{"id":112263,"date":"2026-09-21T12:00:00","date_gmt":"2026-09-21T12:00:00","guid":{"rendered":"https:\/\/www.red-gate.com\/simple-talk\/?p=112263"},"modified":"2026-09-08T15:54:48","modified_gmt":"2026-09-08T15:54:48","slug":"how-test-data-management-helps-meet-doras-resilience-testing-requirements","status":"publish","type":"post","link":"https:\/\/www.red-gate.com\/simple-talk\/data-security-privacy-compliance\/how-test-data-management-helps-meet-doras-resilience-testing-requirements\/","title":{"rendered":"How test data management helps meet DORA&#8217;s resilience testing requirements"},"content":{"rendered":"\n<p><strong>DORA requires financial institutions to run tests that prove their systems can withstand operational disruption <em>without<\/em> exposing sensitive data. This article explains how test data management practices can provide the realistic but safe data needed for resilience testing and the governance controls required under DORA\u2019s ICT risk management rules.&nbsp;<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-dora\">What is DORA?<\/h2>\n\n\n\n<p><strong>For <a href=\"https:\/\/www.red-gate.com\/blog\/inside-perspectives-the-growing-importance-of-security-and-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">compliance,<\/a> financial organizations must perform regular resilience testing &#8211; and sometimes even advanced <a href=\"https:\/\/www.secalliance.com\/blog\/threat-led-penetration-testing-tlpt-vs-traditional-pentests\" target=\"_blank\" rel=\"noreferrer noopener\">threat-led penetration testing (TLPT)<\/a> &#8211; of any systems supporting critical or important functions.<\/strong><\/p>\n\n\n\n<p>At the same time, as part of its <a href=\"https:\/\/en.wikipedia.org\/wiki\/Information_and_communications_technology\" target=\"_blank\" rel=\"noreferrer noopener\">Information and Communication Technology (ICT)<\/a> risk management and governance framework, DORA demands high standards for the availability, integrity, and confidentiality of data in <em>every<\/em> environment &#8211; not just production.&nbsp;<\/p>\n\n\n\n<p><strong>But what exactly is DORA?<\/strong><\/p>\n\n\n\n<p><em>\u201cThe purpose of [DORA] is to strengthen the digital operational resilience of the financial sector.\u201d<\/em> \u2014 <strong>Recital 1, DORA<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>The <a href=\"https:\/\/www.digital-operational-resilience-act.com\" target=\"_blank\" rel=\"noreferrer noopener\">Digital Operational Resilience Act<\/a> (DORA) has been in force across the EU since January 2025 and applies to any organization that works with, or provides services to, an EU-based <a href=\"https:\/\/handbook.fca.org.uk\/glossary\/G3540f\" target=\"_blank\" rel=\"noreferrer noopener\">Financial Entity (FE)<\/a>.&nbsp;<\/strong><\/p>\n\n\n\n<p>DORA is designed to strengthen the ability of financial institutions (such as banks, insurers and investment firms) to withstand operational disruption &#8211; whether caused by technology failures, data corruption, human error, or a <a href=\"https:\/\/www.red-gate.com\/simple-talk\/data-security-privacy-compliance\/cybersecurity-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyber attack<\/a>. <\/p>\n\n\n\n<p>It also requires firms to show that, when incidents occur, they can contain the impact and return to normal operations quickly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-is-test-data-management-relevant-to-dora-nbsp\">Why is test data management relevant to DORA?&nbsp;<\/h2>\n\n\n\n<p>Good <a href=\"https:\/\/www.red-gate.com\/simple-talk\/devops\/testing\/managing-test-data-for-database-development\/#so-whats-involved-in-test-data-management\" target=\"_blank\" rel=\"noreferrer noopener\">test data management (TDM)<\/a> practices will help organizations satisfy <em>both<\/em> sides of DORA\u2019s mandate. Resilience tests can\u2019t run on empty databases, but they also can\u2019t use live customer data. To comply with both DORA and <a href=\"https:\/\/gdpr-info.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">GDPR<\/a>, testing must use data that behaves like production data <em>without<\/em> exposing <a href=\"https:\/\/www.ibm.com\/think\/topics\/pii\" target=\"_blank\" rel=\"noreferrer noopener\">personal or sensitive information<\/a>.&nbsp;<\/p>\n\n\n\n<p>With techniques such as static <a href=\"https:\/\/www.red-gate.com\/products\/data-masker\/\" target=\"_blank\" rel=\"noreferrer noopener\">data masking<\/a>, synthetic <a href=\"https:\/\/www.red-gate.com\/products\/sql-data-generator\/\" target=\"_blank\" rel=\"noreferrer noopener\">data generation<\/a>, and <a href=\"https:\/\/www.red-gate.com\/simple-talk\/databases\/theory-and-design\/database-subsetting-and-data-extraction\/#subsetting-the-good-the-bad-and-the-ugly:~:text=Subsetting%3A%20the%20Good%2C%20the%20Bad%20and%20the%20Ugly\" target=\"_blank\" rel=\"noreferrer noopener\">subsetting<\/a>, a TDM system allows teams to run resilience tests with data that is realistic enough for meaningful results, but without expanding the attack surface or breaching DORA\u2019s data governance requirements.&nbsp;<\/p>\n\n\n\n<section id=\"my-first-block-block_300e5e826256d18cb5af28016a57c2da\" class=\"my-first-block alignwide\">\n    <div class=\"bg-brand-600 text-base-white py-5xl px-4xl rounded-sm bg-gradient-to-r from-brand-600 to-brand-500 red\">\n        <div class=\"gap-4xl items-start md:items-center flex flex-col md:flex-row justify-between\">\n            <div class=\"flex-1 col-span-10 lg:col-span-7\">\n                <h3 class=\"mt-0 font-display mb-2 text-display-sm\">Enhance your data security with an automated masking approach<\/h3>\n                <div class=\"child:last-of-type:mb-0\">\n                                            Data Masker automatically masks sensitive data across your estate, enabling you to deliver secure data to downstream environments in non-production databases for development and testing.                                    <\/div>\n            <\/div>\n                                            <a href=\"https:\/\/www.red-gate.com\/products\/data-masker\/\" class=\"btn btn--secondary btn--lg\" aria-label=\"Learn more &amp; try for free: Enhance your data security with an automated masking approach\">Learn more &amp; try for free<\/a>\n                    <\/div>\n    <\/div>\n<\/section>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-dora-require\">What does DORA require?<\/h2>\n\n\n\n<p><strong>DORA, the common name for <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2022\/2554\/\" target=\"_blank\" rel=\"noreferrer noopener\">Regulation (EU) 2022\/2554<\/a>, establishes the overall digital operational<\/strong> <strong>resilience requirements for EU financial entities&nbsp;across more than 60 articles.&nbsp;Larger organizations are subject to more stringent&nbsp;obligations,&nbsp;penalties for non-compliance can reach 2% of annual turnover, and accountability can extend to individuals as well as organizations.&nbsp;<\/strong><\/p>\n\n\n\n<p>DORA also includes&nbsp;strict&nbsp;requirements for&nbsp;ICT risk management and testing, with Articles 5\u20139 and 24\u201327&nbsp;explaining&nbsp;data governance and resilience&nbsp;testing.&nbsp;The&nbsp;subsequent&nbsp;<a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg_del\/2024\/1774\/oj\/eng\" target=\"_blank\" rel=\"noreferrer noopener\">Commission Delegated Regulation (EU) 2024\/1774<\/a>&nbsp;sets out&nbsp;the&nbsp;more detailed technical requirements for how organizations implement DORA&#8217;s ICT risk-management framework.&nbsp;<\/p>\n\n\n\n<p>To determine where TDM fits with DORA, it helps to understand which of the core parts of DORA are the ones that matter most for IT and data teams:&nbsp;<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Governance and ICT Risk Management (Arts. 5\u20139):<\/strong>&nbsp;<br>Establish a framework for governance, accountability, and security controls that protect the confidentiality, integrity, and availability of data across <em>all<\/em> ICT environments, including test systems.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Incident Reporting (Arts. 17\u201323):<\/strong>&nbsp;<br>Detect and report major ICT-related incidents promptly, with the evidence needed for regulatory assessment.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Operational Resilience Testing (Arts. 24\u201327):<\/strong>&nbsp;<br>Regularly test critical business services under realistic conditions. Some financial entities must also perform advanced threat-led penetration testing (TLPT).&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>ICT Third-Party Risk (Arts. 28\u201344):<\/strong>&nbsp;<br>Ensure oversight, contract controls, and monitoring of any external ICT providers supporting critical functions.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Information Sharing (Art. 45):<\/strong>&nbsp;<br>Voluntarily exchange cyber-threat information to improve sector-wide detection and response.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n\n<p><strong>This article focuses specifically on the testing and data governance requirements (Arts. 5\u20139 and 24\u201327). This is where test data management has the clearest and most direct role.&nbsp;<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-does-test-data-management-tdm-help-achieve-dora-compliance\">How does test data management (TDM) help achieve DORA compliance?<\/h2>\n\n\n\n<p><strong>Test data management helps organizations meet DORA&#8217;s requirements for resilience testing (Articles 24-27) by supplying test datasets that mirror production data while containing <em>only<\/em> <a href=\"https:\/\/www.red-gate.com\/simple-talk\/data-security-privacy-compliance\/how-to-build-a-privacy-aware-analytics-layer-with-sql-4-top-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">anonymized<\/a> or synthetic data.<\/strong> <\/p>\n\n\n\n<p><strong>TDM also helps to protect personal and sensitive data, minimizing the overall surface area of risk (Articles 5\u20139).<\/strong><\/p>\n\n\n\n<p>Here&#8217;s a bit more on how it all works, in detail.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tdm-delivers-safe-production-like-data-for-test-systems-nbsp\">TDM delivers <em>safe<\/em> production-like data for test systems&nbsp;<\/h3>\n\n\n\n<p>This is through:<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Static data masking for irreversible replacement of sensitive data that preserves referential integrity and realistic data distributions.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Synthetic data generation, using statistical\/rule-based or AI-based techniques, to create test datasets that mimic the characteristics and distribution of production data, while containing no real records.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tdm-minimizes-the-attack-surface-area-of-test-environments\">TDM minimizes the &#8216;attack surface area&#8217; of test environments<\/h3>\n\n\n\n<p>This is through:<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Subsetting for minimal but representative datasets, excluding anything outside the scope of the test.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Synthetic datasets for especially sensitive data domains, e.g., using generative AI models trained to match production&#8217;s statistical distributions.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Automated <a href=\"https:\/\/www.red-gate.com\/simple-talk\/devops\/database-devops\/sql-server-database-provisioning\/\" target=\"_blank\" rel=\"noreferrer noopener\">provisioning<\/a> and teardown, often using containerized or virtualized <a href=\"https:\/\/www.red-gate.com\/products\/sql-clone\/\" target=\"_blank\" rel=\"noreferrer noopener\">database clones<\/a>, to ensure test environments are created, refreshed and removed in a controlled way. Meanwhile, <a href=\"https:\/\/www.ibm.com\/think\/topics\/rbac\" target=\"_blank\" rel=\"noreferrer noopener\">role-based controls<\/a> restrict access to only those who need it.<\/li>\n<\/ul>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tdm-gives-auditors-traceable-evidence-of-data-governance\">TDM gives auditors traceable evidence of data governance<\/h3>\n\n\n\n<p>This is through:<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Standardized masking policies stored as configuration and tracked in version control.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>An end-to-end audit trail with centralized logs showing <em>who<\/em> accessed <em>which<\/em> environment, evidence of <em>how<\/em> data was classified, masked, and delivered, and that controls were applied consistently across environments&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tdm-supports-the-full-spectrum-of-dora-tests-arts-24-27-nbsp\">TDM supports the full spectrum of DORA tests (Arts. 24\u201327)&nbsp;<\/h3>\n\n\n\n<p>This is through:<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Consistent, known datasets for resilience tests such as performance under surge, end-to-end process integrity tests, and <a href=\"https:\/\/www.red-gate.com\/simple-talk\/podcasts\/rollback-vs-roll-forward-in-databases\/\" target=\"_blank\" rel=\"noreferrer noopener\">rollback<\/a> routines. AI-based generation is useful for specific test cases, such as resilience tests that simulate corrupt or unusual conditions.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li>Rehearsing detection and response procedures safely before live penetration tests (for Financial entities in TLPT scope).<\/li>\n<\/ul>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-tdm-supports-dora-article-24-27-testing-requirements\">How TDM supports DORA article 24-27 testing requirements<\/h2>\n\n\n\n<p><em>\u201cFinancial entities shall, on a regular basis, conduct appropriate tests of their ICT systems, including tests on operational resilience.\u201d \u2014 <\/em><a href=\"https:\/\/www.digital-operational-resilience-act.com\/Article_24.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>DORA, Article 24(1<\/em><\/strong><em>)<\/em><\/a>&nbsp;<\/p>\n\n\n\n<p><strong>A TDM approach will enable financial institutions to build realistic yet safe test systems &#8211; critical in operational resilience testing, one of the most demanding parts of DORA. It allows teams to create controlled test environments that mimic production workloads, dependencies, and failure scenarios.&nbsp;<\/strong><\/p>\n\n\n\n<p>These safe test systems can also be used in preliminary checks of certain operational recovery procedures before live-system testing, which is useful for organizations required to perform <a href=\"https:\/\/eba.europa.eu\/activities\/single-rulebook\/regulatory-activities\/operational-resilience\/joint-regulatory-technical-standards-specifying-elements-related-threat-led-penetration-tests\" target=\"_blank\" rel=\"noreferrer noopener\">threat-led penetration tests<\/a> (TLPT).&nbsp;<\/p>\n\n\n\n<section id=\"my-first-block-block_4553738b932976af2d161a3241238b11\" class=\"my-first-block alignwide\">\n    <div class=\"bg-brand-600 text-base-white py-5xl px-4xl rounded-sm bg-gradient-to-r from-brand-600 to-brand-500 red\">\n        <div class=\"gap-4xl items-start md:items-center flex flex-col md:flex-row justify-between\">\n            <div class=\"flex-1 col-span-10 lg:col-span-7\">\n                <h3 class=\"mt-0 font-display mb-2 text-display-sm\">Automated and controlled preparation of test databases<\/h3>\n                <div class=\"child:last-of-type:mb-0\">\n                                            Redgate Flyway Enterprise can automatically create a target test database at a known, correct schema version, load the designated test dataset, and deploy it securely to a test system.                                    <\/div>\n            <\/div>\n                                            <a href=\"https:\/\/www.red-gate.com\/products\/flyway\/enterprise\/\" class=\"btn btn--secondary btn--lg\" aria-label=\"Learn more &amp; try for free: Automated and controlled preparation of test databases\">Learn more &amp; try for free<\/a>\n                    <\/div>\n    <\/div>\n<\/section>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-good-operational-resilience-testing-look-like-with-test-data-management\">What does good operational resilience testing look like with test data management?<\/h2>\n\n\n\n<p>Databases that hold core financial records, customer data, and transaction histories are among the most critical ICT systems in any financial organization, so testing their resilience safely is a regulatory priority.&nbsp;<\/p>\n\n\n\n<p>With safe and realistic test data in place, teams can perform many of the resilience tests identified in <a href=\"https:\/\/www.digital-operational-resilience-act.com\/Article_25.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Article 25(1)<\/strong><\/a> that are designed to demonstrate that databases, and the critical services they support, can continue to function in the face of software faults, deployment mistakes that affect data, or abnormal transaction loads.&nbsp;<\/p>\n\n\n\n<p>Imagine a deployment to update a risk-calculation process that accidentally deletes or alters critical data, resulting in incorrect results. Can the problem be detected immediately, and can the deployment be rolled back safely without affecting live systems? Effective TDM practices will support this and several other types of critical tests.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-critical-tests-that-effective-test-data-management-can-help-with\">The critical tests that effective test data management can help with<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Type of test<\/strong>&nbsp;<\/td><td><strong>Example<\/strong>&nbsp;<\/td><td><strong>Test data requirements<\/strong>&nbsp;<\/td><\/tr><tr><td><strong>Scenario-based testing<\/strong>&nbsp;<\/td><td>Simulate a failed deployment to validate rollback process.&nbsp;<\/td><td>Realistic datasets including unpredictable values to reflect incident conditions.&nbsp;<\/td><\/tr><tr><td><strong>Performance testing<\/strong>&nbsp;<\/td><td>Validate that a card-processing platform handles transaction surges.&nbsp;<\/td><td>Data volumes and distributions that mirror live production traffic.&nbsp;<\/td><\/tr><tr><td><strong>End-to-end testing<\/strong>&nbsp;<\/td><td>Verify that trade capture, risk calculation, and settlement workflows operate correctly after database <a href=\"https:\/\/en.wikipedia.org\/wiki\/Failover\" target=\"_blank\" rel=\"noreferrer noopener\">failover<\/a>.&nbsp;<\/td><td>Realistic business datasets that capture a workflow and where values remain consistent for sign-off and validation.&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-support-for-other-dora-testing-requirements-nbsp\">Support for other DORA testing requirements&nbsp;<\/h2>\n\n\n\n<p>In some cases, the same safe test environments can also be used for controlled rehearsals of operational processes that interact with data systems. <\/p>\n\n\n\n<p>For example, teams may validate that deployment rollbacks, failover routines, or certain parts of <a href=\"https:\/\/www.red-gate.com\/simple-talk\/databases\/sql-server\/database-administration-sql-server\/developing-a-backup-plan\/\" target=\"_blank\" rel=\"noreferrer noopener\">backup-and-restore<\/a> workflows behave as expected <em>without<\/em> touching live systems or exposing customer data. While TDM doesn\u2019t replace recovery testing, it <em>does<\/em> provide a safe environment for practicing the data-related steps of these procedures.&nbsp;<\/p>\n\n\n\n<p>TDM also supports the advanced testing activities required under <a href=\"https:\/\/www.digital-operational-resilience-act.com\/Article_26.html\" target=\"_blank\" rel=\"noreferrer noopener\">Article 26<\/a>, particularly for larger financial entities:&nbsp;<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Threat-led penetration testing<\/strong> \u2013 teams can rehearse TLPT scenarios in anonymized environments before engaging live systems, helping validate detection rules and response playbooks safely.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Remediation testing<\/strong> \u2013 once vulnerabilities are identified, TDM environments allow repeatable retesting and validation of fixes using realistic, anonymized data.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-does-tdm-help-manage-ict-risk-dora-articles-5-9\">How does TDM help manage ICT risk (DORA articles 5-9)?<\/h2>\n\n\n\n<p><em>\u201cFinancial entities shall ensure the maintenance of high standards of availability, authenticity, integrity, and confidentiality of data.\u201d \u2014 <\/em><a href=\"https:\/\/www.digital-operational-resilience-act.com\/Article_5.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong><em>DORA Article 5(2)<\/em><\/strong><\/a>&nbsp;<\/p>\n\n\n\n<p>Beyond testing resilience, DORA requires strong <a href=\"https:\/\/www.red-gate.com\/hub\/product-learning\/sql-data-catalog\/data-governance-joining-the-dots\/\" target=\"_blank\" rel=\"noreferrer noopener\">governance<\/a> and control over how data is handled across all ICT environments, including non-production.&nbsp;<\/p>\n\n\n\n<div id=\"callout-block_98e8bd08754e92b8db6e75730bae2d1e\" class=\"callout alignnone\">\n    <div class=\"child-last:mb-0 child-first:mt-0 bg-gray-50 dark:bg-gray-950 p-4xl my-3xl\">\n\n<p><strong>You may also be interested in&#8230;<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/www.red-gate.com\/blog\/dora-in-practice-what-two-roundtables-with-technical-leaders-revealed\/\" target=\"_blank\" rel=\"noreferrer noopener\">DORA in Practice: What Two Roundtables with Technical Leaders Revealed<\/a><\/p>\n\n\n\n<p><em>Insights from senior technology, data and security leaders across banking, insurance, payments and trade finance on the operational gaps that DORA compliance planning often misses, and how to close them.<\/em><\/p>\n\n<\/div>\n<\/div> \n\n\n<h3 class=\"wp-block-heading\" id=\"h-data-protection-during-testing-nbsp\">Data protection during testing&nbsp;<\/h3>\n\n\n\n<p>Resilience testing can expose customer data if test environments aren\u2019t properly controlled. A test data breach that leaks personal data but doesn\u2019t disrupt services may not trigger DORA\u2019s incident-reporting rules (Articles 17\u201323), but would still qualify as a personal data breach under GDPR and a failure of ICT governance under DORA Arts. 5 and 9.&nbsp;<\/p>\n\n\n\n<p>GDPR protects personal data; DORA protects operational continuity. They meet in <a href=\"https:\/\/www.digital-operational-resilience-act.com\/Article_9.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Article 9<\/strong><\/a>, which requires firms to maintain the confidentiality, integrity, and availability of data across all ICT environments, including test systems. <\/p>\n\n\n\n<p>In practice, this means resilience testing must <em>not<\/em> create new risks. It must use realistic but safe data, achieved through TDM practices such as masking, subsetting, or synthetic data generation.&nbsp;<\/p>\n\n\n\n<p>Standardized TDM practices are a critical element of a Financial Entity&#8217;s risk management framework. This is because they will:<\/p>\n\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Prevent PII and sensitive data exposure<\/strong> during testing.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Enforce policy-driven masking <\/strong>with audit trails showing consistent application of controls.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n<div class=\"block-core-list\">\n<ul class=\"wp-block-list\">\n<li><strong>Control access to test environments<\/strong>, ensuring only authorized personnel can access or refresh test datasets.&nbsp;<\/li>\n<\/ul>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-auditability-and-traceability-nbsp\">Auditability and traceability&nbsp;<\/h3>\n\n\n\n<p><strong>While DORA doesn\u2019t require financial entities to maintain the same type of detailed records of data processing activities mandated by GDPR, it <em>does<\/em> require comprehensive documentation of ICT risks, incidents, and resilience testing results. <\/strong><\/p>\n\n\n\n<p><strong>These records must demonstrate that systems and their data are governed, protected, and recoverable under defined controls.&nbsp;<\/strong><\/p>\n\n\n\n<p>Articles 5 and 9 place responsibility on financial entities to demonstrate this control. An auditable TDM approach is one that records <em>when<\/em> and <em>how<\/em> sensitive data is masked, moved, or used in testing. It also provides tangible evidence that ICT-risk and data protection controls are working as intended.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-mapping-dora-requirements-to-test-data-management-practices-nbsp\">Mapping DORA requirements to test data management practices&nbsp;<\/h2>\n\n\n\n<p><strong>Here&#8217;s a summary of how DORA requirements map to test data management (TDM) practices:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>DORA expectation<\/strong>&nbsp;<\/td><td><strong>What auditors look for<\/strong>&nbsp;<\/td><td><strong>How TDM helps<\/strong>&nbsp;<\/td><\/tr><tr><td>Data confidentiality, integrity, and availability in all environments (Arts. 5 &amp; 9)&nbsp;<\/td><td>Policies, controls, and evidence that non-prod systems don\u2019t expose personal\/sensitive data&nbsp;<\/td><td>Masking\/synthetic data by policy; preserved referential integrity; audit logs&nbsp;<\/td><\/tr><tr><td>Annual testing of critical\/important functions (Art. 24)&nbsp;<\/td><td>Risk-based testing program; reproducible test conditions&nbsp;<\/td><td><a href=\"https:\/\/www.techtarget.com\/searchdatamanagement\/definition\/deterministic-probabilistic-data\" target=\"_blank\" rel=\"noreferrer noopener\">Deterministic<\/a>, versioned test datasets; test data per test case; pipeline integration&nbsp;<\/td><\/tr><tr><td>Advanced TLPT every three years (where scoped) (Art. 26)&nbsp;<\/td><td>TLPT scope, governance, remediation tests &amp; evidence&nbsp;<\/td><td>Safe pre-production rehearsals using masked\/synthetic data&nbsp;<\/td><\/tr><tr><td>Board accountability &amp; documentation&nbsp;<\/td><td>Clear ownership; traceable artifacts supporting assertions to supervisors&nbsp;<\/td><td>End-to-end logs from source \u2192 masking \u2192 provisioning \u2192 use \u2192 cleanup&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-in-summary-nbsp-how-test-data-management-helps-meet-dora-s-resilience-testing-requirements-nbsp\">In summary:&nbsp;how test data management helps meet DORA&#8217;s resilience testing requirements&nbsp;<\/h2>\n\n\n\n<p><strong>DORA doesn\u2019t dictate <em>how<\/em> financial institutions should test their resilience, but it does make them responsible for proving that their systems and data are resilient to stress, recoverable quickly in the event of failure or attack, and well governed and protected.&nbsp;<\/strong><\/p>\n\n\n\n<p><strong>Test data management (TDM) can provide the realistic but safe data needed to test effectively &#8211; and the governance, masking, and auditability to do so <em>without<\/em> increasing risk. <\/strong><\/p>\n\n\n\n<p>Because sensitive data remains protected, teams can test effectively without increasing risk or expanding the attack surface. For many financial entities, TDM is not just a testing convenience but an essential part of their ICT risk and compliance framework.&nbsp;<\/p>\n\n\n\n<p>As DORA reshapes expectations around digital resilience, implementing TDM practices will help financial institutions not only meet compliance goals but also strengthen the reliability and integrity of their data practices in the long term.<\/p>\n\n\n\n<section id=\"my-first-block-block_70b72d371099c9d8d50910f2beb33ac0\" class=\"my-first-block alignwide\">\n    <div class=\"bg-brand-600 text-base-white py-5xl px-4xl rounded-sm bg-gradient-to-r from-brand-600 to-brand-500 red\">\n        <div class=\"gap-4xl items-start md:items-center flex flex-col md:flex-row justify-between\">\n            <div class=\"flex-1 col-span-10 lg:col-span-7\">\n                <h3 class=\"mt-0 font-display mb-2 text-display-sm\">Move fast. Govern at scale.<\/h3>\n                <div class=\"child:last-of-type:mb-0\">\n                                            Redgate Flyway Enterprise embeds guardrails in the database layer, so every change is policy-checked, deterministic, and traceable.                                    <\/div>\n            <\/div>\n                                            <a href=\"https:\/\/www.red-gate.com\/products\/flyway\/enterprise\/\" class=\"btn btn--secondary btn--lg\" aria-label=\"Try for free: Move fast. Govern at scale.\">Try for free<\/a>\n                    <\/div>\n    <\/div>\n<\/section>\n\n\n<section id=\"faq\" class=\"faq-block my-5xl\">\n    <h2>FAQs: How test data management helps meet DORA&#039;s resilience testing requirements<\/h2>\n\n                        <h3 class=\"mt-4xl\">1. What is DORA, and who does it apply to?<\/h3>\n            <div class=\"faq-answer\">\n                <p>The Digital Operational Resilience Act (DORA) is an EU regulation that has applied since January 2025 to any organization working with or providing services to an EU-based financial entity. It requires firms to withstand, respond to, and recover from ICT disruptions.<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">2. Why is test data management important for DORA compliance?<\/h3>\n            <div class=\"faq-answer\">\n                <p>DORA requires resilience testing that can&#8217;t run on empty databases, but it also prohibits using live customer data in test environments. Test data management provides realistic, production-like data through masking, subsetting, and synthetic generation \u2014 satisfying both testing and data protection requirements at once.<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">3. Which DORA articles relate most to test data management?<\/h3>\n            <div class=\"faq-answer\">\n                <p>TDM most directly supports Articles 5\u20139 (ICT risk management and data governance) and Articles 24\u201327 (operational resilience testing, including threat-led penetration testing).<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">4. Does a test data breach count as a DORA incident?<\/h3>\n            <div class=\"faq-answer\">\n                <p>Not necessarily. A test environment breach exposing personal data may not trigger DORA&#8217;s incident-reporting rules if it doesn&#8217;t disrupt services \u2014 but it would still qualify as a GDPR personal data breach and a failure of DORA&#8217;s data governance obligations under Articles 5 and 9.<\/p>\n            <\/div>\n                    <h3 class=\"mt-4xl\">5. What TDM techniques help meet DORA requirements?<\/h3>\n            <div class=\"faq-answer\">\n                <p>Key techniques include static data masking (irreversible anonymization preserving referential integrity), synthetic data generation (statistically realistic but non-real datasets), subsetting (minimal representative data), and automated provisioning\/teardown with audit trails.<\/p>\n            <\/div>\n            <\/section>\n","protected":false},"excerpt":{"rendered":"<p>Learn how test data management helps financial institutions meet DORA&#8217;s resilience testing and ICT risk requirements without exposing sensitive data.&hellip;<\/p>\n","protected":false},"author":200703,"featured_media":106224,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[159160,143514,143527,143523,53,46],"tags":[4168,4170,4619,5765,159192],"coauthors":[7955],"class_list":["post-112263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-analytics","category-data-privacy-and-protection","category-database-administration-sql-server","category-databases","category-featured","category-data-security-privacy-compliance","tag-database","tag-database-administration","tag-security","tag-security-and-compliance","tag-test-data-management"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/users\/200703"}],"replies":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/comments?post=112263"}],"version-history":[{"count":16,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112263\/revisions"}],"predecessor-version":[{"id":112598,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/112263\/revisions\/112598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media\/106224"}],"wp:attachment":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media?parent=112263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/categories?post=112263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/tags?post=112263"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/coauthors?post=112263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}