TL;DR: DORA pushes financial entities to treat identity as operational resilience infrastructure, not just account administration, because lifecycle gaps, overprivilege, vendor access, machine identities, and weak evidence trails quickly become audit and incident failures, according to Unosecur. The real issue is that resilience programmes assume identity states are visible, policy-backed, and reviewable when many are still fragmented, static, and difficult to prove.
NHIMG editorial — based on content published by Unosecur: Identity wears many masks and DORA pulls each one off
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities - 46% confirmed, 26% suspected.
Questions worth separating out
Q: How should financial institutions use identity governance for DORA and NIS2 compliance?
A: They should use identity governance as the evidence layer for access approval, review, and removal.
Q: Why do non-human identities create compliance risk even when policies exist?
A: Policies fail when machine credentials are created faster than teams can inventory and review them.
Q: What breaks when third-party access is not included in identity governance?
A: Auditability breaks first, followed by containment.
Practitioner guidance
- Map identity controls to DORA evidence requirements Build a control matrix that links joiner-mover-leaver workflows, privileged access, vendor identities, and machine credentials to auditable artefacts.
- Inventory third-party identities as regulated assets Create a complete inventory of federated vendor accounts, service accounts, and externally managed credentials.
- Rationalise standing privilege across cloud and SaaS estates Review legacy entitlements, emergency access, and role drift across AWS IAM, Entra, GCP, and key SaaS systems.
What's in the full article
Unosecur's full blog covers the operational detail this post intentionally leaves for the source:
- Control-by-control mapping of identity issues to DORA expectations across human, machine, and third-party access
- Practical examples of ISPM and ITDR workflows for regulated identity environments
- Vendor-specific evidence paths and automation examples for lifecycle governance and access review
- How Unosecur describes continuous privilege rationalisation and cross-cloud identity monitoring
👉 Read Unosecur's analysis of how DORA changes identity governance in finance →
DORA and identity governance: are your controls ready for audit?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Identity governance is now part of operational resilience, not a separate IAM workstream. DORA effectively collapses the distinction between access administration and resilience evidence because auditors will judge whether identity decisions can be traced, justified, and reviewed. The implication is that programmes built around siloed IAM tickets, periodic reviews, and informal vendor access will not produce the control narrative DORA expects.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing that remediation windows are still too slow for real-world exposure.
A question worth separating out:
Q: Who is accountable when identity controls fail under DORA?
A: Accountability sits with the institution, not just the IAM team. Financial firms must show that identity services, governance processes, and recovery paths were designed and tested as part of operational resilience, because DORA evaluates whether the business can withstand disruption, not whether a tool was installed.
👉 Read our full editorial: DORA exposes identity as the core resilience control in finance