Close Menu
NCIJ Network NCIJ Network
    What's Hot

    OpenAI’s George Osborne says datacentre nimbys holding back Britain | George Osborne

    September 22, 2026

    Singapore’s Nexstrom wants to bring 2D semiconductors to chip fabs

    September 22, 2026

    AutoScheduler launches warehouse app builder for logistics teams

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI’s George Osborne says datacentre nimbys holding back Britain | George Osborne
    • Singapore’s Nexstrom wants to bring 2D semiconductors to chip fabs
    • AutoScheduler launches warehouse app builder for logistics teams
    • New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
    • Morning Minute: Robinhood CEO Bets Crypto Will Beat Sports at Prediction Markets
    • Will Inuit in Canada Seek Chinese Partnerships Amid Strained Ties With Ottawa?
    • EU deadlocked on changes to Russia sanctions ahead of key Ukraine, Greenland talks – Europe live | World news
    • British man missing after diving into Lake Como to rescue father and son
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    DORA Year Two: Can Your SOC Actually See the Attack?

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows.

    Now in its second year, the harder part of DORA is demonstrating how well frameworks work in practice. EU regulators are increasing their focus on DORA implementation, Information and Communication Technology (ICT) incident analysis, and the effectiveness of ICT risk supervision. For security teams, that raises an important question: does the SOC have enough visibility to detect, investigate, and scope an active intrusion across critical systems?

    While DORA doesn’t prescribe a particular security stack, several of its requirements rely on continuous visibility in the ICT environment to identify behavior that may indicate an emerging risk.

    Continuous monitoring requires more than an inventory

    For DORA, continuous monitoring therefore isn’t just about knowing what should be happening in a network; it’s about having enough visibility to recognize when operational patterns begin to diverge from the norm.

    Article 9, the ninth numbered provision of DORA, requires financial entities to continuously monitor and manage the security and functioning of their ICT ecosystem, and implement processes to minimize the impact of ICT risk.

    An asset inventory shows the systems a financial institution owns or operates. Configuration records will show how those systems are intended to interact. Security logs and endpoint telemetry provide detailed visibility into activity on monitored systems.

    Yet, none of those sources necessarily provides a comprehensive view of communication between systems, particularly across legacy infrastructure, specialized appliances, unmanaged devices, or systems where endpoint telemetry is limited. When confronting adaptive, AI-speed threats, a comprehensive view is necessary to identify the blind spots adversaries specifically target. Unmonitored connections between systems may hold evidence of exploitation, and companies that have visibility into what’s happening in those gaps have a greater likelihood of disrupting the attack chain.

    Network Detection and Response (NDR) is a catalyst for bringing that level of detail together, and thus allowing organizations to work toward meeting the demands of DORA. With continuous monitoring across the environment, NDR helps establish baselines of normal behavior and evaluates timing, volume, and directionality to identify when communications deviate from expected patterns.

    For example, if a payment routing application that normally communicates with an external credit assessment service suddenly communicates substantially more with unfamiliar internal hosts during non-work hours, network telemetry can expose the anomaly even when the application’s own logs don’t.

    Detecting anomalies requires context

    Article 10, the next rule in DORA, requires financial institutions to swiftly detect anomalous activities, including network performance issues and related incidents. Further, thresholds must be established for when incident response needs to be triggered.

    Security alerts are plentiful, but the volume of noise often overwhelms teams and hides the true signals of anomalous behavior. Determining if an alert is part of a larger incident is the real issue. For instance, EDR may identify a suspicious process while an identity system flags a suspicious login. Network data can connect the two by showing which systems communicated, the protocols used, and what happened next. Command-and-control traffic, reconnaissance, lateral movement, and data transfers all leave traces in network traffic, even when other telemetry is incomplete or unavailable.

    NDR makes network evidence usable at scale by extracting structured, protocol-level data that helps analysts investigate alerts in context and in a correlated view rather than reconstructing incidents from siloed sources. Context allows responders to establish an incident’s scope and impact, especially in light of today’s AI-speed attacks, both of which inform Article 19 reporting requirements.

    Under applicable rules, the initial notification must be submitted as early as possible, but no later than four hours after classification as a major ICT-related incident and no later than 24 hours after the organization becomes aware of the incident. Rapid access to network evidence gives responders the clarity needed to move quickly across complex IT environments, tracing affected systems, isolating rogue connections, and assembling the required incident records within the regulation’s required timeframe.

    Third-party risk extends beyond the contract

    Third-party ICT risk management and contractual agreements are the focus of Articles 28 through 30.

    Contracts and vendor assessments define a provider’s authorized access and operational boundaries on paper. Network data shows how that provider’s software packages, tunnels, and API integrations actually function inside the IT environment, which details whether connections adhere to approved data paths or actively deviate from expectations.

    If, for instance, a trusted vendor’s credentials are compromised, the credentials’ access remains legitimate but behavior likely changes. Network evidence from NDR allows the financial organization to observe that activity from its own environment and ask questions that vendor documentation can’t answer:

    • Which internal systems is the connection communicating with?
    • Does the traffic match the documented scope?
    • Has connection timing, protocol use, or data volume changed?

    Year two: test whether the controls work

    As financial institutions move into year two of DORA, it’s clear that network visibility is directly relevant to the requirements in Articles 9 and 10: continuous monitoring, detection, and rapid response. Network data also helps organizations thoroughly investigate incidents involving ICT third-party providers, as mandated in Articles 28 through 30.

    NDR can provide that visibility by showing how systems communicate, where anomalous activity occurs, and how incidents move through an environment. Where DORA requires financial entities to detect, investigate, and respond to ICT-related incidents, the more useful question may be simple: does your SOC have the evidence to respond to and contain an attack?

    Corelight Network Defense

    Corelight network detection and response (NDR) delivers data that’s open, transparent, and explainable—helping detect evasive threats, reduce triage time, and enable agentic AI throughout the SOC. Corelight’s structured network evidence preserves protocol-level context to produce a more complete dataset for investigation and AI. When analysts and AI can reason from evidence instead of isolated alerts or metadata, they can validate findings, reconstruct activity, and reach more reliable conclusions. Learn more about Corelight.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    attack DORA SOC year
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

    Stopping Ozempic may raise heart attack and stroke risk

    The cyber AI parity window now has a deadline

    Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    OpenAI’s George Osborne says datacentre nimbys holding back Britain | George Osborne

    September 22, 2026

    Singapore’s Nexstrom wants to bring 2D semiconductors to chip fabs

    September 22, 2026

    AutoScheduler launches warehouse app builder for logistics teams

    September 22, 2026

    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    September 22, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    OpenAI’s George Osborne says datacentre nimbys holding back Britain | George Osborne

    September 22, 2026

    Singapore’s Nexstrom wants to bring 2D semiconductors to chip fabs

    September 22, 2026

    AutoScheduler launches warehouse app builder for logistics teams

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.