Resilience is proven in day-to-day operations
DORA defines requirements and assesses structures and processes. Whether these measures translate into genuine resilience is determined not in documentation repositories, but in day-to-day IT operations, where attackers actively target technical vulnerabilities and operational weaknesses.
Security must therefore be implemented consistently across the organisation, centrally managed and continuously auditable.
While governance and reporting structures are often clearly defined, technical implementation is frequently hindered by legacy environments. Cryptographic keys may be managed in a decentralised manner, certificates distributed across multiple systems and access management models implemented inconsistently.
Such situations are not necessarily non-compliant, but they increase complexity and therefore risk. Resilience is not simply about having controls in place; it is about being able to maintain control when it matters most.
Identity as a control mechanism in modern infrastructures
In today's hybrid environments, systems, employees, service providers and machines interact across organisational and infrastructure boundaries.
An identity-centric security model, as promoted by Zero Trust principles, ensures that every entity is uniquely authenticated and authorised. Access is no longer granted based on network location but on clearly defined identity and access policies.
Organisations that lack end-to-end control over identities ultimately lose operational control over their entire security architecture.
Cryptography must be manageable
Encryption protects data. However, its effectiveness depends on the reliable management of the underlying keys and certificates.
Manual renewal processes, decentralised key management and limited visibility of certificate lifecycles all represent operational risks.
A resilient security architecture requires a consistent public key infrastructure (PKI), automated certificate lifecycle management and clearly defined processes for the generation, use and revocation of cryptographic keys.
A new dimension: protecting data in use
As critical functions are increasingly moved to cloud environments, parts of the value chain are transferred to external infrastructures.
Traditional security approaches focus on protecting data at rest and data in transit. In cloud-based environments, however, another dimension is becoming increasingly important: protecting data while it is being processed.
Technologies such as confidential computing provide an additional layer of protection through hardware-based isolated execution environments, safeguarding sensitive workloads even against privileged access at infrastructure level.
DORA as a driver of modernisation
Properly understood, DORA is not simply a compliance initiative. It is a catalyst for the structural modernisation of security-critical infrastructures.
Organisations that approach digital resilience strategically should ask themselves four key questions:
Can identities be managed consistently across the organisation?
Is cryptography centrally controlled and auditable?
Is there full visibility of certificates, keys and dependencies?
Are cloud-based and third-party processing environments secured in a technically transparent and verifiable manner?
Only when these questions can be answered confidently does regulatory compliance become a truly resilient security foundation.
Organisations that view DORA solely as a regulatory obligation risk missing an important opportunity to modernise their security architecture.
Digital resilience is not a project with a fixed end date; it is an ongoing maturity journey. Those who embrace it strategically will strengthen not only their regulatory position but also their operational stability in an increasingly interconnected financial world.
Author: Dr. Michael Jahnich, Director Business Development, achelos GmbH