DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows.

Now in its second year, the harder part of DORA is demonstrating how well frameworks work in practice. EU regulators are increasing their focus on DORA implementation, Information and Communication Technology (ICT) incident analysis, and the effectiveness of ICT risk supervision. For security teams, that raises an important question: does the SOC have enough visibility to detect, investigate, and scope an active intrusion across critical systems?

While DORA doesn’t prescribe a particular security stack, several of its requirements rely on continuous visibility in the ICT environment to identify behavior that may indicate an emerging risk.

Continuous monitoring requires more than an inventory

For DORA, continuous monitoring therefore isn’t just about knowing what should be happening in a network; it’s about having enough visibility to recognize when operational patterns begin to diverge from the norm.

Article 9, the ninth numbered provision of DORA, requires financial entities to continuously monitor and manage the security and functioning of their ICT ecosystem, and implement processes to minimize the impact of ICT risk.

An asset inventory shows the systems a financial institution owns or operates. Configuration records will show how those systems are intended to interact. Security logs and endpoint telemetry provide detailed visibility into activity on monitored systems.

Yet, none of those sources necessarily provides a comprehensive view of communication between systems, particularly across legacy infrastructure, specialized appliances, unmanaged devices, or systems where endpoint telemetry is limited. When confronting adaptive, AI-speed threats, a comprehensive view is necessary to identify the blind spots adversaries specifically target. Unmonitored connections between systems may hold evidence of exploitation, and companies that have visibility into what’s happening in those gaps have a greater likelihood of disrupting the attack chain.

Network Detection and Response (NDR) is a catalyst for bringing that level of detail together, and thus allowing organizations to work toward meeting the demands of DORA. With continuous monitoring across the environment, NDR helps establish baselines of normal behavior and evaluates timing, volume, and directionality to identify when communications deviate from expected patterns.

For example, if a payment routing application that normally communicates with an external credit assessment service suddenly communicates substantially more with unfamiliar internal hosts during non-work hours, network telemetry can expose the anomaly even when the application's own logs don't.

Detecting anomalies requires context

Article 10, the next rule in DORA, requires financial institutions to swiftly detect anomalous activities, including network performance issues and related incidents. Further, thresholds must be established for when incident response needs to be triggered.

Security alerts are plentiful, but the volume of noise often overwhelms teams and hides the true signals of anomalous behavior. Determining if an alert is part of a larger incident is the real issue. For instance, EDR may identify a suspicious process while an identity system flags a suspicious login. Network data can connect the two by showing which systems communicated, the protocols used, and what happened next. Command-and-control traffic, reconnaissance, lateral movement, and data transfers all leave traces in network traffic, even when other telemetry is incomplete or unavailable.

NDR makes network evidence usable at scale by extracting structured, protocol-level data that helps analysts investigate alerts in context and in a correlated view rather than reconstructing incidents from siloed sources. Context allows responders to establish an incident’s scope and impact, especially in light of today’s AI-speed attacks, both of which inform Article 19 reporting requirements.

Under applicable rules, the initial notification must be submitted as early as possible, but no later than four hours after classification as a major ICT-related incident and no later than 24 hours after the organization becomes aware of the incident. Rapid access to network evidence gives responders the clarity needed to move quickly across complex IT environments, tracing affected systems, isolating rogue connections, and assembling the required incident records within the regulation’s required timeframe.

Third-party risk extends beyond the contract

Third-party ICT risk management and contractual agreements are the focus of Articles 28 through 30.

Contracts and vendor assessments define a provider’s authorized access and operational boundaries on paper. Network data shows how that provider’s software packages, tunnels, and API integrations actually function inside the IT environment, which details whether connections adhere to approved data paths or actively deviate from expectations.

If, for instance, a trusted vendor’s credentials are compromised, the credentials’ access remains legitimate but behavior likely changes. Network evidence from NDR allows the financial organization to observe that activity from its own environment and ask questions that vendor documentation can’t answer: 

  • Which internal systems is the connection communicating with? 
  • Does the traffic match the documented scope? 
  • Has connection timing, protocol use, or data volume changed?

Year two: test whether the controls work

As financial institutions move into year two of DORA, it’s clear that network visibility is directly relevant to the requirements in Articles 9 and 10: continuous monitoring, detection, and rapid response. Network data also helps organizations thoroughly investigate incidents involving ICT third-party providers, as mandated in Articles 28 through 30.

NDR can provide that visibility by showing how systems communicate, where anomalous activity occurs, and how incidents move through an environment. Where DORA requires financial entities to detect, investigate, and respond to ICT-related incidents, the more useful question may be simple: does your SOC have the evidence to respond to and contain an attack?

Corelight Network Defense

Corelight network detection and response (NDR) delivers data that’s open, transparent, and explainable—helping detect evasive threats, reduce triage time, and enable agentic AI throughout the SOC. Corelight’s structured network evidence preserves protocol-level context to produce a more complete dataset for investigation and AI. When analysts and AI can reason from evidence instead of isolated alerts or metadata, they can validate findings, reconstruct activity, and reach more reliable conclusions. Learn more about Corelight.

source: TheHackerNews