← All industries
Industry deep dive

Finance — DORA, CBEST, NYDFS, MAS TRM

Continuous testing and threat-led validation for DORA and TIBER-EU, CBEST, NYDFS Part 500, MAS TRM and APRA CPS 234 — with ICT-incident evidence mapped in the same appliance.

DORA (Regulation (EU) 2022/2554) entered application on 17 January 2025 across all EU financial entities. Article 25 mandates continuous testing of ICT systems supporting critical or important functions, with a risk-based approach updated annually. Article 26 + the RTS 2025 on TLPT require threat-led penetration testing for significant entities at least every 3 years using a documented methodology (TIBER-EU). The European Banking Authority and the Banca d'Italia have made it clear that "continuous" means continuous, not "more frequent than annual" — and that the testing program must incorporate the latest threat intelligence, not a fixed playbook.

What is on the DORA-regulated CISO's desk

DORA Art. 24–25 testing program

A risk-based program of tests for ICT systems, with those supporting critical or important functions tested at least yearly (Art. 24(6)) — and supervisors increasingly expect evidence between those points. A single yearly report shows the controls held on one day.

DORA Art. 26 / TLPT RTS 2025

Threat-led pentest with TIBER-EU methodology, signed evidence, full chain-of-custody from the threat intelligence input to the final report.

ICT incident reporting (Art. 17-22)

Initial notification at 4h for major incidents, intermediate at 72h, final at 1 month. Same time pressure as NIS2 but with stricter materiality thresholds.

Third-party risk (Art. 28-30)

You inherit the regulator's scrutiny on every ICT third-party provider — including security tooling vendors. SaaS pentest providers are increasingly hard to justify in DORA-scoped procurement.

How Zero Hunt addresses DORA

Pillar 1 — Generative Pentest

Threat-led testing between TLPT cycles

The 10-agent swarm runs threat-led campaigns informed by live intelligence (CISA KEV, EPSS, vendor advisories and the other intelligence sources), with a methodology that maps onto the TIBER-EU phases (threat intelligence, red-team test, purple team, closure). Every phase is signed, so the evidence traces back to the intelligence that drove it — input for your TLPT and for the testing DORA Art. 24 expects between TLPTs. The TLPT itself still runs under the RTS, with the testers and authority oversight it prescribes.

Pillar 3 — Automatic Compliance

ICT incident evidence for DORA Art. 17-19 reporting

Detected events come with the timeline, affected assets and signed evidence your team needs to classify them against the DORA criteria and meet the 4h/72h/1-month reporting cadence. Findings and evidence are mapped to DORA controls and exported from the Trust Center as a signed bundle for auditors and supervisors.

Pillar 2 — AI Traffic Analysis

Wire-speed detection on the payments and trading boundary

AI traffic analysis on the appliance GPU catches the in-progress patterns: market-data exfiltration, payment-system C2, dwell-and-pivot attacks targeting clearing infrastructure. Real-time, not batch.

Capability emphasis for finance

  • ▸Continuous validation of critical ICT systems (Art. 25 baseline)
  • ▸TIBER-EU-aligned TLPT campaign workflow with signed evidence
  • ▸Signed incident evidence and timelines for DORA reporting
  • ▸4h / 72h / 1-month notification timeline as queryable workflow
  • ▸Third-party-risk story: 100% on-prem, no SaaS vendor in scope

Who buys this in finance

CISO sponsoring; Head of ICT Risk co-signing on DORA scope; Compliance / Internal Audit validating against the EBA technical standards; CFO authorizing on the basis that continuous validation between TLPT cycles replaces separate continuous-testing tooling and shortens TLPT preparation — the TLPT itself is still run by the testers the regulation requires (external, or internal ones with the approval of the authority and an external team every third test).

Frameworks mapped for this sector, worldwide

The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:

Global / cross-industry
  • SWIFT Customer Security Programme
  • PCI DSS
  • ISO/IEC 27001:2022
European Union
  • DORA
  • TIBER-EU
United States
  • NYDFS Part 500
  • GLBA / FTC Safeguards Rule
  • SEC cybersecurity disclosure rules
  • SOX IT controls
United Kingdom
  • CBEST / STAR-FS
Canada
  • OSFI Guideline B-13
Asia-Pacific
  • APRA CPS 234
  • MAS Technology Risk Management
  • RBI Cybersecurity Framework
  • FISC Security Guidelines
Middle East
  • Saudi NCA ECC / SAMA CSF
  • Bank of Israel Directive 361

Why this sector runs its AI red team on-premise, on private AI →

Go deeper on the regulations

Want to see this against your environment?

A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.