Since the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, financial institutions have spent the first year establishing risk governance, vendor oversight, updated contracts, and incident escalation workflows. But entering Year Two, regulators are pushing organizations to prove those frameworks actually work—especially in detecting, investigating, and containing cyber intrusions. At the heart of the challenge is whether Security Operations Centers (SOCs) have sufficient visibility across their ICT environments to meet DORA’s requirements.
Why visibility is central for continuous monitoring
DORA’s Article 9 mandates continuous monitoring and management of the security and functioning of ICT ecosystems. That means more than just knowing what assets exist or how systems are configured—it means having telemetry, logs, and network visibility that can detect when system behavior starts diverging from what’s expected. Visibility gaps—unmanaged devices, legacy systems, specialized appliances with limited logging—create blind spots adversaries will exploit. Detecting unusual communication, lateral movement, or suspicious connections depends on this depth of data.
From anomaly detection to actionable incident response
Under Article 10, financial entities must rapidly detect ICT anomalies, performance issues, and cyber threats, with mechanisms, thresholds, and escalation processes clearly in place. But alert fatigue and signal noise are major obstacles. Endpoint detection may flag a rogue process; identity systems may highlight anomalous login behavior. Neither on its own tells the full story. Network Data & Response (NDR) tools bring broader context, showing how systems communicate, exposing unexpected flows, timing discrepancies, and unusual volumes. Such correlation is essential for determining the scope and impact of an incident, meeting DORA’s tight reporting deadlines—no later than four hours after classification of a major incident, or 24 hours after awareness.
Third-party risks demand real visibility, not just contracts
DORA’s obligations in Articles 28-30 focus on third-party ICT service providers. Vendor contracts and risk assessments define what’s expected on paper, but real-world behavior often deviates. Placing trust in supplier credentials is insufficient if compromised credentials are misused. Monitoring vendor-related traffic—how much, when, with whom—is necessary to confirm that policy, configuration, and actual communications align. Network evidence enables organizations to trace whether a vendor’s access remains within documented scope or if unauthorized paths have opened.
With Year Two under way, the questions SOCs should be asking themselves are sharper: Do we have enough visibility across all systems, including legacy and unmanaged ones? Can we connect alerts across identity, endpoint, and network to reconstruct incidents at speed? Can we gather the evidence needed to act—and report—to regulators under DORA?
Closing visibility gaps—often via tools like NDR—is emerging as a linchpin for compliance, not just a best practice. Without it, even well-crafted policies and contracts leave institutions exposed.
What this means: institutions now must move beyond planning to proving. They need to build SOCs that don’t merely log, but truly see, analyze, and act. What to watch: How soon financial entities can restructure monitoring and detection to reduce blind spots; how NDR evolves to become standard; and whether regulators begin issuing enforcement actions based on lack of visibility as much as lack of policy.