DORA Year Two: Can Your SOC Actually See the Attack?
AI-summarised brief · reviewed before publication
After the Digital Operational Resilience Act (DORA) took effect EU-wide in January 2025, financial firms spent a year building risk‑governance structures and vetting third‑party providers. In its second year, regulators are demanding proof that those frameworks actually work, focusing on ICT incident analysis and risk supervision. The key question for security operations centres is whether they have sufficient visibility to detect, investigate and contain an intrusion across critical assets. DORA does not mandate a specific security stack, but Article 9 obliges continuous monitoring of the ICT ecosystem, while Article 10 requires detection of anomalous activity and defined response thresholds. Network Detection and Response (NDR) tools can supply the missing telemetry, correlate alerts, and meet reporting timelines such as the four‑hour major‑incident notice.
💡 Why It Matters
- · Demonstrating real‑time network insight is now a compliance checkpoint, forcing banks to upgrade beyond siloed logs or risk regulatory penalties.