Banking Network
The network of a banking institution, covering branches, headquarters, and data centers, must meet the most stringent requirements: PCI-DSS, Basel III / Basel IV, AML/CFT, DORA (EU 2025), and ACPR compliance. This guide details 2026 banking architecture: security, 99.999% availability, segmentation, SWIFT, and fraud prevention.
Requirements
- Availability: 99.999% (5 min/year) for core banking
- Latency: <2 ms for trading, <10 ms for ATM/DAB
- Compliance: PCI-DSS, Basel, DORA (EU Digital Operational Resilience Act)
- Auditability: logs retained for at least 7 years
- Disaster recovery: RTO <4h, RPO <15 min
- Strict segmentation: front office / back office / core banking / Internet DMZ
Banking architecture
- 3-tier: production data center + synchronous secondary data center + asynchronous DR data center >200 km away
- Core banking (IBM Z mainframe / Murex / Calypso): isolated and mission-critical
- Trading: low latency, bypassing FW inspection (tap monitoring)
- Branches: SD-WAN with a dedicated FW and PCI segmentation
- Internet DMZ: online and mobile banking (3-tier architecture with WAF)
Multi-layer firewalls
- Perimeter FW: Palo Alto PA-5400/7000 or FortiGate 4200F
- Internal segmentation FW: between zones (front / back / core)
- WAF (Web Application Firewall): F5, Imperva for web banking
- API Gateway: for PSD2 open banking (DSP2)
- DDoS mitigation: Radware, Arbor, Cloudflare
Microsegmentation
Each banking application is isolated:
- Core banking: fully isolated, with access through a jump server secured by MFA
- Risk management: Moody's, Murex, Calypso
- Trading: Bloomberg Terminal, Reuters, FIX protocol
- SWIFT: dedicated network, SWIFT Alliance Access appliance
- Compliance: Actico, NetReveal (KYC/AML)
Bank branches
- 2× FortiGate 60F/100F in active-passive HA
- 1× FortiSwitch-148F + 4× FortiAP
- PCI segmentation for TPE + DAB
- FortiGate SD-WAN to HQ + 4G/5G backup
- IP cameras with local + cloud storage
Trading
- Latency-critical: 400G dark fiber to exchanges (LSE, Euronext)
- Low-latency switches: Arista 7130 (35 ns cut-through)
- No FW inspection of trading traffic (tap for SIEM only)
- Colocation: servers in the same data center as the exchange (saving milliseconds)
- Multicast market data: Bloomberg and Reuters feeds
DORA compliance (2025+)
EU Digital Operational Resilience Act effective from 2025:
- Mandatory digital operational resilience
- Threat-Led Penetration Testing (TLPT)
- Continuous monitoring with a 24×7 SIEM/SOC
- ICT risk management: 5 pillars
- Incident reporting within 4h
SWIFT + ISO 20022
- Dedicated SWIFT network: HSM (Hardware Security Modules)
- Mandatory MT → MX (ISO 20022) migration in 2025-2026
- CSP (Customer Security Programme) security: 32 SWIFT controls
- Complete isolation: no Internet access and no corporate AD
SIEM / SOC
- SIEM: Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar
- UEBA: abnormal behavior detection
- 24×7 SOC: in-house for large banks or outsourced
- Threat intelligence: Anomali, Recorded Future
- MITRE ATT&CK framework for detection
Regional bank budget
- Core: ~€2M excl. VAT (data centers + headquarters branches)
- 50 branches: ~€1.5M excl. VAT
- SIEM + SOC: ~€800K excl. VAT/year
- Compliance audits: ~€500K excl. VAT/year
- Total over 3 years: ~€15M excl. VAT
Order from OPTINOC
Turnkey banking network with expertise in DORA, PCI-DSS, and Basel compliance. Palo Alto/Cisco/Fortinet. SWIFT and SIEM integration. Quote within 1 week.
