The Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025. The initial year saw financial entities establishing risk governance, assessing third-party providers, updating contracts, and documenting incident escalation workflows.
Now in its second year, DORA's focus has shifted to demonstrating the practical effectiveness of these frameworks. EU regulators are increasing scrutiny on DORA implementation, Information and Communication Technology (ICT) incident analysis, and the efficacy of ICT risk supervision.
A key challenge for security teams under DORA is ensuring their Security Operations Centers (SOCs) possess adequate visibility. This visibility is crucial for detecting, investigating, and scoping active intrusions across critical systems.
While DORA does not mandate specific security technologies, its requirements for continuous monitoring necessitate the ability to identify behaviors indicating emerging risks within the ICT environment.
Continuous monitoring under DORA extends beyond merely maintaining an asset inventory or configuration records. It requires sufficient visibility to recognize when operational patterns diverge from the norm, as mandated by Article 9 of DORA.
Article 9 specifically requires financial entities to continuously monitor and manage the security and functioning of their ICT ecosystem, implementing processes to minimize ICT risk.
Traditional security sources like asset inventories, configuration records, security logs, and endpoint telemetry often lack a comprehensive view of communication between systems. This is particularly true for legacy infrastructure, specialized appliances, unmanaged devices, or systems with limited endpoint telemetry.
These unmonitored connections represent blind spots that adversaries may target. Comprehensive visibility into these gaps is necessary to identify evidence of exploitation and disrupt attack chains, especially against adaptive, AI-speed threats. Network Detection and Response (NDR) is identified as a tool that can help consolidate this level of detail to meet DORA's demands.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Digital Operational Resilience Act (DORA) is now in its second year of enforcement within the EU, shifting regulatory focus from initial setup to demonstrating effective implementation of ICT incident analysis and risk supervision. Financial entities must ensure their Security Operations Centers (SOCs) have sufficient visibility to detect and investigate intrusions across critical systems, particularly in areas like legacy infrastructure and unmanaged devices. This matters because DORA mandates continuous monitoring beyond basic asset inventories to recognize deviations from normal operational patterns and minimize ICT risk.