La banking security has stopped being a technical department and become the backbone of trust in the financial system. With the entry into force of DORA (Digital Operational Resilience Act) in January 2025, European financial institutions operate under a regulatory framework that requires demonstrable digital operational resilience: ICT risk management, incident management, resilience testing, oversight of critical third parties and cyber-threat information sharing.
In this hub I bring together the articles where I analyse how banks, insurers and regulated entities face the challenges of Financial cybersecurity: from protection against generative-AI fraud and deepfakes to the practical implementation of DORA and NIS2, with their real penalties, incident-notification deadlines and the regulatory overlap that lets you comply once and demonstrate several times. I also cover the CISO’s role in the age of artificial intelligence, continuous supplier auditing and Spain’s ENS framework for entities working with the public sector.
Articles on banking security
Banking security: a strategy against modern cybercrime
Banking security 2026: DORA and NIS2 compliance, Zero Trust, defensive AI, deepfakes and ransomware. A financial-sector guide.
Read article
DORA Regulation: digital operational resilience for the financial sector
DORA in banking and fintech: five pillars, real deadlines and how they fit with NIS2 and the EU AI Act. What I implemented in financial-sector projects.
Read article
Can AI fill the cyber-expert shortage in banking?
AI, cybersecurity, banking and DORA: why AI doesn’t fill the cyber-expert shortage but shifts it. An analysis of the real limit under DORA.
Read article
DORA and the missing cyber-experts in banking
The banking cybersecurity talent gap: 15,000 vacancies DORA requires filling from 2025. A solution with a senior AI/Cyber Project Manager.
Read article
AI cybercrime 2026: deepfakes, phishing and digital fraud
AI cybercrime 2026: voice and video deepfakes, hyper-personalised phishing, banking fraud and AI defences.
Read article
AI agents in regulated environments and sectors: compliance and governance
How to deploy AI agents in regulated sectors without breaking the EU AI Act, NIS2 or DORA. Governance, suppliers and architecture, step by step.
Read article
NIS2 fines 2026: real cases and how to avoid them in IT projects
NIS2 fines 2026: amounts, real cases, the most-penalised mistakes and a 90-day plan to reduce your company’s exposure before the audit.
Read article
Regulatory overlap DORA, NIS2, ENS and AI Act: comply without duplicating
How to manage the overlap between DORA, NIS2, GDPR, EU AI Act and ENS to comply once and demonstrate several times. A practical guide for regulated environments.
Read article
72-hour incident notification: GDPR, NIS2 and DORA compared
Incident-notification deadlines in GDPR (72h), NIS2 (24h) and DORA compared. How to design a single response process to comply with all three at once.
Read article
ENS (National Security Framework): a practical guide for IT projects
What the National Security Framework (ENS) is, who it obligates, its categories and how to pass the audit without paralysing your regulated IT project.
Read article