Risk Partners Life Sciences Roundtable 2025, thank you very much! 

DORA regulation will apply from January 2025.
Significance for our private equity and venture capital clients

Was etwas sperrig mit dem langen Namen „Digital Operational Resilience Act” (kurz: DORA) daherkommt, hat einen sehr ernsten Hintergrund und ist dem Grunde nach zu begrüßen. Denn wenn wir unsere Schadenfälle im Kontext von Cyber Crime auswerten, sind PE- und VC-Fonds bzw. deren KVG jene mit der höchsten Schadenhäufigkeit. Es kann gesichert davon ausgegangen werden, dass jene als „lohnende Zielgruppe” bei im Ausland sitzenden Cyber Kriminellen identifiziert wurden und nun systematisch „bearbeitet werden”. So sehen wir eine Zunahme an umgeleiteten Capital Calls, Payout Distributions oder umgeleitete Investments mit zum Teil aufwendigen Strategien der Angreifer. Es ist daher insbesondere hinsichtlich der Sensibilisierung einer unserer strategischen Fokusthemen für 2024/2025. 

About the DORA Regulation: with this regulation, the European Commission aims to harmonize ICT (Information and Communications Directive) resilience measures across Europe and improve cybersecurity in the financial sector. A special cut-off date is January 17, 2025, when the regulation will come into force (two years after its entry into force). 

In der Verordnung wird betont, dass die Unternehmensleitung – also etwa die Geschäftsführung („GPs”) – verantwortlich ist für das Management der IKT-Risiken ist. Und nicht nur das: Sie muss auch die Strategie für die digitale operationale Resilienz festlegen, genehmigen und hierfür ein angemessenes Budget einplanen. Das erforderliche Know-how muss jederzeit auf dem neuesten Stand gehalten werden. Zusätzlich müssen die Unternehmen des Finanzsektors eine IKT-Risikokontrollfunktion einrichten. Sie enthält Elemente des bereits heute in den Anforderungen an die IT vorgeschriebenen Informationssicherheitsbeauftragten, ist aber nicht deckungsgleich mit diesem.

Who is affected by the DORA Regulation?

The DORA regulation affects us as risk partners (insurance brokers) on the one hand and fully regulated KVGs on the other. Registered AIF KVGs are exempt from this. It can also be assumed that the exemption also applies to EuVECA managers, as these are typically treated in the same way as registered AIF KVGs.

Fully regulated KVGs and those in the process of full regulation should ensure that they are DORA-compliant.

Note: For BPs, a breach of the DORA Regulation constitutes a compliance breach, which is also to be regarded as organizational fault. In case law, this quickly leads to (unlimited) personal liability for GPs.

The DORA Regulation is based on the existing regulatory requirements and incorporates many regulations that the companies concerned are already familiar with from the sectoral IT requirements. It harmonizes these requirements, but is more detailed in its structure and significantly reduces the previous scope for discretion. The new regulatory requirements can be divided into five main areas (based on the colleagues from POELLATH):

ICT-Risk management and ICT-governance:

The DORA regulation stipulates that responsibility for risk management lies directly with the management. ICT risks must be integrated into the company-wide risk management system. While this requirement was already included in previous regulatory requirements, it is now legally binding under the DORA Regulation.

In the area of ICT governance, i.e. the organizational and legal framework conditions for IT structures, the regulation requires ICT to be integrated into the corporate strategy. In addition, the DORA regulation prescribes regular updates and control mechanisms for IT systems. 

According to the presentation by Dr. Fechler from 26.09.2024

In addition, data backup and recovery strategies must be developed to minimize the impact of potential system failures.

Obligation to report ICT-related incidents:

In accordance with the DORA Regulation, BaFin will act as the central national reporting hub for ICT incidents in the financial sector. An "ICT-related incident" is defined as an unplanned event that affects the security of networks or information systems and may have a negative impact on the availability, integrity, authenticity or confidentiality of data and the services of a financial undertaking (Art. 3 para. 1 no. 8 DORA).

The DORA regulation requires companies to set up protection mechanisms and early warning systems to detect cyber attacks in good time and prevent ICT incidents. All ICT-related incidents must be logged. In addition, a procedure for classifying these incidents will be introduced, with serious incidents being subject to mandatory reporting.

Testing digital operational resilience:

DORA obliges fully regulated KVGs to regularly check their ICT security. The regulation provides for various suitable tests to check the software code, network security and the compatibility of hardware and software. The aim of these tests is to uncover and eliminate weaknesses in the company's own digital operational resilience.

ICT third party management / outsourcing:

As more and more ICT services are being outsourced to technology service providers, companies must also identify third-party risks as part of their risk management. This task is likely to cause considerable effort in the German PE/VC landscape in particular due to the need for adjustments. BaFin also receives notifications in connection with ICT third-party management and examines them for potential risks to the financial sector. DORA sets out key contractual provisions as well as certain monitoring and termination rights for outsourcing agreements. The term ICT service is defined broadly in the regulation and includes - with the exception of analog telephone services - all digital and data services that are made available to users via systems. 

Monitoring of critical ICT third-party service providers:

DORA establishes a framework for the supervision of critical ICT technology providers that already existed in Germany in outline form. BaFin's powers have been significantly expanded and include, among other things, the requesting of documents, the imposition of fines and on-site inspections. BaFin is responsible for classifying an ICT service provider as critical and for the associated monitoring. The service providers classified as critical must bear the costs of this monitoring themselves. The typical KVG should not be affected by this. 

With regard to possible risk transfer options, there is unfortunately no specific DORA insurance. However, the good news is that our clients' existing holistic insurance concepts - usually a triad of E&O insurance, cyber insurance and crime insurance - effectively cover the risks for KVGs.

GPs, on the other hand, can rely on their existing criminal law protection and D&O insurance. In addition to the need to keep the respective conditions up to date in a "DORA era", PE/VC AIFMs should critically review their sums insured. This is because both the probability of occurrence and the potential amount of claims are likely to increase in the future.

We will be happy to keep you up to date on trends in the insurance market in our blog. Arrange a non-binding exchange with us: Book your preferred date!

Also read our other blog posts

Being Public

"I believe in a strong IPO comeback in 2024" - Interview Platform Life Sciences

Risk Partners in the trade press. Florian was approached by the journalists from Plattform Life Sciences for an interview on our view of 2024 and the development of Risk Partners over the past year. In addition to challenging claims, product innovations (e.g. all about POSI insurance) from Risk Partners, Florian also discusses our motives for the "team up" with the fantastic colleagues from Atrialis GmbH - experts in clinical trials. Click here for Florian's interview. Read the interview

Read more "
Being Public

Revolution in D&O insurance in Nevada (US insurance market) postponed

The revolution in D&O insurance in Nevada has been called off after all. In the US market, the state of Nevada passed an interesting law (Bill No. 398) in the summer with potentially significant implications for the D&O insurance market. The Governor of Nevada approved the bill on June 3, 2023, so the law came into force on October 1, 2023. We had classified this legislation (in the USA, insurance supervision is organized at state level) as too watchful for our clients, but this law

Read more "
Being Public

Digital and effective prevention of directors' and officers' liability by Risk Partners & Fides Technology

Innovation by Risk Partners & Fides Technology Now on Vimeo and Soundcloud: get practical tips from experts with high relevance for avoiding liability for business managers. Question unanswered? Content: Personal liability is a constant sword of Damocles hovering over managing directors in everyday life. The standard of care is strict and directors bear the burden of proof. In collaboration with the distinguished corporate lawyer Eva Homborg (Esche Schümann Commichau) and the governance expert Philippa Peters (Fides Technology GmbH), we have spent months compiling practical measures on how you can avoid this burden of proof.

Read more "
IPO

Risk Partners is advising Terranor Group AG on its NASDAQ (Sweden) IPO

From Road Builder to IPO Candidate: How Terranor Group AB Conquered Nasdaq First North. It was a day that marked a new chapter not only for Terranor Group AB but for the entire Nordic infrastructure sector: On June 19, 2025, the Swedish company celebrated its successful initial public offering on the Nasdaq First North Premier Growth Market in Stockholm. Risk Partners as IPO Advisor For while Terranor Group shares began trading under the ticker symbol TERNOR on June 30, 2025,

Read more "
Being Public

New SEC Ruling: Transatlantic convergence in dealing with cyber security incidents

Foreign Filers / Private Issuers watch out! 2023 brought further harmonization of European and US standards for cyber incident reporting. According to the SEC Ruling, all companies listed on the US stock exchange are now required to publicly report significant data security incidents to the SEC within four working days. In addition, they must outline in their annual report (10-K) their procedures for identifying and addressing material cybersecurity risks, including the role of the board of directors. Note: This rule also applies to foreign private issuers (e.g., German companies that issue a

Read more "
Management

Capital requirements for (fully regulated) AIFMs

What are the capital requirements for an asset management company? Together with experts Johannes Kiefer (Director of Risk & Compliance at Landsiedel & Partner) and Henry Franz (Managing Director of Layline.tax), we were able to compile our combined expertise on capital requirements, ranging from registered asset management companies to fully licensed ones. In this issue of VC Magazine, we share how E&O insurance, among other things, can provide added value. In addition to our article available below, please also check out the link to the online edition of Venture Capital Magazine. Enjoy!

Read more "