As the Digital Operational Resilience Act (DORA) enters its second year of enforcement across the European Union, financial institutions are confronting a harder challenge than the administrative sprint of year one: proving their security frameworks can actually detect and contain active intrusions across critical systems. The regulation, which became enforceable in January 2025, now sees EU regulators sharpening their focus on how well ICT incident analysis and risk supervision work in practice, according to a new analysis published by The Hacker News. The first year was spent building risk governance, evaluating third-party service providers, revising contract language, and documenting how incidents get escalated—but the real test is whether security operations centers have enough visibility to spot threats moving through their networks.
The report highlights that DORA's requirements depend on continuous visibility into ICT environments to identify behavior signaling emerging risk, yet many financial entities lack comprehensive sight into communication between systems—especially across legacy infrastructure, specialized appliances, unmanaged devices, or systems where endpoint telemetry is limited. Article 9 of DORA mandates that financial entities continuously monitor and manage the security and functioning of their ICT ecosystem while implementing processes to minimize ICT risk impact. Article 10 requires swift detection of anomalous activities, including network performance issues and related incidents, with established thresholds for triggering incident response. Under Article 19, the initial notification of a major ICT-related incident must be submitted no later than four hours after classification and no later than 24 hours after the organization becomes aware of the incident. Articles 28 through 30 address third-party ICT risk management and contractual agreements, demanding that financial institutions understand not just what vendors are authorized to do on paper, but how provider software packages, tunnels, and API integrations actually behave inside the IT environment.
The report argues that asset inventories and configuration records show what systems a financial institution owns and how they're supposed to interact, but these sources don't necessarily provide a full view of communication between systems, particularly in environments with adaptive, AI-speed threats. According to the analysis, "unmonitored connections between systems may hold evidence of exploitation," and organizations with visibility into those gaps have a better chance of disrupting the attack chain. The report points to Network Detection and Response (NDR) as a mechanism for achieving that visibility, explaining that it establishes baselines of normal behavior and evaluates timing, volume, and directionality to spot when communications deviate from expected patterns—such as when a payment routing application that normally talks to an external credit assessment service suddenly communicates much more with unfamiliar internal hosts during non-work hours, even when the application's own logs don't flag anything.
The analysis explains that security alerts are abundant, but the sheer volume of noise frequently buries the real signals of anomalous behavior, and the true challenge is determining whether an alert is part of a larger incident. Network data can connect disparate alerts—say, a suspicious process flagged by endpoint detection and response and a suspicious login flagged by an identity system—by showing which systems communicated, the protocols used, and what happened next. Command-and-control traffic, reconnaissance, lateral movement, and data transfers all leave traces in network traffic, even when other telemetry is incomplete or unavailable, the report notes. For third-party risk, the report emphasizes that if a trusted vendor's credentials are compromised, the credentials' access remains legitimate but behavior likely changes, and network evidence allows the financial organization to observe that activity from its own environment and ask questions vendor documentation can't answer: Which internal systems is the connection communicating with? Does the traffic match the documented scope? Has connection timing, protocol use, or data volume changed?
As financial institutions move into year two of DORA, the report concludes that network visibility is directly relevant to the requirements in Articles 9 and 10 for continuous monitoring, detection, and rapid response, as well as to thorough investigation of incidents involving ICT third-party providers under Articles 28 through 30. The more useful question for security teams may be straightforward: does your SOC have the evidence to respond to and contain an attack? The shift from documentation to demonstration will define whether financial entities can meet regulators' expectations when frameworks are put to the test under real-world conditions. For institutions still operating with blind spots in their monitoring infrastructure, the gap between compliance on paper and operational resilience in practice may widen quickly as supervisory scrutiny intensifies.

