Skip to main content
ComplianceData Protection

DORA Drives Network Visibility to Combat Cyber Threats

Technicians work on server racks and network equipment in a dimly lit server room.

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint.

Article 9: continuous monitoring is more than an inventory

Article 9 requires financial entities to continuously monitor and manage the security and functioning of their ICT ecosystem and implement processes to minimize ICT risk. That obligation moves organizations beyond a simple asset register: an inventory and configuration records describe what should exist and how systems are intended to interact, but they do not guarantee visibility into actual communications.

The source calls out concrete blind spots: legacy infrastructure, specialized appliances, unmanaged devices, and systems with limited endpoint telemetry. Those gaps matter because adversaries target precisely those spaces. Continuous monitoring for DORA must therefore identify when operational patterns diverge from the norm — not just list components on a spreadsheet.

Network Detection and Response (NDR) as the visibility layer

The article positions Network Detection and Response (NDR) as a catalyst for the level of detail DORA demands. NDR aggregates network telemetry to establish baselines of normal behavior and to evaluate timing, volume, and directionality of communications. That allows security operations to spot deviations even when local system logs or endpoint telemetry are silent or incomplete.

An illustrative example in the source: a payment routing application that usually talks to an external credit assessment service might suddenly exchange substantially more data with unfamiliar internal hosts during non-work hours — a pattern detectable in network telemetry even if the application’s own logs don’t show anything suspicious.

Article 10 and Article 19: detect quickly, report quickly

Article 10 requires swift detection of anomalous activities, including network performance issues, and the establishment of thresholds for when incident response must be triggered. The reporting rules tied to incident classification are tight: under applicable rules cited in the source, the initial notification must be submitted as early as possible, but no later than four hours after classification as a major ICT-related incident and no later than 24 hours after the organization becomes aware of the incident.

The operational challenge is noise: security alerts are plentiful and often siloed. The piece notes that endpoint detection (EDR) may flag a suspicious process while an identity system logs a risky login — without network context, teams struggle to determine whether those are related. Network traffic preserves traces of command-and-control, reconnaissance, lateral movement, and data transfers, and NDR turns that traffic into structured, protocol-level evidence analysts can use to scope incidents and assemble the records DORA’s timelines require.

Articles 28–30: third-party contracts on paper, behavior on the wire

Articles 28 through 30 focus on third-party ICT risk and contractual controls. The source draws a distinction between contract language — which defines authorized access and operational boundaries — and network evidence, which shows how vendor software, tunnels, and API integrations actually behave in the environment.

A concrete scenario: if a trusted vendor’s credentials are compromised, those credentials may remain technically valid while the observed behavior changes. Network evidence enables financial organizations to answer operational questions that contracts cannot: which internal systems is the vendor actually talking to, does traffic match the documented scope, and have connection timing, protocol use, or data volume changed?

What this means for security teams, regulators, and procurement leaders

  • Security teams: They must ask whether the SOC has the evidence to detect, investigate, and contain an attack across critical systems. According to the source, NDR can reduce triage time by providing structured, protocol-level data that ties alerts together and helps establish incident scope within DORA timelines.
  • Regulators: Enforcement in year two focuses less on documentation and more on demonstrable effectiveness. The article says EU regulators are increasing focus on DORA implementation, ICT incident analysis, and ICT risk supervision — meaning proof that monitoring and detection work in practice will be scrutinized.
  • Procurement leaders: Contracts and vendor assessments remain necessary but insufficient on their own. The piece emphasizes that network data must be used to validate that third-party behavior matches contractual boundaries, especially when credential misuse or unexpected behavior is possible.

Corelight is named in the source as a vendor whose NDR delivers “data that’s open, transparent, and explainable,” with structured network evidence that preserves protocol-level context and, the vendor claims, enables agentic AI throughout the SOC. The central operational test for year two of DORA is not whether organizations have documented controls on paper but whether they can show the regulator that those controls actually detect, investigate, and contain ICT incidents in real time.

Regulators will ask for evidence; attackers will seek the gaps. In DORA’s second year the decisive question is practical: can the SOC see the attack where it actually happens, on the wire, and can it act within the hours the rules require? The answer, according to the analysis in the source, requires continuous network visibility coupled with the ability to turn raw traffic into explainable, protocol-level evidence.

Original story — The Hacker News