What D.O.R.A means for your security team (2024)

From January 2025, all UK financial organisations that do business in the EU must comply with the new Digital Operational Resilience Act (DORA). In all honesty, it’s a new regulation that forces organisations to do many things that they should have been doing for years. Most financial organisations will breeze through requirements such as red team assessments, business continuity policies and disaster recovery plans because they are already complete. Indeed, many DORA requirements are covered by other regulations, making it a relatively low bar to step over.

That’s not to say that DORA is meaningless. Not at all. It’s a useful addition to the regulatory landscape. First and foremost, it is a simple, common sense backstop regulation that enforces best practice without being overly prescriptive. Like the GDPR, it rarely cites specific tools/products, but instead focuses on outcomes and best practice. This is beneficial in such a fast-moving sector, as cybersecurity regulations can quickly become outdated or useless if they get too bogged down in the minutia. In my opinion, I also think that DORA does a fantastic job of outlining all the ways that a good Security Operations Centre (SOC) should work. It doesn’t tell companies that they need a dedicated SOC or a specific SEIM, SASE or EDR product. It outlines requirements that can be met in several ways, and many organisations will outsource a lot of them to their SOC team. If you read between the lines, DORA is telling organisations to get a SOC, and get their SOC up to scratch.

The SOC plays an important role in meeting the broader aims of the act (operational resiliency), as well as many of the specifics requirements/articles contained therein. There are several articles contained in the final text that read like SOC best practice guidelines, or outline areas that distinguish good SOCs from bad ones.

Article 9, Protection and preventionThere are several lines in article 9 that highlight the importance of the ongoing protection and prevention capabilities offered by a good SOC, which don’t directly compel organisations to build a SOC team. For instance

“continuously monitor and control the security and functioning of ICT systems and tools”

“maintain high standards of availability, authenticity, integrity and confidentiality of data.”

“ensure that data is protected from risks arising from data management, including poor administration, processing-related risks and human error.”

Article 10, DetectionDORA states that Financial entities must be able to“monitor user activity”, “promptly detect anomalous activities”as well as identify“ICT-related incidents”and “potential material single points of failure”.Furthermore, they need must be able to“enable multiple layers of control”and“trigger and initiate ICT-related incident response processes”.

Whether an organisation has its own in-house team or is outsourcing its SOC requirements to a third party, these are exactly the kind of detection activities that organisationswould expect from a good SOC. The best SOCs are not like a help desk responding to alerts. They engage in threat hunting, they proactively search for anomalies, and they stitch together data from all remote endpoints, the network and the cloud.

Article 11, Response and recoveryThe various“arrangements, plans, procedures and mechanisms”outlined in this article include:

ensure continuity of critical functions”

“quickly, appropriately and effectively resolve ICT-related incidents”

“limit damage and prioritise the resumption of activities and recovery actions”

“activate dedicated plans that enable containment measures, processes and technologies”

“set out communication and crisis management actions

“ensure that updated information is transmitted to all relevant internal staff and external stakeholders”

Again, I struggle to understand how an organisation could hope to comply with this section without a dedicated SOC team. The SOC team should be central to any organisation’s response and recovery process, even if it also involves the introduction of additional digital forensics and incident response services. You need a team on the ground who knows the full intricacies of the IT estate before the breach, as well as external IR teams.

Article 7, ICT systems, protocols and toolsThis section speaks to a major challenge facing security teams and traditional first generation SOCs. An organisation’s IT estate and technology requirements can change fast, and so does their security ecosystem.Due to sprawling IT estates and the growing number of alerts generated by organisations’ many security tools, security teams must ingest and analyse huge volumes of information. Under DORA, companies must be “equipped with sufficient capacity to accurately process the data necessary for the performance of activities and the timely provision of services, and to deal with peak orders, message or transaction volumes, as needed, including where new technology is introduced;

This underscores the need to stay on top of IT sprawl and appoint security resources that can scale with demand / potential threats. Unfortunately, some SOCs will purposely limit the amount of data they ingest, potentially missing important alerts, or charge high fees to ingest more data. These are important considerations for the security and finance teams alike.

Getting ready for DORA

As stated in the introduction, DORA is not prescriptive, and it does not tell financial organisations to get a SOC. However, it’s clear from a lot of the key articles and the language therein that building a SOC team or outsourcing a third party SOC would go a long long way to ensuring compliance. If you read between the lines, you could argue that DORA essentially makes having a good SOC mandatory.

As we look ahead to Jan 2025, I think all financial organisations will either be finding a new SOC, or finetuning their current processes.

What D.O.R.A means for your security team (2024)
Top Articles
10 Teas To Drink When You Have a Cold
3 Steps to Fight Your Carpal Tunnel Syndrome
Tattoo Shops Lansing Il
Somboun Asian Market
Thor Majestic 23A Floor Plan
Lexi Vonn
Star Sessions Imx
How To Do A Springboard Attack In Wwe 2K22
Seething Storm 5E
Gameplay Clarkston
27 Places With The Absolute Best Pizza In NYC
What's Wrong with the Chevrolet Tahoe?
Mr Tire Rockland Maine
CA Kapil 🇦🇪 Talreja Dubai on LinkedIn: #businessethics #audit #pwc #evergrande #talrejaandtalreja #businesssetup…
Doby's Funeral Home Obituaries
Tlc Africa Deaths 2021
Top Hat Trailer Wiring Diagram
Ukraine-Russia war: Latest updates
Assets | HIVO Support
6th gen chevy camaro forumCamaro ZL1 Z28 SS LT Camaro forums, news, blog, reviews, wallpapers, pricing – Camaro5.com
Lake Nockamixon Fishing Report
How Much You Should Be Tipping For Beauty Services - American Beauty Institute
Aaa Saugus Ma Appointment
The Blind Showtimes Near Amc Merchants Crossing 16
Finalize Teams Yahoo Fantasy Football
Bible Gateway passage: Revelation 3 - New Living Translation
Air Quality Index Endicott Ny
Sister Souljah Net Worth
kvoa.com | News 4 Tucson
Timeline of the September 11 Attacks
Marilyn Seipt Obituary
Cfv Mychart
Myra's Floral Princeton Wv
Siskiyou Co Craigslist
Rust Belt Revival Auctions
Roto-Rooter Plumbing and Drain Service hiring General Manager in Cincinnati Metropolitan Area | LinkedIn
Selfservice Bright Lending
Helloid Worthington Login
Jennifer Reimold Ex Husband Scott Porter
Flashscore.com Live Football Scores Livescore
Robeson County Mugshots 2022
Low Tide In Twilight Manga Chapter 53
Lonely Wife Dating Club בקורות וחוות דעת משתמשים 2021
Random Animal Hybrid Generator Wheel
Dagelijkse hooikoortsradar: deze pollen zitten nu in de lucht
Human Resources / Payroll Information
Identogo Manahawkin
Edict Of Force Poe
Black Adam Showtimes Near Cinemark Texarkana 14
Unbiased Thrive Cat Food Review In 2024 - Cats.com
One Facing Life Maybe Crossword
Blippi Park Carlsbad
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 5702

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.