DORA · Article 12 · ICT Backup

You signed the DORA Article 12 attestation. Your backups probably don't meet it.

Article 12 requires backup data physically and logically segregated from production. Physical is the word that determines whether your attestation holds. A separate VLAN does not qualify. A different cloud tenant does not qualify. Tape on a shelf reachable by the same domain admin does not qualify.

If your backups are reachable from your production network, by anyone, with any credential, they are not physically segregated. That is the test most EU banks are failing.

Article 12 assessment. No sales pitch.

What DORA Article 12 actually requires

"When restoring backup data using its own systems, the financial entity shall use ICT systems that are physically and logically segregated from the source ICT system."
Source: Regulation (EU) 2022/2554 (DORA), Article 12(5)

The regulation is explicit. Your restoration environment has to be physically separated from the systems it is meant to recover, not merely partitioned in software inside the same infrastructure. A physically isolated recovery vault with no software attack surface meets that standard by design, because the recovery copy cannot be reached, altered, or destroyed from the production network.

What actually happens, in order

Every public ransomware case study from a regulated financial entity in the last 18 months follows the same sequence.

Day zero.

Initial access. Phishing, exposed RDP, a vendor compromise. The vector does not matter.

Day three to seven.

Lateral movement. Privilege escalation. Domain admin.

Day seven to fourteen.

The backup infrastructure is reached. The credentials your backup software uses to write to its repositories are stored in, or recoverable from, the same directory service that has now been compromised. Backups are encrypted, deleted, or both.

Day fourteen.

Production is encrypted. Active Directory is destroyed.

Day fifteen onward.

Recovery begins. The "segregated" backup is gone. The recovery accounts your runbook depends on no longer exist, because AD has been wiped. Restoration enters a phase nobody planned for.

What HyperBUNKER actually holds for a bank

The 8TB inside HyperBUNKER is not a bulk archive. It holds the specific artifacts that determine whether the bank can process a transaction on day one of recovery.

How the vault actually works

Hardware. PLCs and optocouplers gating the data path. No operating system on the disconnect. No remote management interface. No IP address reachable from the production network.

Writes happen during a defined window, gated physically. Outside that window the vault is electrically disconnected. An attacker holding domain admin, backup credentials, and hypervisor access cannot reach what is inside.

The attack surface is not hardened. It is not there.

What we see when banks ask us to look

Before HyperBUNKER, we built recovery infrastructure for industrial environments where downtime has physical consequences. The pattern that brought us into banking is the same one we saw on the OT side. The architecture in most regulated banks today was designed against an availability threat, not against an intelligent adversary holding domain admin. The backup infrastructure is reachable from a network the production domain admin controls. The backup credentials are stored in, or recoverable from, the same identity provider the attacker has already compromised. The recovery procedure has been tested for hardware failure, but not for the scenario in which the directory service itself is destroyed.

Two recent failures, both inside DORA's scope

BridgePay, February 2026. Offline for 22 days following a ransomware incident. By any standard checklist their backup posture looked compliant. The recovery did not.

Marquis Software Solutions, August 2025. A provider of core banking software was breached. 74 financial institutions experienced disruption that cascaded through their customer base. The recovery layer was inside the same blast radius as production.

Questions auditors and CISOs ask first

Does HyperBUNKER replace our existing backup software?

No. The vault sits behind the working backup tier. Existing software handles fast restores and granular recovery. HyperBUNKER holds the artifacts that survive when the backup tier itself is the target.

Is HyperBUNKER physically isolated?

"Air-gapped" has become a software-defined claim. HyperBUNKER is physically disconnected. The control mechanism is hardware, not policy.

Where does the Article 12 audit pack come from?

The vault generates it. Tamper-evident, timestamped, ready for examination by the competent authority. Part of the deployment, not a separate consulting engagement.