DORA and the Architectural Turn in Financial Services Resilience

By Sean O’Dowd, Head of Global Financial Services Strategy & Solutions, Nutanix

Financial services leaders are operating in a moment where resilience is no longer just a technology issue or a regulatory checkbox. It is increasingly a board-level concern tied to continuity, customer trust, and the ability to keep critical services running through disruption.

The shift is visible across markets. In the European Union (EU), the Digital Operational Resilience Act (DORA) has already entered into application, and its core message is clear: financial entities should be able to withstand, respond to, and recover from ICT disruptions such as cyberattacks or system failures. At the same time, other jurisdictions are sharpening expectations around third-party risk, incident readiness, and operational continuity, which means many organizations are now dealing with a convergence of similar demands rather than a single isolated rulebook. A recent example is the UK’s introduction of its Critical Third Party (CTP) regime, which complements and overlaps with DORA in its focus on systemic third-party risk.

That convergence matters because the resilience challenge is bigger than compliance language. Financial institutions are balancing legacy systems, hybrid infrastructure, cloud dependencies, cybersecurity threats, and growing pressure to prove they can operate through disruption. In practice, that means resilience planning now touches architecture, governance, vendor management, testing, reporting, and recovery design all at once.

A useful way to think about this is that resilience must be a design principle, not a governance overlay. It is not enough to protect the perimeter or recover after the fact. Organizations are being pushed to build environments that can absorb disruption, isolate it quickly, and restore service with minimal operational drag. That includes hard questions about where critical workloads live, how much dependence exists on a small number of providers, and whether the organization can move, restore, or re-sequence services when conditions change. In practical terms, this shows up as familiar architectural choices: portable workloads that aren't locked to a single provider, isolated and immutable recovery environments, segmentation that follows the application rather than the network, and telemetry that connects infrastructure events to business impact.

Third-party risk is one of the most visible pressure points. Financial services firms increasingly rely on external platforms for cloud, storage, cybersecurity, payments, data, and core operational services. That can create efficiency and scale, but it can also concentrate risk if resilience depends too heavily on a narrow vendor stack or a single deployment model. 

Industry reporting has consistently shown third-party involvement as a growing factor in operational and security incidents. DORA's emphasis on oversight of ICT providers reflects that reality, and it is one reason many institutions are re-examining portability, testing, and exit strategies as part of their resilience program.

Another reason resilience is rising up the agenda is that the threat environment itself has become more dynamic. Cyberattacks, outages, software failures, and supply chain issues can all affect service availability, but the operational impact is often what regulators, customers, and executives notice first. A firm may have strong security controls and still face business disruption if systems cannot fail over cleanly, critical applications cannot be isolated quickly, or recovery depends on manual steps that do not scale under stress. 

This is where infrastructure strategy starts to matter more than ever. Industry research suggests that most banks have moved past the "all-in public cloud" thesis of the early 2020s and are settling on hybrid architectures as a more durable destination. Organizations that design for resilience early can align their architecture with the realities of incident response, continuity, and recovery testing. That does not eliminate risk, but it can reduce the friction between policy intent and operational execution.

The conversation is also changing because regulators are increasingly interested in evidence, not intention. It is one thing to say an organization has resilience plans; it is another to show that those plans have been tested, that third-party dependencies are mapped, and that incident response can function under real-world conditions. In that sense, resilience is becoming measurable in a way that forces technology and business teams to work from the same playbook.

For many financial institutions, the next phase will be about making resilience more portable, observable, and repeatable. That includes creating environments that support workload mobility, stronger segmentation, recovery validation, and clearer visibility across distributed infrastructure. It also means simplifying how teams test and prove resilience over time, rather than treating it as a once-a-year audit exercise.

There is also a strategic upside here. Institutions that modernize with resilience in mind may find they can move faster, reduce operational complexity, and make better decisions about cloud, security, and vendor mix. In other words, resilience does not have to slow innovation. Done well, it can help enable it.

The most useful conversations are not just about compliance readiness, but about how to build a financial services environment that is adaptable enough to handle the next disruption, not just the last one. This is exactly the kind of environment Nutanix has been designed to support: one where resilience depends on portability, observability, and operational consistency across hybrid multicloud infrastructures. 

For a detailed look at how the Nutanix platform aligns to the architectural questions DORA raises, and how the global frameworks converging around it are reshaping the BFSI conversation, download our whitepaper: Building a Resilient Financial Services Infrastructure: DORA and Beyond.

©2026 Nutanix, Inc. All rights reserved. Nutanix, the Nutanix logo and all Nutanix product and service names mentioned are registered trademarks or trademarks of Nutanix, Inc. in the United States and other countries. All other brand names mentioned are for identification purposes only and may be the trademarks of their respective holder(s). Certain information contained in this content may link or refer to, or be based on, studies, publications, surveys, and other data obtained from third-party sources. While we believe these third-party studies, publications, surveys, and other third-party data are reliable as of the date of publication, they have not independently verified unless specifically stated, and we make no representation as to the adequacy, fairness, accuracy, or completeness of any information obtained from a third-party. Our decision to publish, link to or reference third-party data should not be considered an endorsement of any such content.