"We're really trying to build this compliance program, but it's so complex. I think that's the challenge. We saw this too with GDPR and other broad legislation that is subject to interpretation — what does it actually mean to comply? It means different things to different people," he said.
This lack of a common understanding of what qualifies as robust compliance with DORA has in turn led many institutions to ramp up security standards to the level that they're actually surpassing the "baseline" of what's expected of most firms, Jang added.