Case Studies

Real-World DORA Compliance Transformations

How financial institutions across Europe are navigating operational resilience regulation — with measurable outcomes, honest lessons, and actionable insights.

FeaturedInfrastructureIberian Financial Infrastructure (Cross-Sector)

The 2025 Iberian Blackout: DORA's First Real-World Stress Test

On April 28, 2025, a cascading power failure knocked out 15 GW across Spain and Portugal in five seconds, plunging 60 million people into darkness and crippling financial services infrastructure for hours — just three months after DORA became applicable.

Pillar IPillar IIPillar IIIPillar IVApril 28, 2025 (~10 hours; full POS/ATM restoration April 29)
Read full case study

People Affected

60 million

Spain + Portugal combined

Power Lost

15 GW in 5 seconds

60% of Spain's demand

Card Spending Drop

-41 to 42%

ECB Economic Bulletin data

E-commerce Spending Drop

-54%

ECB Economic Bulletin data

Blackout Duration

~10 hours

Full POS/ATM restoration next morning

Estimated GDP Losses

EUR 400M-1.6B

Broader impact EUR 2-3B

Industry
Pillar
InfrastructureGlobal Financial Infrastructure (Cross-Sector)

CrowdStrike/Microsoft Global Outage: The Concentration Risk DORA Was Designed to Prevent

On July 19, 2024, a faulty CrowdStrike Falcon sensor update crashed approximately 8.5 million Windows devices globally, disrupting banks, payment processors, and insurers worldwide.

Pillar IPillar IVPillar V

Devices Affected

N/A~8.5M globallyPublicly reported by Microsoft
July 19, 2024 (single day event; multi-day recovery)Read case study
InfrastructureCritical Derivatives Trading Infrastructure Provider

ION Trading Group Ransomware Attack: When a Critical Derivatives Infrastructure Provider Goes Dark

On January 31, 2023, the LockBit ransomware group attacked ION Trading Technologies, a Dublin-based provider of critical derivatives trading infrastructure, forcing 42 clients including major clearing firms to revert to manual processing.

Pillar IIPillar IVPillar I

Clients Affected

N/A~42Per press reports
January 31, 2023 (attack); ~5 days recoveryRead case study
BankingECB-Supervised Banks (109 Institutions)

ECB Cyber Resilience Stress Test 2024: What 109 Banks Revealed About Recovery Gaps

In 2024, the European Central Bank conducted its first-ever cyber resilience stress test across 109 directly supervised banks, finding that while response frameworks exist, significant recovery capability gaps remain.

Pillar IIIPillar IPillar II

Banks Tested

N/A109First-ever ECB cyber stress test
H1 2024 (exercise); July 26, 2024 (results published)Read case study
BankingDutch Financial Sector (Cross-Segment)

DNB DORA Preparedness Survey: Why Dutch Financial Institutions Underestimated the Scope

De Nederlandsche Bank surveyed Dutch financial institutions on DORA readiness in 2024, finding widespread underestimation of the regulation's scope and complexity, particularly around ICT risk management frameworks and third-party oversight.

Pillar IPillar IVPillar III

Institutions Supervised

N/A300+DNB supervisory scope
2024 (ongoing supervisory assessment)Read case study
BankingEU Financial Entities (Cross-Sector)

ESMA Register of Information: The Art. 28(3) Data Challenge That Caught the Sector Off Guard

Financial entities across the EU faced their first mandatory submission of the register of information on ICT third-party arrangements under DORA Art. 28(3), revealing widespread data completeness challenges and operational complexity.

Pillar IV

Data Tables in ITS

N/A6 (B.01-B.06)Per ESMA ITS
2024-2025 (preparation and first submission cycle)Read case study
PaymentsForeign Exchange Services Provider (Bank Third-Party)

Travelex Ransomware Attack (2019): What DORA Would Have Required

On December 31, 2019, Travelex — a major foreign exchange services provider to global banks — was hit by REvil ransomware, taking systems offline for weeks, disrupting bank customers, and ultimately contributing to the company entering administration.

Pillar IVPillar IIPillar I

Systems Offline Duration

N/A~2-3 weeksPer press reports
December 31, 2019 (attack); August 2020 (administration)Read case study
InfrastructureNational Financial Infrastructure (Government Registry)

France's National Bank Account Database Breach: 1.2 Million Records and DORA's Incident Reporting Test

In February 2026, attackers exfiltrated 1.2 million records from FICOBA — France's national registry linking citizens to bank accounts — exposing the tension between centralized financial databases and DORA's incident reporting requirements.

Pillar IPillar IIPillar IV

Records Exfiltrated

N/A1.2 millionFrom national banking registry
February 2026 (breach disclosed February 19-22, 2026)Read case study
BankingUS Financial Institutions (Multi-Bank)

Seedworm APT in US Bank Networks: Iranian Cyber Warfare Meets Financial Infrastructure

In March 2026, security researchers revealed that Seedworm (MuddyWater), an Iranian state-sponsored APT group, had infiltrated multiple US financial institution networks — raising urgent questions about nation-state threats to banking infrastructure.

Pillar IPillar IIPillar V

Dwell Time (estimated)

N/AMonths before detectionLong-term persistence prioritized over quick exploitation
March 2026 (disclosed March 5, 2026; intrusions potentially active for months prior)Read case study
BankingUS Financial Sector (Systemic)

US Banks on High Alert: Financial Sector Cyber Mobilization During the Iran War

In March 2026, US financial regulators and banks activated emergency cyber defense protocols as military conflict with Iran escalated — testing the financial sector's ability to coordinate defense against anticipated retaliatory cyberattacks.

Pillar IPillar IIPillar IIIPillar V

Sector Alert Level

BaselineMaximum (FS-ISAC highest tier)First time since 9/11 aftermath
March 2026 (mobilization ongoing as of reporting)Read case study
InvestmentFixed Income Securities Dealer

ASIC vs FIIG Securities: Australia's Landmark Cybersecurity Civil Penalty for Financial Services

In March 2026, the Australian Securities and Investments Commission (ASIC) obtained landmark civil penalties against FIIG Securities for cybersecurity failures — establishing a regulatory precedent with direct implications for DORA enforcement in Europe.

Pillar IPillar II

Client Assets Under Management

N/AAUD 6 billionMid-tier firm held to high standard
March 2026 (ASIC enforcement action reported March 25, 2026)Read case study
BankingUS Top-10 Bank (Retail and Commercial)

Capital One Days-Long Outage and Class Action: When Banking Infrastructure Fails

In January 2025, Capital One suffered a multi-day outage that locked customers out of accounts, delayed direct deposits, and triggered a class action lawsuit — demonstrating the legal and operational consequences of inadequate resilience.

Pillar IPillar IIPillar III

Outage Duration

N/AMultiple daysStarted January 18, 2025; persisted through January 22+
January 18-22+, 2025 (outage); January 29, 2025 (class action filed)Read case study
InfrastructureEuropean Central Bank Payment Infrastructure

ECB Multi-Trillion Payment System Outage: When Europe's Financial Plumbing Breaks

In late February 2025, the European Central Bank's TARGET/T2 payment system — processing trillions of euros in interbank settlements daily — suffered outages that disrupted the financial backbone of the eurozone.

Pillar IPillar IIPillar IV

Daily Transaction Volume

N/A~350,000 transactions/daySeveral trillion euros daily at risk
February 27-28, 2025 (outages); March 10, 2025 (Reuters follow-up)Read case study
BankingUK Systemically Important Bank (Ring-Fenced)

NatWest Locks Out Millions: The June 2025 App Failure That Tested Mobile-Only Banking

In June 2025, NatWest's mobile banking app suffered a major failure that locked out millions of customers, reigniting the debate about the resilience of mobile-first banking strategies in the UK.

Pillar IPillar IIPillar III

Customers Affected

N/AMillionsFrom 19M customer base
June 6, 2025 (The Guardian reporting)Read case study
InfrastructureInternet Infrastructure / DeFi / Fintech (Cross-Sector)

Cloudflare Outage Cascades Into DeFi: When Internet Infrastructure Concentration Meets Finance

In November 2025, a Cloudflare outage cascaded into decentralized finance protocols and traditional fintech services, demonstrating that even "decentralized" financial systems depend on concentrated internet infrastructure.

Pillar IPillar IV

Cloudflare Global Traffic Share

N/A~20% of all web trafficSingle provider serving 1/5 of internet
November 18, 2025 (outage); November 21, 2025 (Galaxy DeFi analysis)Read case study
InfrastructureCloud Infrastructure and Data Center Operators (Gulf Region)

Iranian Strikes on Data Centers: A Legal Analysis Under International Law and DORA

In March 2026, legal scholars analyzed the implications of Iranian retaliatory strikes potentially targeting data centers in the Gulf region — raising unprecedented questions about the intersection of armed conflict, international law, and digital operational resilience.

Pillar IPillar IIIPillar IV

Gulf Data Center Growth

Minimal presence (2015)Major cloud hubs (AWS, Azure, GCP, Oracle)Rapid build-out now in conflict zone
March 2026 (legal analyses published March 12-17, 2026)Read case study
InfrastructureCross-Border Regulatory Framework

The UK-EU Critical Third-Party MoU: Post-Brexit Regulatory Cooperation on Cloud Oversight

In January 2026, the Bank of England and EU supervisory authorities signed a memorandum of understanding on the oversight of critical third-party technology providers — the first concrete post-Brexit regulatory cooperation mechanism for cloud and ICT infrastructure oversight.

Pillar IV

Regulatory Frameworks Coordinated

Independent UK + EU regimesCoordinated via MoUFirst post-Brexit CTP cooperation mechanism
January 14, 2026 (Bank of England MoU announcement)Read case study
BankingECB Banking Supervision (Eurozone-Wide)

ECB Annual Report on Supervisory Activities 2025: What the Numbers Reveal About Digital Resilience

The ECB's March 2026 annual report on supervisory activities provided the first comprehensive post-DORA dataset on digital resilience across eurozone banks — revealing significant gaps between compliance documentation and operational reality.

Pillar IPillar IIPillar IIIPillar IV

Institutions Assessed

N/A109 significant institutions + LSIsFirst DORA-specific SREP assessment
March 18, 2026 (ECB annual report publication)Read case study
InfrastructureMajor Cloud Service Provider (Hyperscaler)

Microsoft's Concentration Risk Framework: A Cloud Provider Writes Its Own DORA Compliance Guide

In February 2026, Microsoft published a comprehensive framework for managing cloud concentration risk and exit strategies under DORA — the first major cloud provider to proactively address its own systemic importance.

Pillar IV

Framework Scope

No provider guidanceComprehensive concentration risk + exit frameworkFirst major cloud provider to publish DORA-aligned guidance
February 2, 2026 (Microsoft framework publication)Read case study
InfrastructureCloud Infrastructure Provider (Hyperscaler)

AWS Officially Confirms Bahrain Region 'Disrupted' Following Drone Activity

On March 24, 2026, Reuters exclusively reported that AWS officially confirmed service disruptions to its Bahrain cloud region (me-south-1) following military drone activity in the Gulf — the first confirmed case of a major cloud region disrupted by armed conflict.

Pillar IPillar IIIPillar IV

Cloud Region Status

Fully operationalOfficially confirmed disruptedFirst confirmed military-related cloud disruption
March 24, 2026 (Reuters exclusive report)Read case study
InfrastructureData Center and Cloud Infrastructure (India)

India's Data Center Boom: How the Gulf Strikes Accelerated South Asia's Cloud Ambitions

Following military strikes near Gulf data centers in March 2026, India emerged as the primary beneficiary of cloud workload migration — with financial institutions rapidly shifting critical infrastructure to Indian cloud regions perceived as geopolitically safer.

Pillar IPillar IV

Cloud Migration Demand Surge

Normal growth300-400% increase in 2 weeksGulf-to-India workload migration
March 2026 (multiple reports documenting migration acceleration)Read case study
BankingGlobal Financial System (Systemic)

Goldman at 30% Recession Odds: When Geopolitical Conflict Creates Systemic Financial Stress

On March 25, 2026, Goldman Sachs raised its US recession probability to 30% amid Iran conflict-driven oil price shocks — demonstrating how geopolitical events create cascading stress across financial systems that operational resilience must withstand.

Pillar IPillar IIPillar III

Recession Probability

15%30%Doubled in weeks due to Iran conflict
March 25, 2026 (Goldman Sachs recession probability update)Read case study
BankingUS Federal Government / Financial Sector

White House Cybercrime Executive Order 2026: Implications for Financial Institutions

On March 24, 2026, the White House issued an executive order strengthening cybercrime enforcement and cross-sector cybersecurity requirements — with direct implications for financial institutions operating in or connected to the US financial system.

Pillar IPillar IIPillar V

Regulatory Frameworks

DORA (EU) onlyDORA + US EO + UK CTPGlobal convergence on financial cybersecurity
March 24, 2026 (White House executive order issued)Read case study
BankingGlobal Systemically Important Bank (G-SIB)

HSBC Digital Banking Outage: When a Global Bank's App Goes Silent

In August 2025, HSBC experienced a significant digital banking outage affecting mobile and online banking services for customers across multiple markets.

Pillar IPillar II

Customers Served

N/A~40 million globallyScale amplifies impact of any outage
August 2025Read case study
BankingNorth American Systemically Important Bank

TD Bank System Failure: The November 2025 Outage That Hit North American Banking

In November 2025, TD Bank experienced a system failure that disrupted banking services for millions of customers across the US and Canada.

Pillar IPillar IIPillar III

Customers Affected

N/A~27 million (US + Canada)Dual-country impact from shared infrastructure
November 2025Read case study
InfrastructureCentral Bank (Emerging Market)

Bangladesh Central Bank Server Failure: Digital Banking Disruption in an Emerging Market

In December 2025, Bangladesh Bank experienced a critical server failure disrupting digital banking services across the country.

Pillar IPillar II

Mobile Money Accounts

N/A100+ million affectedNational-scale disruption
December 5, 2025Read case study
BankingEurozone Systemically Important Bank

Santander Online Banking Down: Another Day, Another Major Bank Outage

In March 2025, Santander online banking went down — adding to the pattern of recurring major bank outages in the first months of DORA applicability.

Pillar IPillar II

EU Bank Outages (Jan-Mar 2025)

DORA applicable Jan 17Barclays + TARGET2 + Santander3 major outages in first 2 months of DORA
March 6, 2025Read case study
BankingBrazilian Banking Sector

Astaroth Banking Trojan: How WhatsApp Became a Vector for Financial Malware in Brazil

In January 2026, the Astaroth banking trojan was distributed through WhatsApp in Brazil, demonstrating how messaging platform dependencies create novel attack vectors.

Pillar IPillar IIPillar V

Customers Targeted

N/AHundreds of thousandsMulti-bank campaign
January 8, 2026Read case study
BankingUS Banking Industry Association

BPI and the 2026 National Cybersecurity Strategy: Banking Industry's Response to Evolving Threats

On March 6, 2026, the Bank Policy Institute published its response to the 2026 National Cybersecurity Strategy, closely aligning with DORA principles.

Pillar IPillar V

BPI-DORA Alignment

N/AHigh across all 5 pillarsUS industry advocating DORA-equivalent capabilities
March 6, 2026Read case study
InfrastructureTechnology Infrastructure in Conflict Zone

NYT Analysis: How U.S. Tech Giants in the Gulf Became Military Targets

The New York Times analyzed how US technology infrastructure concentration in the Gulf created a novel military target category with implications for financial institutions.

Pillar IPillar IV

US Tech Investment

BillionsNow military target categoryCivilian investment in conflict zone
March 13, 2026Read case study
InfrastructureGulf AI and Data Center Infrastructure

Iranian Drone Strikes Test the Gulf's Trillion-Dollar AI Dream

Rest of World analyzed how Iranian strikes threatened the Gulf states' AI and data center investments with cascading implications for financial AI.

Pillar IPillar IV

Gulf AI Investment

Hundreds of billions plannedTrajectory disruptedTrillion-dollar vision threatened
March 2, 2026Read case study
InfrastructureGlobal Technology Infrastructure

Iran Warns U.S. Tech Firms: 'You Could Become Targets'

WIRED reported Iran's explicit warning to US tech companies that their Gulf infrastructure could become military targets — first public state-actor threat to civilian technology infrastructure.

Pillar IPillar IV

Threat Status

TheoreticalExplicit state-actor warningFrom risk to confirmed threat
March 11, 2026Read case study
BankingGlobal Financial Sector

Destructive Attacks on Financial Institutions Surge 13%: The 2025 Cybersecurity Report

Infosecurity Magazine reported a 13% surge in destructive cyberattacks against financial institutions in 2025.

Pillar IPillar IIPillar IIIPillar V

Destructive Attack Growth

2024 baseline+13% in 2025Double-digit annual growth
February 5, 2025Read case study
BankingUK Systemically Important Bank (G-SIB)

Barclays Three-Day Mainframe Outage: GBP 12.5M in Compensation and the Case for DORA Art. 11

On January 31, 2025, a software problem in Barclays' UK mainframe locked millions of customers out of their accounts for three days — coinciding with payday and the UK tax deadline.

Pillar IPillar IIPillar III

Outage Duration

RTO target: 4-24h72 hours3-18x over typical DORA-aligned RTO
January 31 - February 2, 2025 (72-hour outage)Read case study
InfrastructureCritical Third-Party ICT Provider (CTPP)

AWS October 2025 Global Outage: 17 Million Reports, Banking Disruption, and DORA's Concentration Thesis Proven

A malfunctioning internal subsystem in AWS northern Virginia triggered one of the largest internet outages on record, suspending trading on Coinbase and locking customers out of Lloyds and Bank of Scotland.

Pillar IPillar IIPillar IV

User Reports

Normal baseline17 million (970% spike)Largest single-provider outage reports in 2025
October 20, 2025 (15-24 hours)Read case study
InfrastructureGulf Financial Services Infrastructure (Cross-Sector)

AWS Dubai AZ Outage 2026: When DORA's CTPP Framework Meets Gulf Financial Infrastructure

An availability zone failure in AWS's UAE region (me-central-1) disrupted financial services workloads across the Gulf — testing DORA's extraterritorial reach and the cloud concentration assumptions of an entire region.

Pillar IPillar IIPillar IV

Cloud Concentration

Not formally assessedAWS + Azure >70% of Gulf financial workloadsArt. 29 concentration risk now quantified
Early 2026 (AWS me-central-1 AZ failure)Read case study
BankingBanking Software Vendor (Supply Chain)

Marquis Software Solutions: One Vendor, 74 Banks, 672,000 People Exposed — The DORA Third-Party Risk Nightmare

The Akira ransomware group exploited a single SonicWall firewall vulnerability to breach one vendor and compromise customer data across 74 US banks.

Pillar IIPillar IV

Vendor-to-Bank Ratio

N/A1:74Single vendor compromise = 74 institutions breached
August 14, 2025 (breach); September-October 2025 (notifications)Read case study
InfrastructureCritical Third-Party ICT Provider (CTPP)

Azure Front Door Global Outage: $4.8B-$16B in 8 Hours and the Multi-Cloud Reality Check

A configuration change in Azure Front Door cascaded into an approximately 8-hour global disruption, impacting Barclays, Lloyds, and Bank of Scotland — with estimated losses in the billions.

Pillar IPillar IV

Outage Duration

N/A~8 hoursGlobal Front Door service unavailable
2025 (~8-hour global disruption)Read case study
BankingBanking-as-a-Service Provider

Evolve Bank & Trust: $11.85M Settlement After BaaS Supply Chain Breach — The DORA Subcontracting Warning

LockBit ransomware compromised Evolve Bank, exposing 18 million individuals through the Synapse Financial Technologies BaaS chain — resulting in the largest US banking breach settlement of 2025.

Pillar IIPillar IV

Individuals Affected

018 millionLargest BaaS-related breach
2024 (breach); December 15, 2025 ($11.85M settlement final approval)Read case study
BankingEuropean Systemically Important Bank (G-SIB)

Santander/Snowflake Breach: When Your Cloud Data Platform Becomes the Entry Point

Stolen Snowflake credentials obtained via infostealer malware exposed Santander customer data across three countries — part of a broader campaign that compromised over 160 organizations.

Pillar IPillar IV

Countries Affected

N/A3 (Chile, Spain, Uruguay)Multi-jurisdictional reporting required
Mid-2024 (breach); October 2024 (arrests in Canada)Read case study
InfrastructureEU Financial Sector (Cross-Entity)

Register of Information: What the First Submission Taught 22,000 Financial Entities About Their Own Supply Chains

The April 2025 Register of Information submission was the first time most financial entities attempted to comprehensively document their ICT third-party arrangements — and the results revealed systemic blind spots.

Pillar IV

Entities Submitting

N/A10,000+ EU financial companiesFirst comprehensive sector-wide ICT inventory
April 4-30, 2025 (first submission window); May 2025 (second validation round)Read case study
InfrastructureCritical Third-Party ICT Service Providers

The 19 CTPPs: How ESA Designation Changed the Cloud Provider-Bank Relationship Forever

On November 18, 2025, the ESAs designated 19 Critical Third-Party Providers — including AWS, Google, Microsoft, Oracle, and SAP — subjecting them to direct EU supervisory oversight for the first time.

Pillar IV

Providers Designated

0 (pre-DORA)19 CTPPsFirst-ever direct EU oversight of tech providers
November 18, 2025 (designation); 12 months for EU subsidiary establishmentRead case study
BankingNordic Banking Sector (DNB, Nordea, SEB, Handelsbanken)

Nordic Banks DORA Implementation: How Scandinavian Financial Institutions Built a Shared Resilience Framework

Facing DORA's requirements with lean compliance teams, Nordic financial institutions pooled resources, shared testing infrastructure, and developed common frameworks — achieving faster compliance at lower cost.

Pillar IPillar IIIPillar V

Cost Reduction

Independent implementationCollaborative framework30-40% estimated savings
2024-2025 (implementation period; operational by January 2025)Read case study
BankingEuropean G-SIB (French Banking Group)

A French Banking Group's EUR 100M DORA Programme: Lessons From the Largest Known Implementation

One of Europe's largest financial groups invested nearly EUR 100 million in its DORA compliance programme — the most expensive known implementation. Here's what they learned.

Pillar IPillar IIPillar IIIPillar IVPillar V

Total Programme Investment

N/A~EUR 100MLargest known DORA implementation
2023-2025 (24-month programme; operational January 17, 2025)Read case study
BankingItalian Financial Infrastructure (Cross-Sector)

DDoS Campaigns Against Italian Financial Infrastructure: NoName057, Geopolitics, and DORA's Information Sharing Response

Pro-Russian hacktivists launched over 1,500 DDoS attacks across Europe, repeatedly targeting Italian banks and financial infrastructure — until Europol dismantled the operation in July 2025.

Pillar IIPillar V

Total Attacks

N/A1,500+ DDoS attacksMarch 2022 - July 2025
March 2022 - July 2025 (3+ year campaign; Europol takedown July 2025)Read case study
BankingUK Major Retail Banks (Multi-Institution)

Lloyds, Halifax, TSB, Nationwide — All Down on Payday: The Multi-Bank Outage DORA Was Designed to Prevent

On February 28, 2025, four major UK banks simultaneously failed to process transactions on payday — the single most critical day of the month for consumer banking.

Pillar IPillar II

Banks Affected

Normal operations6 simultaneously (Lloyds, Halifax, TSB, Nationwide, First Direct, BoS)Multi-institution correlated failure
February 28, 2025 (payday outage, several hours)Read case study
BankingEuropean G-SIB (Regional Operations)

Deutsche Bank India Deepfake CEO Fraud: EUR 120K Lost and the DORA Training Requirement That Could Have Prevented It

A senior Deutsche Bank India executive transferred EUR 120,000 after a deepfake video call impersonating the CEO — demonstrating how AI-powered social engineering bypasses technical controls.

Pillar IPillar II

Amount Lost

EUR 0EUR 120,000 (INR 1.08 crore)Single deepfake video call
July 2025 (deepfake video call and fraudulent transfer)Read case study
InfrastructureEU Financial Regulatory Framework (Cross-Jurisdiction)

DORA Penalty Framework: How 27 Member States Created a Patchwork of Enforcement — And What It Means for Cross-Border Institutions

Despite DORA being a directly applicable EU Regulation, member states created dramatically different penalty regimes — from EUR 2 million in Czech Republic to EUR 20 million in Italy and 10% of turnover in Sweden.

Pillar I

Highest Absolute Penalty

No DORA penalties existedEUR 20M (Italy)Aligned with GDPR maximum
October 2025 (DLA Piper analysis published); January 2025 onwards (DORA applicable)Read case study

Facing similar challenges?

Valendir is the Operational Resilience OS used by regulated financial institutions to govern, test, prove, and report their DORA compliance — continuously, not annually.