The talent to meet DORA already exists.
The problem is that every financial services firm in Europe is chasing the same people at the same time, against a deadline that has already passed.
The Digital Operational Resilience Act has applied since 17 January 2025. Most firms understand what it asks of them, but far fewer have the people in place to deliver it.
Compliance is now held back less by budget or intent than by capability: the specialists who can operationalise ICT risk management, resilience testing and third-party oversight are in short supply, and demand is rising faster than the market can train them.
That has turned DORA into a hiring problem as much as a regulatory one.
Why DORA has changed cybersecurity hiring
DORA raises the bar for operational resilience across financial services, and it does so in a way that cuts across traditional job boundaries. Meeting the standard is not a matter of adding headcount to an existing security function. It requires people who can connect security, infrastructure, cloud, governance and risk, and hold those threads together under regulatory scrutiny.
That is where most firms feel the strain. A capable security operations centre or a strong penetration testing team does not, on its own, satisfy requirements for ICT third-party risk management, resilience testing or board-level reporting.
The 2025 ISC2 Cybersecurity Workforce Study found that skills gaps have overtaken raw headcount as the profession's most pressing shortage. DORA is a sharp illustration of exactly that.
That combination is rare enough on its own. Add financial services-specific regulatory experience, and the shortlist shrinks further.
Which cybersecurity roles are hardest to hire right now
Financial services firms are competing for a small group of specialists who can deliver the capabilities DORA requires.
- ICT and third-party risk managers who can assess, contract and monitor critical suppliers to DORA's standard
- Operational resilience leads who can map critical business services, set impact tolerances and evidence them
- Governance, risk and compliance specialists with genuine financial services exposure, not adjacent-sector experience
- Cloud security engineers and architects who can secure the environments most firms are still migrating into
- Detection and response professionals who can meet DORA's tighter incident classification and reporting timelines
Demand also remains high for identity and access management, security architecture and DevSecOps professionals.
The commercial cost of being behind on DORA
The first cost is price. A contested pool of operational resilience and GRC specialists means higher salaries, higher day rates for interim cover, and longer, more expensive searches. Waiting does not make the talent cheaper. It makes it scarcer.
The second is time. DORA's obligations are live, not pending. Resilience testing, incident reporting and third-party risk monitoring are ongoing commitments that need owners now. Every month a role sits open is a month those obligations rest with people already stretched across other priorities, which is precisely where gaps and errors appear.
The third is risk. Under-resourced compliance is never neutral. It shows up in weaker third-party oversight, slower incident response, and thinner evidence when a regulator or a critical client asks for it. For a sector where confidence is the product, that is an expensive place to sit.
What a DORA-ready cybersecurity hiring strategy looks like
The organisations making the strongest progress planned early and hired for capability.
They identified capability gaps before they became hiring gaps, looked beyond direct DORA experience and invested in developing existing teams alongside external hiring.
Professionals from cloud security, operational resilience, critical national infrastructure and other regulated sectors often bring the capabilities DORA programmes need.
Hiring early gives organisations more choice. Waiting narrows the talent pool, extends hiring timelines and makes specialist skills harder to secure.
Charlotte Christensen, who leads Montash's Cyber & Cloud practice across Europe, sees the same trend:
“This talent pool is already small and already competitive. Waiting until it's urgent is not a strategy. Whether that's getting ahead on hiring or starting to upskill the team you already have - now is the time.”
Speak to Montash
DORA is changing the skills financial services firms need and the way they hire for them.
If you're building cybersecurity capability across cloud security, operational resilience, governance or risk, speak to Charlotte Christensen and the Montash Cyber & Cloud team.