Jonas Osman Abdelghafour | Banking Risk & ComplianceGeopolitical Compliance Series

Banking governance, prudential risk and compliance · 2026 series

DORA, Cyber Conflict and Financial Resilience

Applying DORA-style resilience disciplines when cyber threats are amplified by geopolitical tension.

The current challenge

State-linked campaigns and conflict spillovers can turn ordinary ICT weaknesses into correlated disruption across institutions. The practical difficulty is that geopolitical events rarely remain within a single risk category. They transmit through customers, suppliers, markets, payment channels, technology, law, reputation and confidence. A control framework that reviews each dimension separately may therefore miss the combined exposure.

Decision-makers should distinguish verified events from assessment, and assessment from scenario. The aim is not to claim certainty about politics. It is to identify how a plausible event could affect the organisation, what evidence would change the view and which actions remain lawful and operationally achievable.

A risk-based compliance response

Map critical services, test severe scenarios, govern third parties, preserve incident evidence and rehearse recovery decisions. This response should be proportionate to exposure and grounded in current legal requirements. Jurisdiction, customer, product, transaction, distribution channel and technology all matter. Geography alone is neither a sufficient control nor evidence of misconduct.

  1. Define scope and ownership. Record which entities, products and decisions are covered and who may approve, stop or escalate activity.
  2. Map exposure and transmission. Connect direct counterparties with beneficial owners, intermediaries, suppliers, routes, currencies and critical technology.
  3. Use current authoritative data. Time-stamp sanctions lists, regulatory guidance and intelligence; preserve source lineage and confidence.
  4. Apply controls at decision points. Screen and investigate before onboarding, contracting, shipment, payment and material amendments—not only at account opening.
  5. Test effectiveness. Measure missed risk, false alerts, investigation quality, response time, overrides and repeat findings.

Scenario analysis

Illustrative scenario: A cyberattack disrupts payments while misinformation creates a liquidity and customer-communication crisis.

The scenario should be translated into observable drivers and tested across more than one severity. Teams should consider second-order effects, including customer behaviour, legal uncertainty, funding needs, market liquidity, operational capacity and the availability of insurance or alternative suppliers. Assumptions should be internally consistent and reviewed by both subject-matter and risk specialists.

Controls and evidence that withstand challenge

A defensible decision file explains what was known, when it was known, which rule or policy applied, how uncertainty was treated and why the action was proportionate. Useful evidence includes ownership records, source documents, screening results, investigator notes, model versions, approvals, exceptions and follow-up dates.

Proportionality, legal interpretation and customer impact

Risk-based compliance is not the same as automatic de-risking. A control should respond to the specific legal obligation and evidenced risk, not to nationality or geography alone. Where activity is restricted, teams should identify whether a prohibition, licence, exemption, reporting duty or enhanced-control requirement applies. Legal interpretation must be current, documented and linked to the actual transaction.

Institutions should also test unintended consequences. Excessive friction can obstruct lawful trade, financial inclusion or humanitarian activity, while weak controls can expose the firm and society to serious harm. Good governance makes that trade-off visible, involves the right specialists and provides a route to challenge or appeal where appropriate.

Data, technology and human accountability

Technology can connect large volumes of ownership, transaction, vessel, trade and event data, but it also inherits missing fields, inconsistent identifiers and historical bias. Data quality should be measured at the decision level: whether the information is complete, timely and reliable enough for the particular action. Model outputs should state uncertainty and the important drivers behind a recommendation.

Human review is meaningful only when reviewers have sufficient time, competence, evidence and authority to disagree. Escalation teams should understand both the regulation and the underlying business. Overrides must be visible, reasoned and monitored; repeated overrides often indicate a policy, data or model problem rather than exceptional cases.

Metrics for management and the board

Volume statistics alone can create false comfort. Reporting should include exposure by risk driver, alert ageing, decision turnaround, high-risk overrides, data-quality gaps, failed controls, scenario loss ranges and whether agreed actions reduce vulnerability. Trends should be explained, not merely displayed.

Questions the board should ask

Common failure modes

Typical weaknesses include treating a screening match as the whole risk assessment, relying on stale ownership data, using country scores without exposure logic, duplicating shocks across models, confusing the absence of an alert with evidence of safety, and allowing commercial urgency to bypass escalation. Each failure is fundamentally a governance problem as much as a technology problem.

Implementation roadmap

  1. First 30 days: identify material exposures, obligations, accountable owners and urgent control gaps.
  2. Days 31–60: connect data, scenarios, decision rules and escalation thresholds; test high-risk cases.
  3. Days 61–90: validate effectiveness, remediate findings, train users and establish board reporting.

Conclusion

Applying DORA-style resilience disciplines when cyber threats are amplified by geopolitical tension. The strongest framework combines current legal interpretation, transparent risk analysis, reliable evidence and timely human accountability. Complexity is justified only when it improves a real decision.

Primary sources and further reading

Related analysis

About the author

Jonas Adam Mohamed Osman Abdelghafour, known as Yonas Osman, publishes independent analysis on geopolitical risk, financial compliance, banking, insurance and quantitative risk modelling.

This article is educational analysis, not legal advice. Organisations should obtain advice for their jurisdictions and facts.