DORA's Second Year Tests Whether SOCs Can Actually See an Attack
The Digital Operational Resilience Act (DORA) became enforceable across the EU in January 2025, prompting financial entities to spend the first year on governance, third-party risk assessments, and incident escalation documentation. In its second year, regulators are now examining how well these frameworks actually work, particularly around ICT incident analysis and continuous monitoring.
A core requirement, Article 9, obliges financial entities to continuously monitor their ICT systems and manage risk to minimise impact. This depends on more than having an asset inventory or configuration records; it requires genuine visibility into how systems communicate with each other, especially across legacy infrastructure, specialised appliances, and unmanaged devices where standard endpoint monitoring often falls short.
These blind spots are exactly where sophisticated attackers look to hide. Unmonitored connections between systems can contain evidence of exploitation that goes unnoticed without broader network visibility. Organisations able to see into these gaps are better placed to detect and disrupt an attack before it spreads.