<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Blog de BlueUP</title>
    <link>https://www.blueup.es/es/blog/</link>
    <description>Artículos sobre cumplimiento DORA, prevención de blanqueo (AML/SEPBLAC), Zero Trust y gobernanza de IA para entidades financieras. Español e inglés.</description>
    <language>es-ES</language>
    <lastBuildDate>Sat, 19 Sep 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://www.blueup.es/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TLPT under DORA: Spain&apos;s first testing cycle</title>
      <link>https://www.blueup.es/en/blog/dora-tlpt-fintech-spain</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/dora-tlpt-fintech-spain</guid>
      <description>TLPT under DORA Article 26: who the authority identifies, the thresholds set by Delegated Regulation (EU) 2025/1190 and the deadlines the cycle imposes.</description>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>TLPT bajo DORA: qué exige el primer ciclo en España</title>
      <link>https://www.blueup.es/es/blog/dora-tlpt-fintech-espana</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/dora-tlpt-fintech-espana</guid>
      <description>Pruebas TLPT del artículo 26 de DORA: a quién identifica la autoridad, qué umbrales fija el Reglamento Delegado (UE) 2025/1190 y qué plazos impone.</description>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>DORA for fintech and insurtech: a practical guide and 90-day checklist</title>
      <link>https://www.blueup.es/en/blog/dora-fintech-insurtech-90-days</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/dora-fintech-insurtech-90-days</guid>
      <description>DORA&apos;s five pillars translated into technical controls, the typical failures of a growing fintech or insurtech, and a 90-day checklist to comply without freezing the business.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>DORA Register of Information: why almost no one passes first time</title>
      <link>https://www.blueup.es/en/blog/dora-register-of-information</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/dora-register-of-information</guid>
      <description>What DORA&apos;s ICT third-party Register of Information (Art. 28) requires, why 93.5% of the ESAs dry run failed a quality check, and how to build one that passes.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>DORA para fintech e insurtech: guía práctica y checklist de 90 días</title>
      <link>https://www.blueup.es/es/blog/dora-fintech-insurtech-90-dias</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/dora-fintech-insurtech-90-dias</guid>
      <description>Los cinco pilares de DORA traducidos a controles técnicos, los fallos típicos de una fintech o insurtech en crecimiento y un checklist de 90 días para cumplir sin paralizar el negocio.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Registro de Información DORA: por qué casi nadie lo pasa a la primera</title>
      <link>https://www.blueup.es/es/blog/registro-informacion-dora</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/registro-informacion-dora</guid>
      <description>Registro de Información DORA (art. 28): qué exige, por qué el 93,5 % del dry run de las ESAs falló alguna comprobación y cómo construir uno presentable.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Anatomy of agentic AI AML triage: what the machine decides</title>
      <link>https://www.blueup.es/en/blog/agentic-ai-aml-triage</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/agentic-ai-aml-triage</guid>
      <description>A case study of an AI agent triaging AML alerts: what it resolves alone, where four eyes stops it, and what the audit trail records for the SEPBLAC filing.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>Agentic AI and regulation: who answers when the agent acts alone</title>
      <link>https://www.blueup.es/en/blog/agentic-ai-regulation</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/agentic-ai-regulation</guid>
      <description>How to govern agentic AI under the AI Act, DORA and Spain&apos;s Law 10/2010: high-risk classification, human oversight and the Digital Omnibus delay.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>IA agéntica y regulación: quién responde cuando el agente actúa solo</title>
      <link>https://www.blueup.es/es/blog/ia-agentica-regulacion</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/ia-agentica-regulacion</guid>
      <description>Cómo gobernar la IA agéntica bajo el AI Act, DORA y la Ley 10/2010: clasificación de alto riesgo, supervisión humana y el aplazamiento del Digital Omnibus.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Anatomía de un triaje AML con agente de IA: qué decide la máquina</title>
      <link>https://www.blueup.es/es/blog/triaje-aml-agente-ia</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/triaje-aml-agente-ia</guid>
      <description>Caso práctico de un agente de IA en triaje de alertas AML: qué resuelve solo, dónde el cuatro ojos lo frena y qué registra el audit trail ante el SEPBLAC.</description>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Anatomy of a DORA incident: from first signal to notification</title>
      <link>https://www.blueup.es/en/blog/dora-incident-case-study</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/dora-incident-case-study</guid>
      <description>A practical scenario of a major incident under DORA: classification, the regulatory notification clock and where the manual process breaks.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>SEPBLAC software: automate AML reporting without losing traceability</title>
      <link>https://www.blueup.es/en/blog/sepblac-software</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/sepblac-software</guid>
      <description>How SEPBLAC software automates the special examination, suspicious-activity reporting and AML filing while preserving audit trail and four-eyes control.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>Anatomía de un incidente DORA: del indicio a la notificación</title>
      <link>https://www.blueup.es/es/blog/incidente-dora-caso-practico</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/incidente-dora-caso-practico</guid>
      <description>Escenario práctico de un incidente grave bajo DORA: clasificación, el reloj de notificación al regulador y dónde el proceso manual falla.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Software SEPBLAC: automatizar el reporting sin perder trazabilidad</title>
      <link>https://www.blueup.es/es/blog/software-sepblac</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/software-sepblac</guid>
      <description>Cómo un software SEPBLAC automatiza el examen especial, la comunicación por indicio y el reporting AML conservando audit trail y principio de cuatro ojos.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Agentic AI and Zero Trust: Why identity must precede connectivity</title>
      <link>https://www.blueup.es/en/blog/agentic-ai-zero-trust</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/agentic-ai-zero-trust</guid>
      <description>Agentic AI multiplies attack velocity. The traditional security model no longer works. Cryptographic identity must be the starting point, not the network.</description>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>IA Agéntica y Zero Trust: Por qué la identidad debe preceder a la conectividad</title>
      <link>https://www.blueup.es/es/blog/ia-agentica-zero-trust</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/ia-agentica-zero-trust</guid>
      <description>La IA agéntica multiplica la velocidad de ataque. El modelo de seguridad tradicional ya no funciona. La identidad criptográfica debe ser el punto de partida, no la red.</description>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>AML Automation with AI: From manual screening to intelligent triage</title>
      <link>https://www.blueup.es/en/blog/aml-automation-ai</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/aml-automation-ai</guid>
      <description>How AI is transforming AML compliance. Sanctions screening, automated special examination, and four-eyes triage with sovereign AI.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>DORA 2026: A practical guide for financial entities</title>
      <link>https://www.blueup.es/en/blog/dora-guide-entities-2026</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/dora-guide-entities-2026</guid>
      <description>What DORA requires, how it affects your financial entity, and what you need to implement. Compliance checklist by department.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>Zero Trust in banking: Why VPNs are no longer enough</title>
      <link>https://www.blueup.es/en/blog/zero-trust-banking</link>
      <guid isPermaLink="true">https://www.blueup.es/en/blog/zero-trust-banking</guid>
      <description>The perimeter security model is exhausted. Zero Trust redefines how financial entities protect their critical applications. Identity, mTLS and Dark Services.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>en</dc:language>
    </item>
    <item>
      <title>Automatización AML con IA: Del screening manual al triaje inteligente</title>
      <link>https://www.blueup.es/es/blog/aml-automatizacion-ia</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/aml-automatizacion-ia</guid>
      <description>Cómo la inteligencia artificial transforma el compliance AML. Screening de sanciones, examen especial automatizado y triaje four-eyes con IA soberana.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>DORA 2026: Guía práctica para entidades financieras</title>
      <link>https://www.blueup.es/es/blog/dora-guia-entidades-2026</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/dora-guia-entidades-2026</guid>
      <description>Qué exige el Reglamento DORA, cómo afecta a tu entidad financiera y qué necesitas implementar. Checklist de cumplimiento por departamento.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
    <item>
      <title>Zero Trust en banca: Por qué las VPN ya no son suficientes</title>
      <link>https://www.blueup.es/es/blog/zero-trust-banca</link>
      <guid isPermaLink="true">https://www.blueup.es/es/blog/zero-trust-banca</guid>
      <description>El modelo de seguridad perimetral está agotado. Zero Trust redefine cómo las entidades financieras protegen sus aplicaciones críticas. Identidad, mTLS y Dark Services.</description>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <dc:language>es</dc:language>
    </item>
  </channel>
</rss>
