DORA Year Two: Real Attack Visibility Challenges

Twelve months into mandatory Digital Operational Resilience Act compliance, European financial institutions are learning a hard lesson: the paperwork was the easy part. Year one brought predictable checkbox activities—governance structures, third-party audits, contractual rewrites. Now, as DORA enforcement intensifies through its second year, organizations are confronting what actually matters: whether their security operations centers can genuinely detect, investigate, and respond to sophisticated attacks faster than adversaries can exploit them.

The distinction between DORA compliance and DORA maturity is becoming painfully visible across the sector. Many institutions completed the administrative requirements on schedule, filed their documentation, and considered themselves done. What they’re discovering now is that regulatory approval doesn’t automatically translate to operational readiness. The real test of DORA’s impact isn’t whether your governance framework is documented—it’s whether your SOC would actually catch a determined attacker before they cause material harm.

From Governance Checkbox to Actual Resilience

The first year of DORA focused on structural foundations that could be built through process redesign and documentation reviews. Institutions mapped their ICT third-party dependencies, updated service level agreements with security clauses, and established incident escalation chains. This work was necessary but fundamentally defensive—it proved you had thought about risk, not that you could prevent it.

Year two demands something different: proof that your cybersecurity infrastructure can actually function during crisis. This means moving beyond policy documentation into operational testing and validation. Organizations need to verify that their monitoring tools generate useful signals rather than noise, that analysts can correlate events across complex infrastructures, and that response procedures work when tested under conditions that approximate real attacks. The vulnerability disclosure processes many firms codified last year need to transition from theoretical to practiced, with actual tabletop exercises revealing gaps between what’s written and what’s executable.

The Threat Detection Reality Check

DORA’s operational resilience testing requirements become more stringent in year two, and this is where many SOCs will struggle. Threat detection at scale requires not just tools but tuned tools—and tuning takes time, expertise, and honest assessment of your current capabilities. Many institutions running legacy monitoring infrastructure will discover that their alerts generate thousands of false positives, that their SIEM indexing can’t correlate events across all their systems, or that their analysts lack specialized training to identify attack patterns that deviate from known signatures.

The regulatory expectation is that financial entities can withstand and rapidly recover from ICT disruptions and attacks. Meeting this standard means your threat detection systems need to identify attacks that are custom-tailored to your environment, not just replays of previously known campaigns. This requires mature logging practices, behavioral analytics capabilities, incident response playbooks that have been tested against realistic scenarios, and analysts who understand your business well enough to spot anomalies. Many SOCs are discovering they have the technology but not the maturity.

Building Toward Genuine Operational Resilience

The path forward for most institutions involves honest assessment of the gap between their current threat detection capabilities and the maturity level DORA expects. This isn’t about achieving some mythical 100-percent detection rate—that’s impossible against sophisticated adversaries. It’s about establishing a credible baseline: knowing what your monitoring can and cannot see, understanding your blind spots, and having a documented strategy for progressively reducing them.

Organizations that took year one seriously are now investing in modern security architecture, analyst training, threat intelligence integration, and regular red team exercises that expose detection failures. They’re treating DORA compliance not as a regulatory burden but as a framework for building genuinely resilient operations. Those that saw DORA primarily as a documentation exercise are now facing the uncomfortable discovery that checking boxes doesn’t prevent breaches, and regulators are increasingly scrutinizing whether firms can prove their cybersecurity investments are producing actual security outcomes.

Key takeaway: DORA’s second year separates institutions that built compliance infrastructure from those that built genuine operational resilience. Your governance documentation and third-party contracts matter, but what really counts is whether your SOC would actually catch an attacker before they achieve their objectives. That requires honest assessment of your threat detection maturity, investment in people and tools, and continuous testing through exercises that force you to see your real capabilities and limitations.

How confident are you that your SOC would detect an attacker who has successfully compromised one of your critical third-party service providers? That’s the DORA year two question every financial firm should be able to answer with specifics, not generalities.

Get Tech Savvy Digest in your inbox

IT news, cybersecurity, and crypto — the signal, not the noise. No spam, unsubscribe anytime.