The EU Regulation on Digital Operational Resilience in the Financial Sector (DORA – EU 2022/2554) has changed the rules of the game for banks, insurers, brokerage firms and IT/ICT service providers. The regulation shifts the focus from passive protection to active, continuous operational resilience. Organisations must not only prove that they can prevent attacks. Above all, they must demonstrate that they monitor threats in real time, manage software vulnerabilities and infrastructure effectively, and can respond to incidents immediately and restore business continuity.
Softinet, as an IT/OT technology integrator and provider of specialised cybersecurity services, offers solutions from global manufacturers. Let us examine how Softinet’s comprehensive architecture addresses the key pillars of the DORA Regulation.
1. ICT, identity and infrastructure risk management (Articles 5–15 of the DORA)
The regulator requires financial institutions, first and foremost, to implement consistent risk identification mechanisms, rigorous access controls, encryption and network segmentation.
- Okta. It ensures compliance with Zero Trust principles in the area of identity. It also enables the implementation of adaptive multi-factor authentication (MFA), centralised identity governance and administration (Identity Governance & Administration), and full control over access risks relating to users and systems.
- Fortinet (Security Fabric / FortiGate NGFW). Fortinet’s integrated Security Fabric architecture enables comprehensive network segmentation, inspection of encrypted traffic (SSL/TLS) and proactive perimeter protection using next-generation firewalls.
- Check Point (Quantum Network & SASE / CloudGuard). The Quantum series firewalls and SASE architecture provide multi-layered protection for enterprise networks and cloud environments, preventing advanced zero-day attacks.
- Fortinet (Security Fabric / FortiGate NGFW). Zintegrowana architektura Fortinet Security Fabric pozwala na kompletną segmentację sieci, inspekcję zaszyfrowanego ruchu (SSL/TLS) oraz proaktywną ochronę obwodową przy użyciu zapór nowej generacji.
- Check Point (Quantum Network & SASE / CloudGuard). Zapory z serii Quantum i architektura SASE zapewniają wielowarstwową ochronę sieci enterprise i środowisk chmurowych, zapobiegając zaawansowanym atakom typu Zero-Day.
2. Incident detection, endpoint protection and threat intelligence (Articles 10, 13 and 17 of the DORA)
DORA also imposes an obligation to continuously monitor operations, respond immediately to suspicious behaviour and gather intelligence on threats.
- SentinelOne (Singularity XDR Platform). It utilises autonomous artificial intelligence algorithms directly on endpoints and in the cloud, enabling automatic detection, real-time attack containment and immediate rollback to the system’s pre-infection state.
- CrowdStrike (Falcon Platform). It combines EDR/XDR and NGAV modules with MDR services (OverWatch), enabling behavioural analysis of indicators of attack (IOA) and the isolation of compromised devices.
- Recorded Future. It fulfils the requirement for proactive cyber threat intelligence. It provides automated insights into credential leaks, threats targeting the financial sector and indicators of compromise (IoC), feeding this information into defence systems in real time.
- CrowdStrike (Falcon Platform). Łączy moduły EDR/XDR, NGAV i usługi MDR (OverWatch), pozwalając na behawioralną analizę wskaźników ataku (IOA) i izolację zagrożonych urządzeń.
- Recorded Future. Realizuje wymóg proaktywnego wywiadu o cyfrowych zagrożeniach (Cyber Threat Intelligence). Zapewnia automatyczny wgląd w wycieki poświadczeń, zagrożenia ukierunkowane na sektor finansowy oraz wskaźniki kompromitacji (IoC), zasilając systemy obronne w czasie rzeczywistym.
3. Vulnerability management, software lifecycle management and automated validation (Articles 8, 24–27 of DORA)
The obligation to continuously test operational resilience, verify code and map the attack surface is undoubtedly one of the most rigorous pillars of DORA.
- Pentera (Automated Security Validation). It enables continuous, automated testing of resilience to attacks (including the requirements of Threat-Led Penetration Testing – TLPT) in production environments. It safely emulates real-world hacking techniques (e.g. ransomware, credential theft) without causing downtime, thereby verifying the actual effectiveness of defences.
- Rapid7 (InsightVM / InsightAppSec / Metasploit). It provides continuous vulnerability management across the entire infrastructure, automatic prioritisation of vulnerabilities based on their actual business risk, and comprehensive security testing of IT assets.
- Veracode (Application Security Platform). It enables continuous software analysis (SAST, DAST, SCA) at every stage of the DevSecOps cycle, thereby eliminating vulnerabilities in proprietary code and open-source libraries.
- Rapid7 (InsightVM / InsightAppSec / Metasploit). Zapewnia ciągłe zarządzanie podatnościami w całej infrastrukturze, automatyczną priorytetyzację luk na podstawie ich realnego ryzyka biznesowego oraz kompleksowe testowanie bezpieczeństwa zasobów IT.
- Veracode (Application Security Platform). Umożliwia stałą analizę oprogramowania (SAST, DAST, SCA) na każdym etapie cyklu DevSecOps, dzięki czemu eliminuje luki w kodzie własnym oraz bibliotekach open-source.
4. Data security, business continuity and recovery (Articles 11–12 of the DORA)
The regulator also requires a reduction in recovery time objective (RTO) and the elimination of the risk of data loss following a cyber incident.
- Commvault (Commvault Cloud & Cleanroom Recovery). It guarantees that backups are immune to encryption (Zero Trust architecture, isolated Air-Gapped / Compliance Lock repositories). It enables data to be recovered to secure, isolated cloud environments (‘Cleanroom’), where systems are scanned for hidden malware before being restored to production.
5. Incident response and continuous 24/7 monitoring (Articles 17–23 of the DORA)
Simply possessing the technology is not enough, as the regulation requires operational continuity and well-established operational procedures.
- Security Operations Centre (SOC) from Softinet. The hardware and software portfolio is complemented by an integrated Security Operations Centre (SOC) service provided directly by Softinet. A team of certified engineers (using SIEM, SOAR and EDR/XDR tools) provides round-the-clock monitoring 24/7/365, event analysis, and rapid correlation and incident handling. This, in turn, facilitates compliance with DORA requirements regarding the reporting of serious ICT incidents.
Implementing the requirements of the DORA Regulation does not necessarily mean having to build complex and isolated systems from scratch. By utilizing integrated technologies from trusted vendors within Softinet’s portfolio, combined with the expertise and services of Softinet SOC, financial institutions gain a comprehensive, scalable, and coherent security ecosystem. Having such an architecture in place not only enables the efficient fulfilment of regulatory obligations but above all allows for the development of genuine, auditable digital operational resilience.
_____________________
Are you planning to implement DORA requirements within your organisation? We can help you through this process – from selecting the right technology to round-the-clock support from our SOC team. Get in touch with us.