DORA Is Live: What Financial Services Teams Need From Their Logging And Monitoring
The Digital Operational Resilience Act is no longer on the horizon. It has applied since January 2025, regulators have moved from guidance to enforcement, and the question for many teams is whether their logging and monitoring could actually meet its demands under pressure.
DORA In Brief
DORA, formally Regulation (EU) 2022/2554, is the European Union’s dedicated framework for managing information and communication technology risk in the financial sector. Unlike a directive, a regulation applies directly across all member states without national transposition, so the core obligations are the same in every jurisdiction from the day it took effect. It reaches around twenty two thousand financial entities together with the ICT providers that serve them.
The framework rests on five pillars, covering ICT risk management, incident management and reporting, digital operational resilience testing, third party risk management and information sharing. Senior management carries accountabilities for all of it. Penalties are significant, reaching up to two percent of annual global turnover for financial entities, with higher exposure for the most serious breaches, and a separate regime for the critical providers the sector depends on.
Why UK Firms Are in Scope
A UK organisation cannot assume DORA is somebody else’s concern. For financial entities inside its scope, DORA takes the place of the general obligations that would otherwise apply, and its third-party provisions extend its reach well beyond the EU’s regulated firms. A UK business that provides ICT or security services to an EU financial entity is drawn in through the contracts, assessments and evidence its customers are now required to demand.
The point was underlined in late 2025 when European authorities named their first set of critical ICT third party providers, a list that included the major cloud and technology platforms the sector relies on, placing them under direct oversight. Financial entities must record their dependencies on such providers and assess the concentration risk that comes with them, and that scrutiny flows down the supply chain to everyone involved in delivering those services.
What DORA Demands from Your Logging and Monitoring
Beneath the legal language, a great deal of DORA depends on the quality of your operational data. Several obligations are difficult to imagine meeting without it.
- Incident detection and the reporting clock set a demanding pace. For a major incident an initial notification is expected very quickly after classification, an intermediate report follows within days and a final report within one month. Hitting those windows relies on fast, dependable access to the logs needed to scope and reconstruct what happened.
- Forensic evidence has to be preserved. DORA expects financial entities to reconstruct incidents in a defensible way, which means maintaining a clear chain of custody and audit trails that stand up to examination rather than a partial picture assembled after the fact.
- Resilience testing generates data that has to be captured and acted on. The results of testing, including the more advanced threat led exercises, are only useful if the evidence is retained and the lessons feed back into your controls.
- Third party risk has to be monitored, not just documented. Understanding the activity of the ICT providers you depend on is far easier when that activity is reflected in data you can actually see and search.
- Retention must be long enough to investigate, report and prove. Evidence that has aged out before you need it leaves the same gap as evidence you never collected.
Where Financial Firms Fall Short
The common weaknesses look familiar. Log coverage is uneven, with important sources missing or trimmed to control cost, so the gaps only become visible when an incident lands in one of them. The data that is collected is slow to search, which turns a tight reporting deadline into a frantic hunt through disconnected systems. Because sources are not normalised to a shared format, correlating an identity event with a network event and an endpoint event becomes a manual exercise rather than a query.
Chain of custody is often the weakest point of all. Few teams can produce a clean, defensible account of who did what and when across the whole estate, which undermines both the reporting obligation and the forensic expectations that sit behind it. Reporting itself is frequently improvised under stress, assembled by hand at the very moment the team can least afford the distraction.
A Data Centric Path to Resilience
Financial entities that find DORA manageable tend to treat their security data as core infrastructure rather than a byproduct. That begins with centralising the relevant sources and normalising them to a common standard such as the Open Cybersecurity Schema Framework, so information from very different systems can be searched and correlated together.
On that foundation the pillars become far more tractable. Fast, federated search lets a team scope an incident within the reporting windows instead of racing them. Compliance dashboards turn resilience from an annual set piece into a state you can see at any moment. Audit ready trails capture defensible evidence as a natural output of normal operation. Third party telemetry brings the providers you depend on into the same picture as everything else. The shift is from scrambling to answer a question you cannot quickly resolve, to operating from a position where the answer is already in front of you.
A Practical Note on Scope
DORA is directly applicable, but the way it bites on any given organisation depends on your role in the financial ecosystem, your specific ICT dependencies and the guidance issued by the relevant authorities. Treat this as an orientation to what the regulation asks of your data and confirm your precise obligations with your supervisory authority and your own legal advisers. The data foundations described here support resilience whatever the detail of your position.
HOOP Cyber helps financial services organisations build the security data foundation that DORA now requires, from centralised collection and normalisation to fast incident scoping, audit ready evidence and compliance dashboards. To talk through your resilience, get in touch at .