YUDU Sentinel Blog

How Communication Tools Support DORA Compliance

Written by Edward Jones | 24 Sep 2026

DORA is not simply a cybersecurity regulation. For financial entities, the Digital Operational Resilience Act establishes requirements for maintaining critical operations, responding to ICT-related incidents, communicating during disruption and reporting major incidents to the relevant authorities.

That makes communication an important part of operational resilience.

When an ICT incident occurs, organisations need to be able to coordinate response teams, keep management informed, communicate with employees and external stakeholders, maintain an accurate record of events and provide the information required for regulatory reporting.

The challenge is that the incident itself may affect the systems normally used to do all of this.

For security and business continuity teams, the question is therefore not simply whether an organisation has a communication platform. It is whether its communication arrangements will remain secure, available and usable when the primary IT environment is disrupted or cannot be trusted.

What does DORA require around communication?

Several parts of DORA are directly relevant to how organisations communicate during an ICT-related incident.

Article 11 requires financial entities to establish an ICT business continuity policy and associated response and recovery arrangements. These must include communication and crisis management actions to ensure updated information is transmitted to relevant internal staff and external stakeholders, alongside reporting to competent authorities.

Article 14 goes further, requiring financial entities to maintain crisis communication plans covering the responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and, where appropriate, the public. It also requires communication policies for internal staff and external stakeholders, with defined responsibility for implementing the communication strategy during ICT-related incidents.

Article 17 requires organisations to establish an ICT-related incident management process covering the detection, management and notification of incidents. That process must include roles and responsibilities, incident tracking and classification, internal escalation, communication with staff and external stakeholders, and reporting major incidents to senior management and the management body.

Together, these requirements make communication an operational component of incident response rather than a separate corporate communications activity.

Why conventional communication tools may not be enough

In normal circumstances, an organisation may rely heavily on Microsoft 365, email, Teams, internal telephony and other corporate systems.

During a serious ICT incident, those assumptions can change.

A ransomware attack could compromise corporate identities and collaboration systems. A cloud outage could make critical services temporarily unavailable. An attack on an identity provider could prevent authorised users from accessing otherwise unaffected applications.

In these circumstances, having a documented communication plan is important. But the plan also needs a dependable means of executing it.

This is where resilient communication infrastructure can support DORA requirements.

A communication capability designed specifically for incident response can provide an alternative channel for:

  • Activating incident response teams
  • Escalating incidents to senior management
  • Coordinating technical and business response teams
  • Issuing urgent notifications to employees and other stakeholders
  • Sharing verified information during an unfolding incident
  • Holding secure crisis meetings
  • Maintaining access to critical response information
  • Recording actions and communications for subsequent review

The objective is not necessarily to replace everyday collaboration tools. It is to ensure that the organisation has a communication capability that remains available when those tools are unavailable, compromised or unsuitable for managing a crisis.

The communication capabilities regulated firms should evaluate

DORA does not prescribe a particular communication product. Instead, organisations need to assess whether their arrangements support their wider ICT risk management, business continuity and incident response requirements.

The following capabilities are therefore worth evaluating.

1. Independent or out-of-band communications

The first question is dependency.

If the primary corporate network, identity environment or collaboration platform is affected, can the organisation still communicate?

An out-of-band communication capability provides a separate route for crisis communications, reducing reliance on the systems potentially affected by the incident.

For cyber incidents in particular, independence matters. A backup communication system that depends on the same compromised identity provider, network or infrastructure as the primary system may provide less resilience than it appears to.

2. Secure messaging for incident response

Incident teams need somewhere to communicate that is appropriate for sensitive operational information.

A resilient platform should provide controlled access, secure messaging and appropriate protections for information in transit and at rest.

It should also support structured communication between different groups. A major ICT incident may involve security teams, IT operations, business continuity, executives, legal teams, communications specialists and external partners.

The ability to establish controlled channels or groups can help ensure that information reaches the people who need it without creating unnecessary exposure.

3. Multiple communication channels

No single delivery mechanism is guaranteed to reach everyone during a crisis.

Email may be unavailable. Mobile data may be disrupted. Employees may not have access to corporate devices. Some stakeholders may not use the organisation's primary collaboration platform.

Resilient communication arrangements can therefore combine channels such as:

  • SMS
  • Email
  • Voice
  • Mobile applications
  • Secure messaging
  • Web-based communications

The important consideration is not the number of channels in isolation, but whether the organisation can select the appropriate channel for the situation and confirm who has received critical communications.

4. Two-way communication

Sending an alert is only part of incident management.

Response teams may also need to know:

  • Who has received the message?
  • Who has acknowledged it?
  • Who is available to respond?
  • Who needs assistance?
  • What information is being reported from different locations?

Two-way communication can turn mass notification into an operational response capability, allowing organisations to gather information as well as distribute it.

5. Secure crisis meetings

Some incidents require more than messaging.

Senior management and response teams may need to hold an immediate crisis meeting, bring in technical specialists or external advisers, review the situation collectively and make decisions under pressure.

A secure video capability can form part of this response architecture, particularly where conventional corporate conferencing services are unavailable or cannot be trusted.

The key consideration is again independence: if the same incident that triggers the crisis response can also prevent access to the meeting platform, the organisation needs to understand what alternative arrangements are available.

6. Access to critical information during disruption

Communication is much less useful if the response team cannot access the information needed to make decisions.

DORA requires business continuity and response arrangements to support continuity of critical or important functions and to maintain accessible records around disruption events.

Organisations should therefore consider how crisis teams will access and distribute essential files containing information such as:

  • Incident response procedures
  • Contact lists
  • Escalation procedures
  • Business continuity plans
  • Crisis management checklists
  • System recovery information
  • Emergency contacts
  • Regulatory reporting procedures

For resilience purposes, this information should be accessible through the same disruption scenarios being considered for the communication system itself.

7. Audit trails and incident records

DORA places significant emphasis on incident management, classification, reporting and learning from incidents.

Article 17 requires financial entities to record ICT-related incidents and significant cyber threats, while Article 13 requires post-incident reviews to consider, among other things, the effectiveness of incident escalation and internal and external communication.

A communication platform that provides an auditable record of messages, alerts, meetings, actions and other activity can therefore contribute to the evidence available after an incident.

This does not replace the organisation's formal incident record or regulatory reporting process. It can, however, provide useful supporting evidence of what happened, when communications were issued and how the response developed.

Communication also supports DORA incident reporting

DORA's incident reporting requirements create another reason to think carefully about communication infrastructure.

Financial entities must classify ICT-related incidents and determine their impact using defined criteria, including the number and relevance of clients or counterparties affected, duration, geographical spread, data loss, criticality of affected services and economic impact.

Where an incident is classified as major, it must be reported through the applicable regulatory reporting process.

The European Supervisory Authorities have subsequently established detailed requirements around the content, format and timing of major ICT-related incident reporting. Current operational guidance also emphasises the use of established reporting channels, templates and formats.

Communication tools do not perform this regulatory reporting automatically. Their value is in helping the organisation establish and maintain the information flow needed to understand the incident, coordinate the response, keep management informed and maintain an accurate record from which reporting can be completed.

That distinction is important.

The communication platform supports the incident-management process; it does not replace the regulated firm's reporting obligations.

What should security and resilience teams ask when evaluating a communication platform?

Rather than asking simply whether a product offers secure messaging or mass notification, organisations should assess the complete resilience capability.

A practical evaluation could include the following questions:

Area Questions to ask
Independence Can the platform operate if the corporate network, Microsoft 365, identity provider or primary collaboration environment is unavailable?
Security How is information protected in transit and at rest? How are users authenticated and access controlled?
Availability What infrastructure supports the service and what happens if the organisation's primary IT environment is compromised?
Incident response Can response teams quickly establish dedicated communication channels for different incidents?
Notification Can critical alerts be distributed through multiple channels and can receipt or acknowledgement be monitored?
Two-way communication Can recipients respond and provide information back to the incident team?
Crisis meetings Can teams conduct secure meetings if their normal conferencing environment is unavailable?
Critical information Can authorised users access essential response documents and procedures during an IT disruption?
Auditability Can communications and response activity be recorded for subsequent review and evidence?
Testing Can the organisation regularly test the communication arrangements as part of its resilience exercises?
Governance Are roles, permissions, escalation procedures and ownership clearly defined?
Scalability Can the platform support employees, contractors, counterparties and other stakeholders when required?

 

Communication resilience should be tested, not just documented

One of the biggest risks with crisis communication is assuming that a documented process will work because it exists.

DORA places considerable emphasis on testing digital operational resilience and learning from real incidents and exercises. The regulation requires business continuity plans and related arrangements to be periodically tested, while lessons from testing and real incidents should feed back into the ICT risk assessment process.

Communication should be included in those tests.

A useful exercise might simulate the loss of the organisation's normal collaboration environment and ask the response team to:

  1. Activate the alternative communication system.
  2. Contact the incident management team.
  3. Escalate to senior management.
  4. Issue an employee or stakeholder notification.
  5. Establish a secure crisis meeting.
  6. Access critical response information.
  7. Record key decisions and actions.
  8. Capture the information required for subsequent incident reporting.
  9. Review how quickly and reliably communications were delivered.
  10. Identify gaps and update the relevant response procedures.

This turns communication from a theoretical control into a tested operational capability.

The wider role of communication in digital operational resilience

DORA's approach reflects a broader principle of operational resilience: organisations need to be able to continue managing a disruption even when the technology supporting normal operations is affected.

The EBA defines operational resilience in terms of an institution's ability to deliver critical operations through disruption. Its work on DORA also highlights the importance of ICT risk management, incident reporting, testing and third-party risk management.

Communication sits across all of these activities.

It enables the organisation to coordinate its response. It helps management maintain situational awareness. It provides a mechanism for communicating with employees, clients and counterparties. And, when properly recorded, it can contribute to the evidence needed to review and improve the response afterwards.

For that reason, secure communication should be considered as part of the organisation's wider operational resilience architecture rather than simply as another collaboration application.

A practical approach to DORA-ready communication

For security and business continuity teams, the starting point is not necessarily buying another communication platform.

It is understanding the organisation's dependencies.

Map the communication channels used during a major ICT incident. Identify which rely on the corporate network, identity provider, cloud services or other systems that could be affected by the same incident. Then determine what the response team would use if those systems became unavailable or untrusted.

From there, evaluate whether the alternative provides:

  • Independent access
  • Secure communications
  • Multiple delivery channels
  • Two-way communication
  • Crisis meeting capability
  • Access to critical response information
  • Appropriate auditability
  • Defined ownership and escalation
  • Regular testing

The result should be a communication capability that supports the organisation before, during and after an ICT disruption.

Conclusion

DORA does not prescribe a particular communication technology. Instead, it requires financial entities to establish the processes, policies and capabilities necessary to communicate effectively during ICT incidents and maintain the continuity of critical operations.

That makes the resilience of the communication layer an important consideration for security, operational resilience and business continuity teams.

The key question is simple:

If your primary IT environment became unavailable tomorrow, could your organisation still communicate, coordinate its response, keep management informed and maintain the information needed to report and review the incident?

If the answer depends entirely on the systems affected by the incident, there may be a gap between having a crisis communication plan and having a crisis communication capability.

For organisations subject to DORA, closing that gap is an important part of building genuine digital operational resilience.