DORA and the cyber experts missing from banking
I have spent weeks talking to banking leaders and they all describe the same bottleneck: the cybersecurity talent shortage in banking is now the main obstacle to complying with DORA in Spain. The financial sector concentrates some 15,000 unfilled vacancies, within a national deficit of close to 99,600 specialist posts. Banking accounts for 34% of cyberattacks on critical operators and, since 17 January 2025, every financial entity has a legal obligation to comply with DORA. The question is no longer what the regulator requires. It is who is going to execute it.
Cybersecurity talent shortage in banking: the figure the regulator describes
The figure on the cybersecurity talent shortage in banking was published by Vozpópuli on 10 May 2026 and accurately sums up a problem that is not new, but is now enforceable. INCIBE handled 122,223 incidents in 2025, 26% more than the previous year. 96% of European banks have suffered breaches linked to external providers, and 97% have recorded incidents with third parties. The attack surface grows every time a new provider, a new mobile app or a cloud migration is integrated.
DORA, the Digital Operational Resilience Regulation, does not recommend: it obliges. The Bank of Spain supervises compliance and the financial consequences are real. We are talking about a regulatory architecture articulated around five operational pillars —ICT risk management, notification of major incidents, resilience testing, ICT third-party risk management and threat intelligence sharing— which I already developed in detail in my guide to the DORA Regulation and the digital resilience of the financial sector. Each of those pillars needs people with a very specific profile that the market does not produce at the pace the regulation demands.
Cybersecurity in banking: why it is the favourite target of attacks
The cybersecurity talent shortage in banking is also explained by the nature of the sector. Banking is a priority target for three structural reasons. First, it concentrates liquid economic value, which makes it profitable for the attacker. Second, the sector’s accelerated digitalisation has multiplied the attack surface: every exposed API, every provider SDK, every payment integration opens a door. Third, the sector depends on a huge technology supply chain that has proved to be the preferred vector for APT groups and ransomware operators.
The Bank of Spain documents that cyberattacks on the financial sector doubled in frequency between 2018 and 2022 globally. The growth has not stopped: generative artificial intelligence has lowered the barrier to entry for personalised phishing campaigns, social engineering at scale and automated exploitation of vulnerabilities. I analyse this dynamic in detail in my article on banking security against modern cybercrime. Each new attack technique demands an equivalent defensive response, and only professionals who understand technology, regulation and the banking business at once can articulate that response.
The profile that closes the cybersecurity talent shortage in banking
The cybersecurity talent shortage in banking is not just about pentesters or junior SOC analysts. What is critical is the lack of professionals able to bridge three worlds that rarely coexist in a single person:
- The technical language of the threat (SIEM, SOAR, XDR, Zero Trust, threat hunting, incident management).
- The regulatory framework in force (DORA, NIS2, GDPR, EU AI Act, national schemes such as the ENS), which I map in my guide to IT regulations 2026.
- The business language that the management committee and the Bank of Spain supervisor understand.
That triple profile —technical, regulatory and executive— is exactly that of the AI/Cybersecurity Project Manager. It is not a consultant who delivers a report and leaves. It is someone who directs the DORA programme end to end: defines the compliance roadmap, coordinates the internal security, risk, legal and IT teams, manages the relationship with critical ICT providers, prepares the mandatory notifications to the regulator and translates the regulation into auditable operational controls.
Universities do not produce that profile. Not because their programmes are badly designed, but because the combination is built with years of real exposure to regulated sectors. That is why the deficit exists and why it will keep existing for several more years.
What entities can do while they train their internal talent
48% of companies in Spain are trying to fill cybersecurity vacancies by training their own staff, but only two in ten positions are filled with internal talent. Training takes between 18 and 36 months; DORA has been enforceable for almost a year and a half. The arithmetic does not add up. The entities managing the transition best work with three combined levers:
1. Direct hiring of senior profiles with regulatory vision
Hiring on staff professionals with 15-30 years of experience in regulated sectors who already speak the language of DORA, NIS2 and the GDPR. These profiles do not need training: they need system access and an executive mandate. The cost is high but the time-to-value is weeks, not years. It is exactly the proposal I set out in hiring an AI Project Manager on staff, interim or retainer.
2. Hybrid teams with external leadership and internal execution
An external or in-house Project Manager with DORA experience pilots the programme, while the junior and mid-level internal teams execute specific tasks. This architecture makes it possible to comply with the regulation without driving up cost and, at the same time, transfer knowledge to the internal team. In three years, the team is autonomous. It is the model I apply when I come in as a DORA consultant in banking to direct the programme end to end.
3. Compliance management platforms
When people are scarce, the right tool multiplies the available team. A multi-tenant platform that centralises document control, incident traceability, the mandatory DORA/NIS2/GDPR notifications and auditing drastically reduces the dependence on scarce profiles for structured tasks. It is exactly the logic I apply in RegComply, my regulatory compliance platform deployed at regcomply.joseenrique.es. That same logic of amplifying the team applies to legacy: modernising COBOL with AI allows small teams to tackle migrations that previously required entire workforces.
What a senior AI/Cybersecurity Project Manager brings
Closing the cybersecurity talent shortage in banking requires a combination of technical and regulatory judgement built over years in the field. After 30 years in banking, insurance, energy, agri-food and public administration, the pattern repeats: entities do not fail from not knowing the regulation, they fail in execution. Managing a DORA programme requires, at the same time:
- A gap analysis against the five pillars of DORA and the relevant articles of NIS2 and the GDPR.
- Design and maintenance of the ICT provider information register (Article 28 DORA), enforceable and with periodic updates to the supervisor.
- Definition of the operational resilience testing framework, including TLPT eligibility.
- Coordination with the SOC, incident response teams and external providers to close the SIEM-SOAR-XDR cycle.
- Integration of the EU AI Act into the AI models used by the entity: risk classification, impact assessment and model traceability.
- Executive reporting to the management committee and the supervisor in business language.
This is what I deliver as programme management. And it is the kind of figure the Vozpópuli article describes as non-existent in the market. If you are interested in how I articulate the move from delivery to compliance, I develop it in from delivery to compliance: NIS2 for Project Managers.
The cybersecurity talent shortage in banking is not technological, it is about people
The cybersecurity talent shortage in banking will not be solved in a year. The Spanish financial sector has ahead of it a capability-building process that will not be completed in a year. The regulation demands, the attacks do not cease and talent is scarce. The entities that are already compliant are not the ones with the biggest budget: they are the ones that have combined senior talent with regulatory vision, internal teams in training and management tools that multiply the available team.
If your entity —or your client— is in this gap, we can talk. I work hybrid or remote, available for immediate incorporation as an AI/Cybersecurity Project Manager on staff or as external programme management. You can write to me from the contact page.
Frequently asked questions about DORA and the cybersecurity deficit in banking
According to the data published by Vozpópuli in May 2026, the Spanish financial sector has an estimated deficit of 15,000 unfilled cybersecurity vacancies. The figure sits within a national deficit of close to 99,600 specialist posts. Banking also accounts for 34% of cyberattacks on critical operators, which makes the problem structural and a priority.
DORA has been fully enforceable since 17 January 2025 and allows no gradualism. It obliges financial entities to deploy five pillars simultaneously (ICT risk, major incidents, resilience testing, third-party risk and intelligence sharing), each with specialised profiles combining technology, regulation and business. That combination rarely exists in a single person and the market does not produce it at the pace the regulation demands.
The key profile is the senior AI/Cybersecurity Project Manager with experience in regulated sectors. They are the one who directs the programme end to end: defines the roadmap, coordinates security, risk, legal and IT, manages critical ICT providers, prepares the notifications to the supervisor and translates the regulation into auditable operational controls. It is not a consultant who delivers a report, it is a programme director with an executive mandate.
Training internal staff in regulated cybersecurity takes between 18 and 36 months depending on the starting point. DORA has been enforceable for almost a year and a half, so pure training does not solve the immediate compliance problem. The effective strategy combines senior hiring with regulatory vision, hybrid teams with external leadership and compliance platforms that multiply the available team.
Yes, especially in structured tasks such as document control, incident traceability, mandatory notifications and auditing. A multi-tenant platform that centralises DORA, NIS2, GDPR and the EU AI Act frees up hours for the few available senior profiles so they can focus on decisions, not on document management. It is the logic I apply in RegComply, my regulatory compliance platform.
More on DORA compliance and banking cybersecurity
- DORA consultant for banking: programme management
- DORA Regulation: digital resilience of the financial sector
- Banking security: strategy against modern cybercrime
- IT regulations 2026: NIS2, DORA and the EU AI Act
- The RegComply platform (DORA / EU AI Act / NIS2 / GDPR)
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes