As reported by The Hacker News, the Digital Operational Resilience Act (DORA) is entering its second enforcement year with EU regulators shifting focus from documentation to operational reality. The core question is no longer whether financial entities have governance frameworks on paper — it's whether their Security Operations Centers can actually detect, investigate, and scope an active intrusion across critical systems.

Key Insight: The core question is no longer whether financial entities have governance frameworks on paper — it's whether their Security Operations Centers can actually detect, investigate, and scope an active intrusion across critical systems.

This transition from compliance theater to genuine resilience testing is overdue. Shield53 has observed a recurring pattern in financial sector engagements: organizations that invested heavily in DORA's first-year administrative requirements — vendor inventories, contract clause updates, escalation matrices — built governance scaffolding without necessarily improving their detection posture. The gap between what a policy document says happens during an incident and what a SOC can actually see in real time is often significant.

The Visibility Problem Article 9 Exposes

DORA Article 9's continuous monitoring requirement is deceptively straightforward in language but operationally complex. Most financial institutions have reasonable visibility into endpoint activity through EDR deployments and solid log coverage for tier-one applications. The blind spots emerge in the connective tissue:

The Visibility Problem Article 9 Exposes
Legacy infrastructure where endpoint agents cannot be installed or are unsupported
Specialized financial appliances — payment switches, trading platforms, SWIFT gateways — that often lack comprehensive logging
Unmanaged or IoT devices in branch infrastructure and ATMs
East-west traffic between segmented systems that perimeter monitoring never sees
Third-party and cloud service connections where the entity lacks telemetry rights

These gaps are precisely where adversaries operate. Threat actors conducting intrusions in financial environments routinely enumerate monitoring coverage and pivot through paths that lack detection instrumentation. The article's point about AI-speed threats amplifying this problem is well-taken — automated attack tooling can move through unmonitored network paths faster than human analysts can identify the deviation.

Why Network Detection and Response Matters Now

The article positions NDR as a catalyst for DORA compliance, and Shield53 broadly agrees — with important caveats. NDR fills the visibility gap that endpoint and log-centric monitoring leave open by analyzing actual network communications regardless of whether endpoints are instrumented. This matters for three DORA-relevant reasons:

First, NDR establishes behavioral baselines that make anomalous communication patterns visible. A payment application that suddenly communicates with an unfamiliar internal host is a signal that log analysis alone may miss if that host isn't logging comprehensively.

Second, NDR provides evidence of lateral movement and data staging — activities that occur in network gaps and are critical for incident scoping under DORA's major incident reporting requirements.

Third, NDR coverage extends to systems where agent deployment is operationally impossible, which is common in financial environments with legacy core banking systems.

However, NDR is not a checkbox purchase. Deploying sensors without tuning detection logic to the financial environment's specific communication patterns generates alert fatigue and creates a false sense of coverage. The tool must be operationalized, not just installed.

Shield53 Recommendations

Immediate Actions

  • Conduct a visibility assessment across your ICT environment. Map which critical assets have endpoint telemetry, which have log coverage, and which have neither. Prioritize filling the largest gaps first.
  • Validate your SOC's detection against realistic scenarios. Run tabletop exercises or purple team engagements that specifically test detection of lateral movement through unmonitored network paths. Document the results — regulators will ask.
  • Inventory and test third-party telemetry. For critical ICT service providers, confirm what detection data you're contractually entitled to and whether your SOC actually receives and ingests it.
  • Deploy NDR coverage in phases, starting with critical payment processing and core banking segments. Tune baselines for 30-60 days before relying on alerts for operational decisions.

Strategic Actions

  • Map DORA Article 9 requirements to specific detection capabilities. For each monitoring obligation, document which tool provides the visibility, where gaps remain, and what the remediation plan is. This creates an audit-ready evidence trail.
  • Invest in SOC analyst training for network traffic analysis. NDR data is only valuable if analysts can interpret it under pressure during an active incident.
  • Establish metrics for detection effectiveness — mean time to detect, percentage of critical assets with full telemetry coverage, number of blind-spot paths identified and closed. These metrics demonstrate operational resilience maturity beyond policy documentation.

Regulators in year two are looking for evidence that DORA frameworks work under pressure, not just that they exist. Financial entities that can demonstrate genuine detection capability across their full ICT ecosystem — including the difficult legacy and third-party corners — will be positioned far better than those relying on documentation alone. The organizations still treating DORA as a paperwork exercise should expect uncomfortable supervisory conversations in the coming quarters.