Cybinity
Back to Insights
Zero Trust

Why Regulated Industries Are Accelerating Zero Trust in 2026

DORA, NIS2, and FCA operational resilience rules are converging on a single architectural answer. Here is why regulated industries can no longer treat Zero Trust as a future-state ambition.

By Cybinity Security Team
Why Regulated Industries Are Accelerating Zero Trust in 2026

The Regulatory Convergence

For years, Zero Trust Architecture was treated as a long-term aspiration — something to plan for in the next budget cycle, after the current infrastructure refresh, once the team had capacity. That window has closed.

In 2026, three converging regulatory frameworks are making Zero Trust a near-term operational requirement for organisations in financial services, critical infrastructure, and healthcare. DORA, NIS2, and FCA operational resilience rules don't mandate Zero Trust by name — but their requirements map almost exactly onto what a mature Zero Trust programme delivers.

DORA: ICT Risk Management at Scale

The Digital Operational Resilience Act came into full effect for EU financial entities in January 2025. Its ICT risk management requirements — covering network segmentation, access controls, identity management, and third-party risk — align closely with Zero Trust principles.

DORA's Article 9 requirements on protection and prevention explicitly call for network segmentation strategies that limit the blast radius of a compromise. Article 10 on detection requires continuous monitoring of network activity. These aren't abstract principles — they're audit checkpoints that regulators are actively testing.

Organisations that have deployed Zero Trust controls — particularly microsegmentation, identity-based access, and continuous authentication — are finding that DORA compliance becomes significantly more straightforward. Those relying on legacy perimeter architectures are discovering that their existing controls don't map cleanly to DORA's requirements.

NIS2: Raising the Bar for Critical Infrastructure

The NIS2 Directive, transposed into national law across EU member states through 2024 and 2025, substantially expands the scope of organisations subject to cybersecurity obligations. It now covers essential and important entities across energy, transport, banking, financial market infrastructure, health, digital infrastructure, and more.

NIS2's Article 21 security measures include network segmentation, access control, multi-factor authentication, and supply chain security — all core components of a Zero Trust architecture. The directive also introduces personal liability for senior management, which has concentrated board-level attention on cybersecurity posture in a way that previous frameworks did not.

FCA Operational Resilience: The UK Dimension

The FCA's operational resilience framework, which reached its full implementation deadline in March 2025, requires UK financial services firms to demonstrate that they can remain within impact tolerances for important business services during severe but plausible disruption scenarios.

While the FCA framework is outcome-focused rather than prescriptive about architecture, the practical requirements — mapping dependencies, limiting the spread of disruption, maintaining service continuity — push firms toward the same architectural outcomes as Zero Trust.

Why Legacy Perimeter Architecture Fails the Regulatory Test

The fundamental problem with perimeter-based security in a regulated environment is that it assumes trust based on network location. Once an attacker — or a compromised insider — is inside the perimeter, they typically have broad access to systems and data.

This creates several specific problems for regulated firms. Blast radius is uncontrolled — a single compromised credential can provide access to systems far beyond what the attacker needs. Lateral movement is hard to detect. Third-party access is difficult to control. And audit evidence is incomplete.

What Zero Trust Actually Requires

Zero Trust is not a product. It's an architectural principle — and implementing it properly requires a structured programme, not a vendor deployment.

The NIST SP 800-207 framework defines Zero Trust around three core principles: verify explicitly, use least-privilege access, and assume breach. The CISA Zero Trust Maturity Model provides a practical implementation roadmap across five pillars: Identity, Devices, Networks, Applications and Workloads, and Data.

A credible Zero Trust programme for a regulated organisation typically involves a maturity assessment across all five CISA pillars, identity and access governance, network microsegmentation, continuous monitoring, and regulatory mapping to DORA, NIS2, and FCA requirements.

The Vendor Landscape: Why Independence Matters

The Zero Trust vendor market is crowded, and every major security vendor now claims to offer a Zero Trust solution. No single vendor delivers a complete Zero Trust architecture. A mature programme typically involves multiple vendors across identity, network security, microsegmentation, and endpoint.

Independent architecture guidance, developed before vendor selection, is essential to avoid the outcome where a single vendor's product becomes the architecture by default — and their gaps become your gaps.

Speak with a Cybinity security architect about your Zero Trust programme

Zero TrustDORANIS2FCARegulated Industries