Banking security: DORA, NIS2 and operational resilience

La banking security has stopped being a technical department and become the backbone of trust in the financial system. With the entry into force of DORA (Digital Operational Resilience Act) in January 2025, European financial institutions operate under a regulatory framework that requires demonstrable digital operational resilience: ICT risk management, incident management, resilience testing, oversight of critical third parties and cyber-threat information sharing.

In this hub I bring together the articles where I analyse how banks, insurers and regulated entities face the challenges of Financial cybersecurity: from protection against generative-AI fraud and deepfakes to the practical implementation of DORA and NIS2, with their real penalties, incident-notification deadlines and the regulatory overlap that lets you comply once and demonstrate several times. I also cover the CISO’s role in the age of artificial intelligence, continuous supplier auditing and Spain’s ENS framework for entities working with the public sector.

Financial cybersecurity

Articles on banking security