Financial institutions should use data-centric security to maintain control over sensitive data as it moves across internal systems and third parties. Under DORA, the focus is on protecting data in use, in transit, and at rest, while preserving confidentiality, integrity, authenticity, and availability. Persistent controls, classification, and activity visibility help teams prove resilience and support audit and reporting obligations.
Why This Matters for Security Teams
Data-centric security matters to DORA compliance because regulated institutions cannot rely on perimeter controls alone when data is continuously exchanged with cloud platforms, payment processors, managed service providers, and internal analytics tools. DORA expects operational resilience to hold up under disruption, so security teams need persistent controls that move with the data itself, not just with the network boundary. That means knowing where critical data lives, who can touch it, and whether it can be trusted after transfer or processing. The DORA — Digital Operational Resilience Act places real weight on this operational view of resilience. For financial institutions, the practical issue is not simply confidentiality. Integrity failures can corrupt reporting, availability failures can interrupt customer service, and weak provenance can make it impossible to show which system altered a record. Data-centric security gives teams a way to attach policy, classification, encryption, tokenisation, and access rules to the information itself, which helps support audit evidence and incident response. In practice, many security teams encounter weak data governance only after a third-party integration or recovery test has already exposed it.How It Works in Practice
Effective implementation starts with identifying which data sets are operationally critical, regulated, or highly sensitive, then applying controls based on business impact and processing context. For DORA, that usually means treating customer records, payment data, identity attributes, logs, and model inputs as controlled assets throughout their lifecycle. A useful reference point is the NIST Cybersecurity Framework 2.0, especially its emphasis on governance, asset management, protective technology, and recovery. A workable program usually includes:- Data classification tied to handling rules so controls follow the record, file, or event stream.
- Encryption in transit and at rest, plus strong key management and rotation.
- Tokenisation or masking for production-like use in test, analytics, and support environments.
- Activity logging that shows access, export, modification, and deletion events.
- Data loss prevention and policy enforcement for file movement, sharing, and API access.
- Retention and deletion rules that are consistent across subsidiaries, vendors, and cloud regions.
Common Variations and Edge Cases
Tighter data-centric controls often increase operational overhead, requiring institutions to balance resilience gains against latency, user friction, and integration complexity. That tradeoff is especially visible in high-volume payment processing, fraud analytics, and cross-border operations where data must move quickly without losing traceability. Best practice is evolving for AI-assisted processing and automated decisioning. If institutions use large language models, fraud models, or agentic workflows on regulated data, they need to treat prompts, retrieval sources, training sets, and output handling as part of the protected data perimeter. Current guidance suggests that DORA-aligned controls should cover not only production records, but also derived data, logs, and exports that can recreate sensitive content. That is where the line between cybersecurity, model governance, and operational resilience starts to blur. Edge cases also include outsourced recovery, shared services, and legacy core systems where encryption and tokenisation may not be uniformly available. In those environments, compensating controls such as segmentation, strict access review, immutable logging, and manual approval workflows may be necessary. Institutions should not assume that a vendor contract alone satisfies DORA expectations if the institution cannot still evidence control over the data path. Where identity data is part of the regulated processing chain, the assurance expectations described in NIST SP 800-63 Digital Identity Guidelines become especially important for proving who accessed what, when, and under which trust level.Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS | Data security protections map directly to the protect function for regulated information. |
| DORA | DORA requires institutions to prove operational resilience for critical digital services and data. | |
| NIST SP 800-63 | IAL/AAL/FAL | Identity assurance levels support trustworthy access to sensitive financial data. |
| NIST SP 800-53 Rev 5 | SC-13 | Cryptographic protection is essential for data in transit and at rest. |
| ISO/IEC 27001:2022 | A.5, A.8 | ISMS governance and asset controls support repeatable data-centric security operations. |
Classify critical data and enforce encryption, access controls, and monitoring across its lifecycle.
Related resources from NHI Mgmt Group
- How should financial institutions use identity governance for DORA and NIS2 compliance?
- How should financial institutions use behavioural analytics to support CSCRF compliance?
- How should financial institutions secure non-human identities to support DORA compliance?
- How should financial institutions use converged identity and access management to support digital transformation without weakening security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org