Navigating DORA with Calico: Strengthening Kubernetes Operational Resilience in Financial Services

A single cyberattack or system outage can threaten not just one financial institution, but the stability of a vast portion of the entire financial sector. For today’s financial enterprises, securing dynamic infrastructure like Kubernetes is a core operational and regulatory challenge. The solution lies in achieving DORA compliance for Kubernetes, which transforms your cloud-native infrastructure into a resilient, compliant, and secure backbone for critical financial services.

The Challenge DORA Seeks to Solve

Before DORA (Digital Operational Resilience Act), rules for financial companies primarily focused on making sure they had enough financial capital to cover losses. But what if a cyberattack or tech failure brought a large part of the financial system down? Even with plenty of financial capital, a major outage could stop most operations and cause big problems for the whole financial market. DORA steps in to fix this. It’s all about making sure financial firms can withstand, respond to, and recover quickly from cyberattacks and other digital disruptions.

What is DORA?

The Digital Operational Resilience Act (DORA) is a European Union (EU) regulation that came into effect on January 17, 2025 and is designed to strengthen the security of financial entities. It establishes uniform requirements across the financial sector for managing Information and Communication Technology (ICT) risk, reporting major ICT-related incidents, conducting digital operational resilience testing, and overseeing ICT third-party risk. DORA applies to a broad range of financial entities, including banks, insurance companies, investment firms, payment service providers, and their ICT third-party service providers, ensuring a consolidated and robust approach to digital resilience across the European Union.

A visual representation of the five pillars of DORA (Digital Operational Resilience Act), including ICT Risk Management, ICT-Related Incident Management and Reporting, Digital Operational Resilience Testing, ICT Third-Party Risk Management, and Information Sharing.
Why DORA Matters for Kubernetes

Kubernetes is the standard for deploying and managing cloud-native containerized applications, offering unparalleled agility, scalability, and efficiency. However, this power comes bundled with complexity. For financial institutions leveraging Kubernetes, DORA’s requirements directly impact how their containerized environments are designed, secured, and operated. The dynamic, distributed nature of Kubernetes, with its dynamic flux of pods, services, and network connections, presents unique challenges in maintaining DORA compliance. Organizations must demonstrate granular visibility into their Kubernetes infrastructure, enforce strict access controls, manage third-party dependencies within their container images and supply chain, and ensure rapid incident response and recovery. Meeting DORA’s mandates in a Kubernetes environment requires a deep understanding of Kubernetes networking, network security, and observability, and the ability to apply these principles consistently across potentially large public cloud, hybrid, and on-premise deployments.

5 Ways Calico Products Can Help with DORA Compliance

Granular Network Microsegmentation and Policy Enforcement

DORA mandates robust ICT risk management frameworks, including effective security controls to protect critical assets. Calico empowers financial entities to implement fine-grained network microsegmentation for Kubernetes workloads, isolating applications and services to minimize the blast radius of attacks and breaches. Beyond basic Kubernetes Network Policies, Calico’s advanced policy engine supports policy tiers, allow and deny rules, DNS policies, and IP ranges, allowing organizations to create highly specific and enforceable security boundaries. This ensures that even if an attacker breaches one part of the system, lateral movement is severely restricted. This aligns directly with DORA’s requirement for preventing and containing ICT incidents.

Comprehensive Network Observability

DORA emphasizes proactive monitoring and timely reporting of ICT-related incidents. Calico provides deep network visibility and flow logging, correlating network activity with rich Kubernetes context. Calico Dynamic Service Graph visualizes network topology and traffic flows, enabling security teams to quickly identify anomalous behavior, unauthorized communication attempts, and potential threats. With features like real-time flow logs, DNS logs, and L7 (HTTP) logs, coupled with the ability to quickly detect and alert on suspicious events, Calico helps financial institutions meet DORA’s requirements for continuous monitoring and rapid incident detection and resolution.

Threat Detection and Mitigation

DORA requires that financial entities strengthen their detection, containment, and recovery capabilities. Calico workload-level Intrusion Detection/Prevention System (IDS/IPS) capabilities and utilizes threat intelligence feeds to identify and block communication with known malicious IPs and domains. Its workload-centric Web Application Firewall (WAF) protects against common HTTP-based attacks, and it can detect and mitigate DDoS attacks at the host level. This comprehensive threat detection and prevention capabilities directly contributes to DORA compliance by bolstering the organization’s ability to resist and respond to cyber threats, safeguarding the availability and integrity of financial services.

Automated Compliance Reporting and Audit Trails

DORA requires continuous adherence to security and resilience standards, often necessitating audit-ready documentation. Calico simplifies compliance by providing automated collection, correlation, and reporting of network activity and policy enforcement data to support various compliance standards, including PCI DSS, HIPAA, DORA, and NIST. Calico has the ability to monitor and log network traffic and all changes to network security policies to enable financial institutions to demonstrate continuous compliance and provide critical evidence during regulatory assessments, reducing the burden of manual reporting.

Case Study in Compliance: Aldagi

Aldagi logoGeorgia’s largest private insurance provider, Aldagi, faced a familiar challenge: securely migrating its services to the cloud to serve a growing customer base while meeting strict EU GDPR compliance.

By leveraging Calico Enterprise, Aldagi was able to achieve zero-trust workload access controls and gain critical visibility over sensitive data. Most importantly, Calico’s automated compliance reporting enabled them to continuously monitor their environment and provide audit-ready proof of compliance on demand.

The result? Aldagi securely deployed 20 new cloud-native applications, reducing application launch time from days to just five minutes.

Want to learn more? 👉 Read the full Aldagi Case Study to see how they achieved GDPR compliance with Calico.

Secure Multi-Cluster and Hybrid Cloud Operations

Financial institutions often operate across multiple Kubernetes clusters, on-premises data centers, and public cloud environments. DORA’s scope extends to these interconnected multi-cluster ICT systems. Calico Enterprise’s ability to provide consistent network security controls and observability across any Kubernetes distribution, hybrid cloud, and even integrating with VMs and bare-metal workloads, is crucial for mult-cluster and hybrid operations.

A diagram illustrating how Calico provides seamless scaling from a single Kubernetes cluster to multiple clusters. The diagram highlights Calico's capabilities for pod-to-pod connectivity, security, cross-cluster service discovery, and observability in a multi-cluster environment.

Calico Cluster Mesh feature enables seamless, secure communication and centralized policy management across disparate clusters, ensuring that DORA’s operational resilience requirements are met across multi-cluster deployments. This unified approach simplifies management and reduces the attack surface across heterogeneous environments.

Mapping DORA Requirements to Calico Capabilities

To help understand how Calico supports DORA compliance for Kubernetes environments we’ve included a mapping table that ties core DORA requirements to the relevant Calico capabilities.

DORA Requirement How Calico Helps Relevant Capabilities
ICT Risk Management & Security Controls – Implement strong defenses to protect critical assets and reduce impact of incidents. Calico can provide granular network microsegmentation to isolate workloads and restrict lateral movement, reducing attack blast radius. Network policies, policy tiers, staged policies, policy recommendations, DNS policies, Networksets
Continuous Monitoring & Incident Reporting – Proactive detection and timely reporting of ICT-related incidents. Calico delivers deep observability of Kubernetes network traffic with context-rich flow logs and real-time visualization for rapid detection of issues and anomalies. Flow logs (L3–L7), DNS logs, dashboards, Dynamic Service Graph, packet capture, alerting
Threat Detection, Containment & Recovery – Strengthen ability to detect, contain, and respond to cyber threats. Calico includes workload-level IDS/IPS, WAF, DDoS protection, and integration with threat intelligence feeds to block malicious IPs and domains. IDS/IPS, WAF, DDoS mitigation, threat intel integration, alerting
Compliance Evidence & Audit Trails – Maintain documentation to prove compliance during regulatory reviews. Calico automates compliance reporting, creates detailed traffic flow logs, logs policy changes, and produces audit-ready reports for regulators. Automated compliance reports, network policy change logs, flow logs (L3–L7), DNS logs, audit logs, and more
Resilience Across Multi-Cluster/Hybrid Environments – Ensure resilience across distributed ICT infrastructure, including cloud and on-prem. Calico enforces consistent security and observability across clusters, VMs, and bare metal, supporting hybrid and multi-cloud setups. Cluster Mesh, support for hybrid cloud security, support for VM and bare metal hosts, centralized policy mgmt, support for many Kubernetes distributions and dataplanes

Note probably the best summary of DORA is the EUR-Lex summary of Regulation (EU) 2022/2554. This summary provides an accessible overview of how DORA establishes uniform rules on the security of network and information systems for EU-regulated financial entities such as banks, insurers, and investment firms. And the actual Regulation (EU) 2022/2554, which is available for download in many different languages.

Summary

By leveraging Calico’s advanced networking, network security, and observability capabilities, financial institutions can systematically address the complex demands of DORA, transforming their Kubernetes deployments into resilient, compliant, and secure platforms for critical financial services.

Discover how Calico helps financial institutions meet DORA’s mandates. Schedule a demo today.

Join our mailing list

Get updates on blog posts, workshops, certification programs, new releases, and more!

X