# DORA Year Two: Can Your SOC Actually See the Attack?
The Digital Operational Resilience Act entered enforcement phase across the European Union in January 2025, and the first year proved administratively brutal. Financial institutions spent twelve months establishing risk governance frameworks, auditing third-party service providers, rewriting vendor contracts, and documenting incident escalation procedures. Now halfway through DORA's implementation cycle, organizations face a sharper problem: knowing whether their security operations centers can detect threats when they arrive.
DORA's first year focused on compliance theater. Spreadsheets multiplied. Risk registers grew. Third-party questionnaires became templates copied between firms. The low-hanging fruit of governance infrastructure got addressed. Financial regulators across the EU accepted documentation, endorsed frameworks, and cleared initial compliance checkpoints. But compliance architecture and actual detection capability occupy different universes.
The second year of DORA enforcement pivots to operational resilience testing. The regulation demands more than policies on paper. Article 19 of DORA mandates "advanced testing of ICT capabilities and operational resilience." This translates into tangible adversarial simulation. Regulators expect financial entities to run attack scenarios, penetration tests, and adversarial simulations against their own infrastructure. The European Banking Authority and national financial regulators now validate that SOCs can spot intrusions, contain threats, and execute recovery procedures when pressure becomes real.
This shift exposes a fundamental weakness in many financial organizations. Documentation of incident response looks clean in review meetings. Actual detection rates look different. A SOC built to flag anomalies in routine network traffic often misses sophisticated intrusions designed to blend in. Lateral movement by attackers might traverse systems for days before triggering alerts. Data exfiltration can occur through legitimate business channels that bypass traditional monitoring.
The testing framework under DORA includes several components. Adversarial simulations pit red teams against blue teams to validate detection. Physical penetration tests verify that access controls function as documented. Logical penetration tests attack authentication systems, application vulnerabilities, and network boundaries. Supply chain resilience tests verify that financial organizations can withstand compromises in critical service providers. The EBA has outlined testing plans for 2025 and 2026 that will accelerate scrutiny.
Financial entities now confront uncomfortable realities. SOCs optimized for log analysis may lack behavioral analytics to catch account compromise. Monitoring designed around perimeter security may miss insider threats or compromised cloud credentials. Detection tools chosen years ago may run obsolete signatures while threats evolve. Incident response playbooks, even when tested, often fail under genuine pressure because teams, tools, and processes haven't operated together at speed.
DORA's second year demands that organizations move from "we have a process" to "our process works." This requires rearchitecting monitoring stacks, hiring SOC staff with deeper expertise, and running unannounced tabletop exercises to validate response times. Regulators will begin publishing testing results, creating competitive pressure among institutions to demonstrate real detection capability rather than compliant documentation.
Organizations that treated DORA's first year as a checkbox exercise now face uncomfortable reckonings. Auditors and regulators will interrogate detection rates, time-to-detect metrics, and actual response times. Financial institutions that believed their SOCs were adequate will learn otherwise when red teams move through their networks undetected for hours or days. This is the real cost of DORA's second year: visibility into whether your defenses actually work.
