By NHI Mgmt Group Editorial TeamBased on RSA Security: “A Practical CISO Playbook for DORA: Identity, Continuity and Controls” (September 8, 2025)

TL;DR: DORA pushes financial firms to prove identity controls, continuity, and governance can withstand severe disruption, and RSA Security frames that test around visibility, risk-based access, failover, phishing-resistant authentication, and lifecycle automation for CISOs and IAM leaders. The real issue is not whether controls exist, but whether identity operations remain governable under outage, credential theft, and audit pressure.


At a glance

What this is: This is a DORA-focused identity resilience playbook that argues financial firms must harden IAM, authentication, continuity, and governance to survive severe disruption.

Why it matters: It matters because DORA turns identity from a support function into an operational resilience requirement, so IAM, IGA, and PAM teams must prove controls still work during outage, attack, and audit conditions.


Context

DORA is forcing financial organisations to treat identity as part of operational resilience, not just access administration. The article argues that access control, authentication, continuity, and governance now sit inside the same regulatory test, which makes weak IAM processes a business continuity issue as much as a security issue.

For IAM and IGA teams, the practical question is whether identity services still function when infrastructure, networks, or cloud dependencies fail. The article's focus on visibility, adaptive access, failover, and lifecycle automation reflects a broader governance shift: resilience has to be built into identity operations, not added after controls are deployed.


Key questions

Q: What breaks when identity governance still depends on periodic certification?

A: Periodic certification breaks when identities change faster than the review cycle can capture. Access drift, standing privilege and delegated permissions can remain in place long after the business context has changed. In mixed human, non-human and AI estates, that means governance can look complete on paper while actual exposure keeps growing between review windows.

Q: Why does DORA make phishing-resistant authentication a resilience issue?

A: Because credential theft is not only an account security problem. If stolen secrets can still open critical access paths, then the identity layer fails to absorb the disruption that DORA expects institutions to withstand. Strong authentication protects continuity by keeping attackers from turning compromised credentials into operational outage.

Q: How do teams know if IAM lifecycle controls are working?

A: They should be able to prove that accounts are provisioned and removed on schedule, that access changes are logged, and that stale entitlements are rare. If deprovisioning is incomplete or audit evidence is fragmented, lifecycle control is failing even when the front-end access experience looks smooth.

Q: Which frameworks align most closely with DORA-driven identity resilience work?

A: NIST Zero Trust Architecture and the NIST Cybersecurity Framework both fit the identity resilience problem because they emphasise continuous verification, recovery, and governance. Financial firms should use them to structure controls around authentication, access decisions, and operational continuity rather than treating identity as a standalone compliance silo.


Technical breakdown

Identity risk audits under DORA

A DORA-aligned identity risk audit starts by mapping where access control, authentication, identity continuity, and incident response depend on manual work or legacy tooling. The technical issue is not simply coverage, but whether identity policy, authentication services, and governance workflows can still operate when disruption affects normal administration paths. That makes identity inventory and control mapping part of resilience engineering, not paperwork. In practice, the audit should surface single points of failure across identity infrastructure, policy enforcement, and recovery procedures.

Practical implication: build an identity control map that shows which services, approvals, and recovery steps fail first during disruption.

Risk-based access and phishing-resistant authentication

Risk-based access combines contextual signals such as device posture, geolocation, time of day, behavioural patterns, and historical access trends to adjust authorisation decisions dynamically. Under DORA, this matters because static access rules are too blunt for high-pressure environments where credential theft and abnormal access patterns are likely. Phishing-resistant authentication adds another layer by reducing the value of captured credentials, especially for workforce and customer access paths. Together, these controls shift identity assurance from a one-time login event to continuous evaluation.

Practical implication: prioritise context-aware access policies and phishing-resistant MFA on the accounts and journeys most exposed to credential theft.

IAM continuity and governance automation

IAM continuity means authentication and identity governance remain available even when a cloud, data centre, or network dependency fails. That is a different problem from normal high availability because the identity stack must survive the loss of its usual operating assumptions. Governance automation matters for the same reason: manual certification and entitlement review processes do not scale to the volume and speed of modern identity change, especially during disruption. The article ties continuity and automation together because resilience depends on both runtime availability and lifecycle control.

Practical implication: test failover for identity services and automate joiner-mover-leaver and certification workflows so governance does not collapse during outages.


Threat narrative

Attacker objective: The attacker aims to disrupt trusted access and weaken the organisation's ability to prove control over identity operations during a resilience event.

  1. Entry occurs through weak identity assurance, such as stolen credentials or a phishing path that reaches workforce or customer access.
  2. Privilege is then exercised through access paths that are too static to react to context, letting the attacker operate under legitimate-looking permissions.
  3. Impact follows when identity services, governance workflows, or authentication dependencies fail under disruption, exposing the organisation to operational and compliance loss.

NHI Mgmt Group analysis

DORA turns identity into a resilience control, not a support layer. The regulation does not merely ask whether access controls exist. It asks whether the organisation can still authenticate users, govern privileges, and evidence control when systems are under stress. That shifts IAM, IGA, and authentication from operational tooling into board-relevant resilience capability.

Manual certification is the wrong mental model for resilience. The article's warning about entitlement reviews and certification campaigns reflects a deeper problem: governance processes that depend on calm, scheduled operations will always lag disruption. When identity change is high volume and time-sensitive, resilience depends on automated lifecycle control and audit-ready evidence generation.

Phishing-resistant authentication is now a continuity issue as much as a fraud control. DORA-era identity design has to assume credential theft attempts are routine, not exceptional. If authentication can be bypassed through weak factors, the continuity promise is hollow because access still depends on trust in stolen secrets.

Risk-based access is the right direction only if it is governable under audit pressure. Adaptive access can reduce false positives and absorb context, but it also raises the evidentiary bar. Practitioners need policies that are explainable, reviewable, and aligned to resilience obligations, otherwise context-aware access becomes another opaque control.

Identity continuity should be treated as a named resilience capability. A useful concept here is identity recovery independence: the ability for authentication and governance functions to keep operating when a primary cloud, data centre, or network path is degraded. Financial CISOs should measure identity resilience separately from generic infrastructure uptime.

From our research library:

What this signals

Identity recovery independence: financial firms should now treat identity services as a resilience boundary in their own right. If authentication and governance only work in the steady state, DORA pressure will expose that weakness long before a regulator does.

The most consequential shift is organisational, not technical: IAM, IGA, security, and resilience teams have to share the same operating model for failure, recovery, and evidence. Zero Trust thinking helps here, and 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.


For practitioners

  • Map identity services to DORA control areas Document where access control, authentication, continuity, and incident response rely on manual intervention, legacy tooling, or a single operating dependency.
  • Prioritise phishing-resistant authentication Move workforce and customer access paths that are most exposed to credential theft onto phishing-resistant factors and reduce reliance on push or OTP alone.
  • Test identity failover under disruption Validate that authentication, governance, and reporting still function when the primary cloud, data centre, or network path is unavailable.
  • Automate lifecycle and certification workflows Replace manual joiner-mover-leaver steps and periodic entitlement reviews with policy-driven workflows that continue producing audit evidence during incidents.

Key takeaways

  • DORA elevates identity from a control domain to a resilience obligation, which means access, authentication, and governance must survive operational stress.
  • The article's core message is that manual identity processes and static policies are too fragile for outage, credential theft, and audit conditions.
  • Financial CISOs should test failover, harden authentication, and automate lifecycle governance so identity operations remain defensible when normal conditions break.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsDORA identity resilience depends on governing who can access what under changing risk conditions.
Recommendation — Apply PR.AA-05 to review whether access decisions remain valid when context or disruption changes.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPhishing-resistant authentication and credential security are central themes of the article.
IA-9 — Service Identification and AuthenticationIdentity continuity and machine-facing authentication are part of the resilience problem.
Recommendation — Use IA-5 to harden authenticator lifecycle controls and reduce credential theft exposure. Apply IA-9 where services and identity infrastructure must authenticate reliably during failover.
CIS Controls v8CIS-5 — Account ManagementLifecycle automation and entitlement review are core operational themes in the article.
Recommendation — Use CIS-5 to reduce manual account review work and keep identity governance auditable.
NIST Zero Trust (SP 800-207)Continuous Verification — Continuous VerificationThe article's adaptive access and resilience themes align with continuous verification under Zero Trust.
Recommendation — Adopt continuous verification so access decisions adapt as device, location, and behaviour change.

Key terms

  • DORA identity resilience: The ability for identity controls to keep working when financial services face disruption, outage, or audit pressure. It covers authentication, access governance, lifecycle management, and evidence generation, because regulators are evaluating whether identity can support business continuity rather than merely grant access in normal conditions.
  • Risk-Based Access: An access model that changes authentication or authorisation decisions based on behavioural and contextual signals. It can reduce friction and improve responsiveness, but it depends on accurate telemetry and clear response thresholds, especially when applied to service accounts and other NHIs.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Identity Continuity: Identity continuity is the ability to preserve a workload’s verified identity across proxies, services, and other infrastructure boundaries. It matters because zero trust breaks down when a request loses its original proof of identity and falls back to network trust or header-based assumptions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org