Network security and operations for financial services
Industry

Financial Services & Fintech

DORA, MIFID II, PSD2 and AML applied to banks, fintech, asset managers and payment entities in Spain and Portugal.

How to prepare an IT decision in financial services and fintech

A useful assessment starts with an operational map: sites, users, applications, equipment, vendors, change windows and owners. In financial services and fintech, the priority is to understand resilience, control evidence and third-party management; a product list without that context cannot support a comparable option or a realistic scope.

Inventory and dependencies before scope is defined.
Inventory and dependencies before scope is defined.

The inventory links critical services, processes, data, ICT third parties, controls and evidence to an owner. Classification starts from the framework applicable to the entity, validated by compliance, and avoids presenting an obligation or sanction as universal.

Technical validation with documented acceptance criteria.
Technical validation with documented acceptance criteria.

Testing selects a traceable scenario such as provider loss, channel outage, restoration or incident escalation. Time, decision, communication, result and exception are recorded so the exercise can be repeated and audited.

Coordination and evidence handed over to the accountable team.
Coordination and evidence handed over to the accountable team.

The control view preserves source and period for availability, incidents, backups, changes and third parties. A metric with no data is shown as unknown, not as zero or as proof that the control works.

Documentation remains useful through a visible date, version and owner. Assumptions that have not yet been verified stay marked as assumptions and do not become commercial commitments.

Handover records results, exceptions, relevant configuration, tests and subsequent controls. This lets the internal team distinguish a completed improvement from an outstanding dependency and measure the service against data agreed for its environment.

DORA by entity and function : Regulation (EU) 2022/2554 has applied since 17 January 2025, but specific controls, tests and registers depend on the entity and its role. Scope is validated with compliance and legal counsel.

Typical challenges in financial services

  • MIFID II + reporting: full order traceability, microsecond time-stamping, encrypted voice recording, 5+ year retention.
  • PSD2 / SCA: open banking, Strong Customer Authentication, regulated APIs, TPP management.
  • Operational AML / KYC: anti-money-laundering screening, beneficial owners, source of funds, SEPBLAC reporting (Spain), BdP (Portugal).
  • Operational resilience: demonstrable capacity to survive major incidents without stopping critical service. Active-active or active-passive + tested business continuity.
  • Constant audits: BdE, CNMV, BdP, CMVM, EIOPA — each inspection asks for detailed technical evidence on tight deadlines.

How we tackle it at Impulso

  • Measurable operational resilience: active-active or active-passive architecture per RTO/RPO, major-incident drills every 6 months, real-time SLA metrics dashboard.
  • Defined coverage and escalation: service hours, priorities, response targets and third-party escalation are agreed per engagement; permanent availability or a fixed nationwide response is not assumed.
  • MIFID II / PSD2 documented compliance: order traceability, time-stamping, encrypted voice records, PSD2 APIs with full audit.
  • Operational AML / KYC: Refinitiv, Dow Jones or equivalent integration; automated screening and review flow.

Iberian financial regulatory framework

  • MIFID II (Directive 2014/65/EU): order traceability, product governance, voice recording, price transparency.
  • PSD2 (Directive 2015/2366/EU): open banking, SCA, TPP management.
  • AML / 6AMLD: anti-money-laundering. SEPBLAC (Spain) and BdP (Portugal) supervise.
  • GDPR + LOPDGDD / Law 58/2019: financial data special category when associated with health or behavior.
  • NIS2 scope to be validated: applicability, category, obligations and dates are checked against current official rules based on activity, size, country and supply-chain role; the legal or compliance team owns the legal determination.

Why Impulso for Iberian financial services

  • We approach financial services and fintech projects from the actual environment, its dependencies and the priorities agreed with the client. Scope is confirmed after reviewing locations, systems, access, risks and owners.
  • Case-by-case on-site coverage: our own team is based in Madrid and, elsewhere in Spain and Portugal, the suitable local resource or nearest available partner is assigned after location, resource, timing, scope and access are confirmed for each request.
  • Technology matched to the environment: vendors, licences, integrations and capabilities are validated during design; any certification or contractual requirement is confirmed before it enters a proposal.
  • Transparent terms: scope, windows, owners, dependencies and price are documented after the initial review, without assuming one fee or SLA fits every environment.

Frequently asked questions

  • What is reviewed before scoping an IT project for financial services and fintech?
    We review sites, users, inventory, applications, dependencies, vendors, access, incidents and change windows. For financial services and fintech, we also document resilience, control evidence and third-party management. Scope and objectives are confirmed from that evidence.
  • How are risks reduced during a change?
    Each change identifies prerequisites, an owner, a window, the prior state or backup, acceptance tests and rollback. When impact warrants it, validation starts with a representative site, system or group.
  • How is work coordinated with the internal team and other vendors?
    A responsibility matrix states who approves, performs, validates and receives each task. Carrier, vendor or software dependencies are recorded before dates are set, and handover includes decisions, results and open items.
  • Which metrics and evidence are useful?
    It depends on the objective: measured availability, recurring incidents, observed timings, inventory coverage, backup success, recovery tests, change compliance or site acceptance. The source and period of each metric should remain visible.
Let's talk

Want to know how we can help in your sector?

30 minutes with a senior consultant. No commitment, no sales pitch. An honest conversation about what you need and what we can do together.