Skip to content

DORA obliges financial institutions to implement robust identity protection

Bottom line: DORA makes identity and access protection a binding regulatory obligation for financial institutions in the EU for the first time, rather than a voluntary security measure.

The Digital Operational Resilience Act (DORA) makes identity and access management a regulatory obligation for financial institutions for the first time. The background to this is that digital identities are increasingly seen as an attack surface with particularly low tolerance for error.

According to the report, digital identities are coming into sharper focus as an attack vector, since compromised credentials and excessive permissions give attackers direct access to critical systems. DORA responds to this development by treating the protection of digital identities for financial institutions in the EU no longer as a voluntary security measure, but as a regulatory requirement.

For CISOs in the financial sector, this means that identity and access management processes must in future be designed to be robustly documented and demonstrable not only for security reasons, but also to meet supervisory requirements. The regulation thus shifts responsibility for identity protection from a purely technical level to one with direct regulatory consequences in the event of violations.

Institutions should review their existing identity and access management concepts with regard to DORA compliance, particularly with respect to the granting of permissions, traceability of access, and the handling of privileged accounts. The original article itself does not go into specific technical measures or deadlines, but points to the fundamental need to embed identity protection as a fixed component of operational resilience.


Source: www.security-insider.de · Published August 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: