Agentic Artificial Intelligence
Agentic Artificial Intelligence (AI) is transforming not only business and security operations but also advancing a new phase in the evolution of AI systems. By extending traditional machine learning (ML) and large language models (LLMs) with autonomy and decision-making capabilities, agentic AI introduces both powerful new opportunities and important considerations for organizations adopting these technologies.
Critical or Important Functions Under DORA
Under the Digital Operational Resilience Act (Regulation (EU) 2022/2554), there are two criticality criteria:
- Criticality of the function using the information and communication technology (ICT) service: article 8.5 of DORA, as determined by financial entities; and
- Criticality of the ICT service provider: article 31 of DORA, as determined by the European Supervisory Authorities (ESAs).
Source: Proofpoint
U.S. Securities and Exchange Commission Regulation S-P
Regulation SP Requires registered broker-dealers, investment companies, and investment advisers to adopt written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer records and information.
Source: U.S. Securities and Exchange Commission
Australian Prudential Regulation Authority (APRA) - CPS 230 FAQs
CPS 230 is an Australian Prudential Standard designed to strengthen operational risk management and resilience across the Australian financial sector. The regulation took effect on July 1, 2025.
Source: Proofpoint
Australian Prudential Regulation Authority (APRA) - CPS 234 FAQs
CPS 234 is an Australian Prudential Standard designed to ensure APRA-regulated entities can effectively prevent, detect, respond to, and recover from information security incidents, including cyberattacks.
Source: Proofpoint
Alignment with NIST Cybersecurity Framework and NIS2
The Network and Information Security Directive 2022/2555, otherwise known as NIS2, is a European Union (EU) directive designed to improve the security of network and information systems in the EU.
Source: Proofpoint
Digital Operational Resilience Act (DORA) FAQs
The Digital Operational Resilience Act (“DORA”) was adopted on 27 December 2022. It is a European Union regulation designed to increase the cybersecurity requirements for financial institutions (“FSIs”- Financial Services Industries) and their information and communication technology (“ICT”) service providers.
Source: Proofpoint
Information Security Registered Assessors Program (IRAP) - Email Protection
IRAP is an Australian Government initiative managed by the Australian Signals Directorate (ASD) designed to help ensure that information and communications technology (ICT) systems meet the requirements of the Australian Government Information Security Manual (ISM). By meeting IRAP control requirements, organizations can have confidence that Proofpoint maintains the security controls necessary to securely protect government systems and information.
Source: Proofpoint
Digital Operational Resilience Act
The Digital Operational Resilience Act (“DORA”) was adopted on 27 December 2022. It is a European Union regulation designed to increase the cybersecurity requirements for financial institutions (“FSIs”- Financial Services Industries) and their information and communication technology (“ICT”) service providers.
Source: Proofpoint
Executive order on Safe, Secure, and Trustworthy Artificial Intelligence
On October 30, 2023, the Biden administration issued an Executive Order (EO) on the Safe, Secure and Trustworthy Development and Use of Artificial Intelligence (AI) (“Order”).
Source: Proofpoint
© 2026 Proofpoint. All rights reserved. The content on this site is intended for informational purposes only.
Last updated November 26, 2025.
Proofpoint Trust
Proofpoint helps companies protect their people from the ever-evolving threats in the digital ecosystem.