyber-threat intelligence. This role is primarily fulfilled by the BSI, which gathers information from incident reports, technical analyses and international partners. The BSI issues warnings, situation reports and technical advisories to public authorities and private operators. Information sharing is structured but largely co-oper - ative. The State encourages early reporting and vol - untary information exchange to improve situational awareness and collective defence. While participa - tion is mandatory for in-scope entities under certain regimes, the broader intelligence-sharing framework is designed to support prevention rather than enforce - ment. Public–Private Co-Operation Public–private co-operation is a core element of Ger - many’s cybersecurity model. The State actively pro - motes collaboration with industry, recognising that much of the country’s critical digital infrastructure is privately operated. Platforms for co-operation include sector-specific working groups, information-sharing forums and joint response structures co-ordinated by the BSI. The National Cyber Defence Centre serves as a co- ordination hub in serious incidents, enabling infor - mation exchange between security authorities and, where appropriate, affected private operators. This reflects a policy approach that relies on partnership and shared responsibility rather than purely top-down regulation. International and EU-Level Engagement Germany also has responsibilities at EU and interna - tional level, contributing to collective cyber-resilience through co-operation with EU institutions, other mem - ber states and international partners. This includes participation in cross-border incident co-ordination, alignment with EU cybersecurity initiatives and engagement in international threat intelligence net - works.
148 CHAMBERS.COM
Powered by FlippingBook