Risk Partners Life Sciences Roundtable 2024, thank you very much! Sign up now for the 26.06.2025 >

DORA regulation will apply from January 2025.
Significance for our private equity and venture capital clients

The somewhat unwieldy name "Digital Operational Resilience Act" ( DORA for short) has a very serious background and is to be welcomed in principle. After all, when we evaluate our claims in the context of cybercrime, PE and VC funds and their KVGs are those with the highest frequency of claims. It can be safely assumed that theyhave been identified as a "worthwhile target group" for cyber criminals based abroad and are now being systematically "processed". We are seeing an increase in redirected capital calls, payout distributions or redirected investments, some of which involve elaborate strategies on the part of the attackers. It is therefore one of our strategic focus topics for 2024/2025, particularly in terms of raising awareness.

About the DORA Regulation: with this regulation, the European Commission aims to harmonize ICT (Information and Communications Directive) resilience measures across Europe and improve cybersecurity in the financial sector. A special cut-off date is January 17, 2025, when the regulation will come into force (two years after its entry into force). 

The regulation emphasizes that the company management - i.e. the executive board ("GPs") - is responsible for managing ICT risks. And that's not all: they must also define and approve the strategy for digital operational resilience and plan an appropriate budget for it. The necessary know-how must be kept up to date at all times. In addition, companies in the financial sector must set up an ICT risk control function. It contains elements of the information security officer already prescribed in the IT requirements, but is not congruent with them.

Who is affected by the DORA Regulation?

The DORA regulation affects us as risk partners (insurance brokers) on the one hand and fully regulated KVGs on the other. Registered AIF KVGs are exempt from this. It can also be assumed that the exemption also applies to EuVECA managers, as these are typically treated in the same way as registered AIF KVGs.

Fully regulated KVGs and those in the process of full regulation should ensure that they are DORA-compliant.

Note: For BPs, a breach of the DORA Regulation constitutes a compliance breach, which is also to be regarded as organizational fault. In case law, this quickly leads to (unlimited) personal liability for GPs.

The DORA Regulation is based on the existing regulatory requirements and incorporates many regulations that the companies concerned are already familiar with from the sectoral IT requirements. It harmonizes these requirements, but is more detailed in its structure and significantly reduces the previous scope for discretion. The new regulatory requirements can be divided into five main areas (based on the colleagues from POELLATH):

ICT-Risk management and ICT-governance:

The DORA regulation stipulates that responsibility for risk management lies directly with the management. ICT risks must be integrated into the company-wide risk management system. While this requirement was already included in previous regulatory requirements, it is now legally binding under the DORA Regulation.

In the area of ICT governance, i.e. the organizational and legal framework conditions for IT structures, the regulation requires ICT to be integrated into the corporate strategy. In addition, the DORA regulation prescribes regular updates and control mechanisms for IT systems. 

According to the presentation by Dr. Fechler from 26.09.2024

In addition, data backup and recovery strategies must be developed to minimize the impact of potential system failures.

Obligation to report ICT-related incidents:

In accordance with the DORA Regulation, BaFin will act as the central national reporting hub for ICT incidents in the financial sector. An "ICT-related incident" is defined as an unplanned event that affects the security of networks or information systems and may have a negative impact on the availability, integrity, authenticity or confidentiality of data and the services of a financial undertaking (Art. 3 para. 1 no. 8 DORA).

The DORA regulation requires companies to set up protection mechanisms and early warning systems to detect cyber attacks in good time and prevent ICT incidents. All ICT-related incidents must be logged. In addition, a procedure for classifying these incidents will be introduced, with serious incidents being subject to mandatory reporting.

Testing digital operational resilience:

DORA obliges fully regulated KVGs to regularly check their ICT security. The regulation provides for various suitable tests to check the software code, network security and the compatibility of hardware and software. The aim of these tests is to uncover and eliminate weaknesses in the company's own digital operational resilience.

ICT third party management / outsourcing:

As more and more ICT services are being outsourced to technology service providers, companies must also identify third-party risks as part of their risk management. This task is likely to cause considerable effort in the German PE/VC landscape in particular due to the need for adjustments. BaFin also receives notifications in connection with ICT third-party management and examines them for potential risks to the financial sector. DORA sets out key contractual provisions as well as certain monitoring and termination rights for outsourcing agreements. The term ICT service is defined broadly in the regulation and includes - with the exception of analog telephone services - all digital and data services that are made available to users via systems. 

Monitoring of critical ICT third-party service providers:

DORA establishes a framework for the supervision of critical ICT technology providers that already existed in Germany in outline form. BaFin's powers have been significantly expanded and include, among other things, the requesting of documents, the imposition of fines and on-site inspections. BaFin is responsible for classifying an ICT service provider as critical and for the associated monitoring. The service providers classified as critical must bear the costs of this monitoring themselves. The typical KVG should not be affected by this. 

With regard to possible risk transfer options, there is unfortunately no specific DORA insurance. However, the good news is that our clients' existing holistic insurance concepts - usually a triad of E&O insurance, cyber insurance and crime insurance - effectively cover the risks for KVGs.

GPs, on the other hand, can rely on their existing criminal law protection and D&O insurance. In addition to the need to keep the respective conditions up to date in a "DORA era", PE/VC AIFMs should critically review their sums insured. This is because both the probability of occurrence and the potential amount of claims are likely to increase in the future.

We will be happy to keep you up to date on trends in the insurance market in our blog. Arrange a non-binding exchange with us: Book your preferred date!

Also read our other blog posts

Being Public

Global Integrity and Compliance Forum 2024 

𝗚𝗹𝗼𝗯𝗮𝗹 𝗜𝗻𝘁𝗲𝗴𝗿𝗶𝘁𝘆 𝗮𝗻𝗱 𝗖𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝗰𝗲 𝗙𝗼𝗿𝘂𝗺 𝟮𝟬𝟮𝟮𝟰 "D&O and Co. - Plan B to cover personal liability!" Last Friday, Florian had the honor of taking part in the Global Integrity and Compliance Forum at the Ludwig-Maximilians-Universität in Munich. Under the motto "The RULE of LAW in the Era of Integrity & Compliance", international legal experts, company managers, in-house councils and compliance officers from all over the world gathered to discuss the future of good corporate governance in 2024. Key discussions and insights One of the

Read more "
Being Public

Risk Partners supports successful IPO of Steyr Motors AG

We congratulate Steyr Motors AG on its successful listing in the Scale Segment of the German Stock Exchange on October 30, 2024! Risk Partners had the honor to act as IPO underwriting advisor on this transaction. Our team, led by Florian Eckstein and Björn Stressenreuter, supported Steyr Motors AG in its IPO on the Frankfurt Stock Exchange. Our expertise and comprehensive support were focused on providing Steyr Motors with a safe and successful start on the capital markets. We would like to thank Julian Cassutti and Christoph Cerar from Steyr Motors

Read more "
Being Public

Revolution in D&O insurance in Nevada (US insurance market) postponed

The revolution in D&O insurance in Nevada has been called off after all. In the US market, the state of Nevada passed an interesting law (Bill No. 398) in the summer with potentially significant implications for the D&O insurance market. The Governor of Nevada approved the bill on June 3, 2023, so the law came into force on October 1, 2023. We had classified this legislation (in the USA, insurance supervision is organized at state level) as too watchful for our clients, but this law

Read more "
Venture Capital

We provide information on liability risks for VC funds in the VC Magazine

In December, we were asked by VC-Magazin whether we could provide insights into liability and risk management issues relating to venture capital funds. With pleasure! Together with the team, Florian not only provided insights into current challenges, but also suggested practical solutions to effectively minimize and sensibly transfer the risks of a VC fund. In the VC Magazine article, you will therefore find: added value of customized insurance concepts for VC funds (focus: D&O/E&O insurance #Moonshot Protect), key measures for risk prevention (learning curve from our claims world), indemnifying contractual provisions as a preventive measure, and

Read more "
Life Sciences

Finance Day 2023

Growth capital for biotechnology: Yesterday, today, tomorrow! A few days ago, Jutta Zaglauer and Florian Eckstein from our team attended the Finance Day 2023 on the occasion of the 25th anniversary of biotechnology at the IZB - Innovation and Startup Center for Biotechnology. The event offered an exciting exchange and insights into current financing and capital market issues of biotechnology companies. As an experienced specialist insurance broker for the areas of life sciences, venture capital and IPOs, all three cornerstones of our "magic expertise triangle" were part of the exciting agenda. It was also interesting to discuss the importance of customized

Read more "
Being Public

New SEC Ruling: Transatlantic convergence in dealing with cyber security incidents

Foreign Filers / Private Issuers watch out! 2023 brought further harmonization of European and US standards for cyber incident reporting. According to the SEC Ruling, all companies listed on the US stock exchange are now required to publicly report significant data security incidents to the SEC within four working days. In addition, they must outline in their annual report (10-K) their procedures for identifying and addressing material cybersecurity risks, including the role of the board of directors. Note: This rule also applies to foreign private issuers (e.g., German companies that issue a

Read more "