Why financial institutions should include drone threats in their operational resilience strategy

Financial services are increasingly digital, but the infrastructure behind those services remains physical. Data centres, offices, network infrastructure and other critical facilities are essential to keeping financial services available. If these physical assets are disrupted, the consequences can quickly become digital: systems become unavailable, services are interrupted and customers can be affected.

This is where the Digital Operational Resilience Act (DORA) comes into play.

DORA is about more than cyberattacks

DORA requires financial entities in the EU to establish a comprehensive ICT risk management framework and protect the information and ICT assets that support their operations.
Importantly, this includes physical components and infrastructure such as premises, data centres and sensitive designated areas. DORA also requires financial entities to maintain the resilience, continuity and availability of ICT systems supporting critical or important functions.

The physical threat landscape is changing

Cyberattacks are an obvious threat to digital infrastructure. But financial institutions also face a broader range of physical and hybrid threats. Drones are one example.
Drones can be used to conduct reconnaissance, monitor sensitive facilities, interfere with operations or potentially support physical attacks. Even when no direct damage occurs, unauthorised drone activity around critical sites can be an early indicator of hostile or suspicious activity.

This is no longer purely a theoretical concern. Sweden’s financial supervisor, Finansinspektionen, explicitly identified drone fly-bys alongside cyberattacks, data breaches and cable disruptions as incidents that can challenge the operational resilience of financial-sector firms.

The blind spot above the building

Most financial institutions have invested heavily in perimeter security, access control, and camera coverage at ground level. Very few have visibility into the airspace above their sites.

That’s a gap. Drones can be flown for reconnaissance ahead of a physical intrusion, to disrupt operations at sensitive sites, or simply to fly where they shouldn’t over critical infrastructure. Most organizations have no way to detect, classify, or respond to that activity. For a data center or operations hub supporting a critical financial function, an unmanaged airspace is an unmanaged risk, and under DORA, unmanaged risk to a critical ICT asset is exactly what regulators are asking institutions to eliminate.

Where SiteSecure fits

SiteSecure, part of SkeyDrone’s suite of airspace solutions, was built for exactly this kind of site: critical infrastructure and sensitive locations that need continuous, reliable awareness of what’s happening above them.

Rather than raw drone detection alerts, SiteSecure applies the DITTA™ model to turn fragmented signals into a clear operational picture:

  • Detection: spot drone activity above the site in real time
  • Identification: determine drone type, operator and authorisation status
  • Tracking: follow position, movement, and behaviour over time
  • Threat Assessment: assess whether the activity represents a credible risk
  • Action: trigger an appropriate, proportionate response

For a financial institution, this means a documented, auditable process for monitoring physical airspace risk to critical sites. This is the kind of structured, evidence-based control that maps naturally onto DORA’s expectations around ICT risk management, protection and prevention, and the ability to demonstrate resilience to a supervisor.

Discover here how SiteSecure can help protect your critical sites.

We're Ready, Let's Talk.​

Your Name
Newsletter