Skip to main content

Banking Network

·3 min read·480 words

The network of a banking institution, covering branches, headquarters, and data centers, must meet the most stringent requirements: PCI-DSS, Basel III / Basel IV, AML/CFT, DORA (EU 2025), and ACPR compliance. This guide details 2026 banking architecture: security, 99.999% availability, segmentation, SWIFT, and fraud prevention.

Requirements

  • Availability: 99.999% (5 min/year) for core banking
  • Latency: <2 ms for trading, <10 ms for ATM/DAB
  • Compliance: PCI-DSS, Basel, DORA (EU Digital Operational Resilience Act)
  • Auditability: logs retained for at least 7 years
  • Disaster recovery: RTO <4h, RPO <15 min
  • Strict segmentation: front office / back office / core banking / Internet DMZ

Banking architecture

  • 3-tier: production data center + synchronous secondary data center + asynchronous DR data center >200 km away
  • Core banking (IBM Z mainframe / Murex / Calypso): isolated and mission-critical
  • Trading: low latency, bypassing FW inspection (tap monitoring)
  • Branches: SD-WAN with a dedicated FW and PCI segmentation
  • Internet DMZ: online and mobile banking (3-tier architecture with WAF)

Multi-layer firewalls

  • Perimeter FW: Palo Alto PA-5400/7000 or FortiGate 4200F
  • Internal segmentation FW: between zones (front / back / core)
  • WAF (Web Application Firewall): F5, Imperva for web banking
  • API Gateway: for PSD2 open banking (DSP2)
  • DDoS mitigation: Radware, Arbor, Cloudflare

Microsegmentation

Each banking application is isolated:

  • Core banking: fully isolated, with access through a jump server secured by MFA
  • Risk management: Moody's, Murex, Calypso
  • Trading: Bloomberg Terminal, Reuters, FIX protocol
  • SWIFT: dedicated network, SWIFT Alliance Access appliance
  • Compliance: Actico, NetReveal (KYC/AML)

Bank branches

  • 2× FortiGate 60F/100F in active-passive HA
  • 1× FortiSwitch-148F + 4× FortiAP
  • PCI segmentation for TPE + DAB
  • FortiGate SD-WAN to HQ + 4G/5G backup
  • IP cameras with local + cloud storage

Trading

  • Latency-critical: 400G dark fiber to exchanges (LSE, Euronext)
  • Low-latency switches: Arista 7130 (35 ns cut-through)
  • No FW inspection of trading traffic (tap for SIEM only)
  • Colocation: servers in the same data center as the exchange (saving milliseconds)
  • Multicast market data: Bloomberg and Reuters feeds

DORA compliance (2025+)

EU Digital Operational Resilience Act effective from 2025:

  • Mandatory digital operational resilience
  • Threat-Led Penetration Testing (TLPT)
  • Continuous monitoring with a 24×7 SIEM/SOC
  • ICT risk management: 5 pillars
  • Incident reporting within 4h

SWIFT + ISO 20022

  • Dedicated SWIFT network: HSM (Hardware Security Modules)
  • Mandatory MT → MX (ISO 20022) migration in 2025-2026
  • CSP (Customer Security Programme) security: 32 SWIFT controls
  • Complete isolation: no Internet access and no corporate AD

SIEM / SOC

  • SIEM: Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar
  • UEBA: abnormal behavior detection
  • 24×7 SOC: in-house for large banks or outsourced
  • Threat intelligence: Anomali, Recorded Future
  • MITRE ATT&CK framework for detection

Regional bank budget

  • Core: ~€2M excl. VAT (data centers + headquarters branches)
  • 50 branches: ~€1.5M excl. VAT
  • SIEM + SOC: ~€800K excl. VAT/year
  • Compliance audits: ~€500K excl. VAT/year
  • Total over 3 years: ~€15M excl. VAT

Order from OPTINOC

Turnkey banking network with expertise in DORA, PCI-DSS, and Basel compliance. Palo Alto/Cisco/Fortinet. SWIFT and SIEM integration. Quote within 1 week.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote