← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

DORA's Second Year Focuses on Practical ICT Incident Response and Risk Supervision

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DORA's second year emphasizes practical implementation and effectiveness of ICT risk supervision.
  • Financial entities need comprehensive SOC visibility for intrusion detection and investigation.
  • Continuous monitoring under DORA requires recognizing deviations from normal operational patterns.
  • Network Detection and Response (NDR) can help address DORA's visibility requirements.

DORA's Evolving Focus

The Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025. The initial year saw financial entities establishing risk governance, assessing third-party providers, updating contracts, and documenting incident escalation workflows.

Now in its second year, DORA's focus has shifted to demonstrating the practical effectiveness of these frameworks. EU regulators are increasing scrutiny on DORA implementation, Information and Communication Technology (ICT) incident analysis, and the efficacy of ICT risk supervision.

Visibility Challenges for Security Operations Centers

A key challenge for security teams under DORA is ensuring their Security Operations Centers (SOCs) possess adequate visibility. This visibility is crucial for detecting, investigating, and scoping active intrusions across critical systems.

While DORA does not mandate specific security technologies, its requirements for continuous monitoring necessitate the ability to identify behaviors indicating emerging risks within the ICT environment.

Beyond Basic Monitoring

Continuous monitoring under DORA extends beyond merely maintaining an asset inventory or configuration records. It requires sufficient visibility to recognize when operational patterns diverge from the norm, as mandated by Article 9 of DORA.

Article 9 specifically requires financial entities to continuously monitor and manage the security and functioning of their ICT ecosystem, implementing processes to minimize ICT risk.

Addressing Blind Spots

Traditional security sources like asset inventories, configuration records, security logs, and endpoint telemetry often lack a comprehensive view of communication between systems. This is particularly true for legacy infrastructure, specialized appliances, unmanaged devices, or systems with limited endpoint telemetry.

These unmonitored connections represent blind spots that adversaries may target. Comprehensive visibility into these gaps is necessary to identify evidence of exploitation and disrupt attack chains, especially against adaptive, AI-speed threats. Network Detection and Response (NDR) is identified as a tool that can help consolidate this level of detail to meet DORA's demands.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Digital Operational Resilience Act (DORA) is now in its second year of enforcement within the EU, shifting regulatory focus from initial setup to demonstrating effective implementation of ICT incident analysis and risk supervision. Financial entities must ensure their Security Operations Centers (SOCs) have sufficient visibility to detect and investigate intrusions across critical systems, particularly in areas like legacy infrastructure and unmanaged devices. This matters because DORA mandates continuous monitoring beyond basic asset inventories to recognize deviations from normal operational patterns and minimize ICT risk.