Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

DORA, explained: what it actually asks you to do

The Digital Operational Resilience Act has applied since January 2025. Five obligations, and the one that catches most firms out.

Updated August 2026 · 8 minute read

What DORA is

The Digital Operational Resilience Act is an EU regulation that sets a single standard for how financial entities manage information and communications technology risk. It has applied since 17 January 2025.

Because it is a regulation rather than a directive, it applies directly. There is no national implementation to wait for and no local variation to interpret, which is a meaningful difference from NIS2.

Scope is broad. It reaches banks, investment firms, insurers, payment institutions, crypto-asset service providers, trading venues and more, and it reaches the ICT providers those firms depend on.

The five pillars

ICT risk management. A governed framework, owned by the management body, covering identification, protection, detection, response and recovery. The management body is explicitly accountable, which is the part that changes board conversations.

Incident management and reporting. Classify ICT-related incidents against defined criteria and report major ones to your competent authority on a defined timetable. The work that makes this survivable is done before the incident, not during it.

Digital operational resilience testing. A programme of testing proportionate to your risk. For a subset of significant entities this includes threat-led penetration testing, which carries its own scope and provider requirements set by the regulator.

ICT third-party risk. Contractual requirements, oversight, exit strategies, and a register of information on all contractual arrangements with ICT providers.

Information sharing. Permitted and encouraged between entities on cyber threat information.

The register of information

This is the pillar firms consistently underestimate. It is not a vendor list. It is a structured record of every contractual arrangement for ICT services, at entity level, with the detail needed to understand which services support which functions and where concentration sits.

The difficulty is rarely the template. It is that the underlying information lives in procurement, in legal, in the CMDB and in several people memories, and none of those agree. Firms that treat the register as a reporting exercise rebuild it every submission. Firms that treat it as an operational record maintain it once.

What supervisors are actually asking

The pattern across the pillars is the same: show us that this operates. A policy describing a control and a control that demonstrably ran are different things, and DORA is written to close the gap between them.

That is why evidence generation matters more than documentation. If your evidence is produced by the act of operating, the supervisory conversation is a report you run. If it is assembled by hand for each review, it is a project you survive, and it will be out of date by the time it is finished.

Where to start

Map your important business services first, then the ICT and third parties each one depends on. Almost every DORA obligation resolves back to that map, and almost every firm that struggles has skipped it.

Whether and how DORA applies to your specific entities is a question for your counsel. We confirm applicability with you during onboarding rather than asserting it here.

FAQ

Questions, answered

Does DORA apply to us if we are outside the EU?
It can. DORA applies to in-scope financial entities in the EU, but it also reaches ICT providers serving them, and non-EU firms frequently encounter it contractually through EU clients who must flow the obligations down. The practical test is usually who your customers are, not where you are.
Is threat-led penetration testing mandatory?
Only for entities identified as significant by their competent authority, and where it applies it carries specific scope and provider requirements that must be met on their own terms. Continuous testing does not replace it; it keeps the picture current between formal exercises.
How does DORA relate to NIS2?
They overlap but are not the same. DORA is sector-specific to finance and directly applicable; NIS2 is broader and transposed nationally. Where both apply, DORA generally takes precedence for the financial entity as lex specialis. At control level the two ask for much the same things, which is why one control set can evidence both.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.