DORA Year Two: Can Your SOC Actually See the Attack?
The European Union’s Digital Operational Resilience Act (DORA) is pushing financial institutions to significantly improve their ICT risk supervision and incident response capabilities. As DORA enters its second year, the challenge lies in demonstrating that existing security controls and monitoring systems can effectively detect and respond to attacks, particularly across complex IT environments and with the increasing sophistication of AI-powered threats. Network Detection and Response (NDR) is emerging as a critical tool for achieving this by providing a comprehensive view of network communication and behavior, enabling SOC teams to identify anomalies and respond to incidents within the required regulatory timeframe. The article highlights how NDR helps financial institutions validate findings, reconstruct activity, and reach more reliable conclusions, addressing the gaps in traditional security monitoring.
The European Union’s Digital Operational Resilience Act (DORA) is pushing financial institutions to significantly improve their ICT risk supervision and incident response capabilities. As DORA enters its second year, the challenge lies in demonstrating that existing security controls and monitoring systems can effectively detect and respond to attacks, particularly across complex IT environments and with the increasing sophistication of AI-powered threats. Network Detection and Response (NDR) is emerging as a critical tool for achieving this by providing a comprehensive view of network communication and behavior, enabling SOC teams to identify anomalies and respond to incidents within the required regulatory timeframe. The article highlights how NDR helps financial institutions validate findings, reconstruct activity, and reach more reliable conclusions, addressing the gaps in traditional security monitoring.
Financial institutions are grappling with the complexities of DORA, which requires continuous monitoring and management of their ICT ecosystems, alongside swift detection of anomalous activities and rapid incident response. Traditional security measures, such as asset inventories and configuration records, provide a limited view of system interactions, particularly across legacy infrastructure and with unmanaged devices. The article emphasizes that simply knowing *what* systems exist isn't enough; it's crucial to understand *how* they communicate and whether that communication aligns with expected behavior.
Network Detection and Response (NDR) is presented as a solution to bridge these gaps. NDR tools analyze network traffic to establish baselines of normal behavior and identify deviations that could indicate an attack. This is particularly important in light of AI-speed attacks, where adversaries can quickly adapt and evade traditional security measures.
The article details how NDR can uncover critical insights, such as:
- Which internal systems are being communicated with by a third-party vendor’s software packages.
- Whether the traffic matches the approved scope of a vendor’s contract.
- Changes in connection timing, protocol use, or data volume.
Furthermore, DORA’s reporting requirements necessitate swift notification of major ICT-related incidents, with a maximum of four hours for classification and 24 hours for initial reporting. NDR’s ability to rapidly provide network evidence is therefore essential for meeting these deadlines and demonstrating compliance.
The focus on third-party risk management (Articles 28-30) underscores the need to extend monitoring beyond internal systems to encompass vendor interactions. NDR can reveal whether a compromised vendor’s credentials are being misused, even if the vendor’s own logs don’t immediately indicate a problem.
Corelight, a vendor specializing in NDR, highlights the benefits of their solution: providing open, transparent, and explainable data, reducing triage time, and enabling agentic AI throughout the SOC. Their structured network evidence preserves protocol-level context to produce a more complete dataset for investigation and AI.
Ultimately, the article suggests that the core question for financial institutions is not simply whether they *have* the controls in place, but whether their SOC has the *evidence* to respond to and contain an attack effectively.
