DORA in the financial sector: compliance is not enough

Few sectors are targeted by sophisticated cyberattacks as consistently as the financial industry. High-value assets, sensitive customer data, complex IT ecosystems and a strong reliance on third-party providers make banks and insurance companies particularly attractive targets. Ransomware, data theft and attacks via the digital supply chain have become realistic threat scenarios.

The European Union has responded to these challenges with the Digital Operational Resilience Act (DORA). ICT risk management, technical security controls, structured incident response and stricter oversight of third-party ICT providers are now regulatory requirements for all supervised financial institutions.

Many organisations have already strengthened governance structures, documented policies and established reporting processes. This is an important step, but it is not enough.
What is often overlooked is this:
Formal compliance can create a false sense of security. Digital resilience is not achieved through completed checklists, but through security architectures that can be effectively managed and controlled in practice.

Resilience is proven in day-to-day operations

DORA defines requirements and assesses structures and processes. Whether these measures translate into genuine resilience is determined not in documentation repositories, but in day-to-day IT operations, where attackers actively target technical vulnerabilities and operational weaknesses.

Security must therefore be implemented consistently across the organisation, centrally managed and continuously auditable.

While governance and reporting structures are often clearly defined, technical implementation is frequently hindered by legacy environments. Cryptographic keys may be managed in a decentralised manner, certificates distributed across multiple systems and access management models implemented inconsistently.

Such situations are not necessarily non-compliant, but they increase complexity and therefore risk. Resilience is not simply about having controls in place; it is about being able to maintain control when it matters most.

Identity as a control mechanism in modern infrastructures

In today's hybrid environments, systems, employees, service providers and machines interact across organisational and infrastructure boundaries.

An identity-centric security model, as promoted by Zero Trust principles, ensures that every entity is uniquely authenticated and authorised. Access is no longer granted based on network location but on clearly defined identity and access policies.

Organisations that lack end-to-end control over identities ultimately lose operational control over their entire security architecture.

Cryptography must be manageable

Encryption protects data. However, its effectiveness depends on the reliable management of the underlying keys and certificates.

Manual renewal processes, decentralised key management and limited visibility of certificate lifecycles all represent operational risks.

A resilient security architecture requires a consistent public key infrastructure (PKI), automated certificate lifecycle management and clearly defined processes for the generation, use and revocation of cryptographic keys.

A new dimension: protecting data in use

As critical functions are increasingly moved to cloud environments, parts of the value chain are transferred to external infrastructures.

Traditional security approaches focus on protecting data at rest and data in transit. In cloud-based environments, however, another dimension is becoming increasingly important: protecting data while it is being processed.

Technologies such as confidential computing provide an additional layer of protection through hardware-based isolated execution environments, safeguarding sensitive workloads even against privileged access at infrastructure level.

DORA as a driver of modernisation

Properly understood, DORA is not simply a compliance initiative. It is a catalyst for the structural modernisation of security-critical infrastructures.

Organisations that approach digital resilience strategically should ask themselves four key questions:

  1. Can identities be managed consistently across the organisation?

  2. Is cryptography centrally controlled and auditable?

  3. Is there full visibility of certificates, keys and dependencies?

  4. Are cloud-based and third-party processing environments secured in a technically transparent and verifiable manner?

Only when these questions can be answered confidently does regulatory compliance become a truly resilient security foundation.

Organisations that view DORA solely as a regulatory obligation risk missing an important opportunity to modernise their security architecture.

Digital resilience is not a project with a fixed end date; it is an ongoing maturity journey. Those who embrace it strategically will strengthen not only their regulatory position but also their operational stability in an increasingly interconnected financial world.

 

Author: Dr. Michael Jahnich, Director Business Development, achelos GmbH

DORA