DORA Year Two: Can Your SOC Actually See the Attack?
Summary
As DORA becomes enforceable in the EU in January 2025, financial entities are entering the second year of its implementation. The first year focused on establishing risk governance, assessing third-party providers, and updating contracts, while the current year shifts to more challenging aspects of the regulation.
IFF Assessment
The article discusses a regulation aimed at improving the cybersecurity and operational resilience of financial entities, which is beneficial for defenders.
Defender Context
This article highlights the ongoing implementation of the Digital Operational Resilience Act (DORA) in the EU, which mandates significant security and resilience improvements for financial entities. Defenders should be aware of these evolving regulatory landscapes and the increased scrutiny on operational resilience and third-party risk management within the financial sector.