Ethical Hacking News
The Digital Operational Resilience Act (DORA) has been a game-changer for financial entities across the European Union, but now, the real challenge has begun - demonstrating how well frameworks work in practice. The question remains: does the SOC have enough visibility to detect, investigate, and scope an active intrusion across critical systems? With the increased focus on DORA implementation, ICT incident analysis, and ICT risk supervision, it's crucial to understand the role of network visibility in meeting the demands of DORA. Can your SOC actually see the attack?
EU regulators are increasing focus on DORA implementation, ICT incident analysis, and ICT risk supervision, raising questions about Security Operations Center (SOC) visibility and detection capabilities.Continuous monitoring is crucial to identify emerging risks, but traditional sources such as asset inventory and security logs often lack comprehensive visibility into system communication.Network Detection and Response (NDR) can provide visibility into system communication, establish baselines of normal behavior, and detect anomalies, helping organizations meet DORA requirements.NDR can extract structured data, making it usable at scale, and provide context for incident investigation and response.Third-party risk management and contractual agreements are also impacted by DORA, requiring financial organizations to assess and monitor vendor activity within their IT environment.Financial institutions must ensure their SOC has sufficient evidence to detect, investigate, and respond to ICT-related incidents, making network visibility a critical requirement.
The Digital Operational Resilience Act (DORA) has been a game-changer for financial entities across the European Union, as it has triggered an administrative sprint to establish risk governance, assess third-party service providers, and update contract clauses. Now, in its second year, the real challenge has begun - demonstrating how well frameworks work in practice. EU regulators are increasing their focus on DORA implementation, Information and Communication Technology (ICT) incident analysis, and the effectiveness of ICT risk supervision.
For security teams, this raises a crucial question: does the Security Operations Center (SOC) have enough visibility to detect, investigate, and scope an active intrusion across critical systems? While DORA does not prescribe a particular security stack, several of its requirements rely on continuous visibility in the ICT environment to identify behavior that may indicate an emerging risk.
Continuous monitoring is not just about knowing what should be happening in a network; it's about having enough visibility to recognize when operational patterns begin to diverge from the norm. According to Article 9 of DORA, financial entities are required to continuously monitor and manage the security and functioning of their ICT ecosystem, and implement processes to minimize the impact of ICT risk.
However, none of the sources such as asset inventory, configuration records, security logs, and endpoint telemetry provides a comprehensive view of communication between systems, particularly across legacy infrastructure, specialized appliances, unmanaged devices, or systems where endpoint telemetry is limited. Unmonitored connections between systems may hold evidence of exploitation, and companies that have visibility into what's happening in those gaps have a greater likelihood of disrupting the attack chain.
Network Detection and Response (NDR) is a catalyst for bringing that level of detail together, and thus allowing organizations to work towards meeting the demands of DORA. With continuous monitoring across the environment, NDR helps establish baselines of normal behavior and evaluates timing, volume, and directionality to identify when communications deviate from expected patterns.
For instance, if a payment routing application that normally communicates with an external credit assessment service suddenly communicates substantially more with unfamiliar internal hosts during non-work hours, network telemetry can expose the anomaly even when the application's own logs don't. Detecting anomalies requires context, and network data can connect the two by showing which systems communicated, the protocols used, and what happened next.
NDR makes network evidence usable at scale by extracting structured, protocol-level data that helps analysts investigate alerts in context and in a correlated view rather than reconstructing incidents from siloed sources. Context allows responders to establish an incident's scope and impact, especially in light of today's AI-speed attacks, both of which inform Article 19 reporting requirements.
The increased focus on DORA implementation, ICT incident analysis, and ICT risk supervision also raises questions about third-party risk management and contractual agreements. According to Articles 28 through 30 of DORA, contracts and vendor assessments define a provider's authorized access and operational boundaries on paper. However, network data shows how that provider's software packages, tunnels, and API integrations actually function inside the IT environment, which details whether connections adhere to approved data paths or actively deviate from expectations.
If, for instance, a trusted vendor's credentials are compromised, the credentials' access remains legitimate but behavior likely changes. Network evidence from NDR allows the financial organization to observe that activity from its own environment and ask questions that vendor documentation can't answer: which internal systems is the connection communicating with? Does the traffic match the documented scope? Has connection timing, protocol use, or data volume changed?
As financial institutions move into year two of DORA, it's clear that network visibility is directly relevant to the requirements in Articles 9 and 10: continuous monitoring, detection, and rapid response. NDR can provide that visibility by showing how systems communicate, where anomalous activity occurs, and how incidents move through an environment. Where DORA requires financial entities to detect, investigate, and respond to ICT-related incidents, the more useful question may be simple: does your SOC have the evidence to respond to and contain an attack?
Related Information:
https://www.ethicalhackingnews.com/articles/Unlocking-the-Secrets-of-Network-Visibility-Can-Your-SOC-Actually-See-the-Attack-ehn.shtml
https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html
https://vulners.com/thn/THN:38F73ADB54076A8C59310B5E2D29697F
Published: Tue Sep 22 07:14:07 2026 by llama3.2 3B Q4_K_M