← Blog

DORA is here: what operational resilience really means for your network

The EU Digital Operational Resilience Act has been fully applicable since 17 January 2025, and the grace period is over. National regulators collected the first Register of Information filings by the end of March 2026, and the early picture is sobering: industry estimates suggest only about half of in-scope firms are fully compliant. With penalties reaching up to 10% of annual turnover, “we’ll get to it” is no longer a defensible position.

Most DORA commentary focuses on governance, paperwork, and vendor contracts. That matters — but it skips the layer where operational resilience is actually won or lost. Trades don’t clear on a policy document. They clear across a network. And the network underneath financial services is exactly where DORA’s five pillars translate into concrete, testable requirements.

Translating the five pillars into network reality

DORA rests on five pillars — ICT risk management, incident reporting, resilience testing, third-party risk oversight, and information sharing. Read them as a network engineer and they stop being abstract.

ICT risk management starts with knowing what you have and how it connects. You cannot manage risk in an estate you cannot fully see. That means an accurate, current picture of routing, BGP adjacencies, VRF and MPLS boundaries, circuits, and configuration across every vendor in the estate — not a diagram from two years ago that nobody trusts.

Incident reporting runs on the clock. DORA sets tight windows for classifying and reporting major incidents, and you cannot report what you cannot explain. When something breaks, the question isn’t only “what alarmed?” but “what changed, when, and what did it touch?” A history of network state — the ability to compare now against a known-good point in time — turns a frantic reconstruction into a factual timeline.

Resilience testing means proving the network survives failure before failure finds you. That is failure-impact analysis: if this link, this peer, or this device drops, which services lose reachability, and does traffic actually reconverge the way the design assumes? Testing resilience on paper is not testing resilience.

Change is where resilience quietly erodes

Here is the uncomfortable truth behind most major incidents: the network was resilient until someone changed it. A route-target edit, a filter tweak, a maintenance window that didn’t roll back cleanly — each is a small bet that nothing downstream breaks.

DORA’s emphasis on governance and testing points directly at change intelligence: understanding the blast radius of a change before it ships, and holding evidence of exactly what changed after. That evidence is what turns an audit from an anxious scramble into a document you already have. When a regulator asks how you assessed the risk of a change, “we predicted the impact, approved it, executed it, and confirmed the result matched” is a complete answer.

Third-party dependencies don’t stop at the contract

The third-party risk pillar is usually framed as vendor due diligence. But your exposure to a provider isn’t only contractual — it’s topological. A carrier circuit, a peering relationship, a managed connection: these are load-bearing dependencies whose health you’re accountable for even when you don’t operate them. Overseeing third-party risk means continuously seeing those connectivity dependencies and knowing, in real time, when one degrades — not learning about it from the counterparty after settlement fails.

Across all five pillars, the same capabilities keep surfacing: know your estate precisely, detect and explain incidents fast, test resilience against real failure, govern change with evidence, and watch the dependencies you don’t control. That is a network-state and change-intelligence problem, and it’s exactly where firms that treated DORA as a legal exercise are now discovering gaps.

Phantom Networks was built for this layer — continuously tracking deep network state across multi-vendor estates, keeping a defensible history, predicting change impact before the window opens, and producing the evidence resilience testing and audits demand. It runs entirely on your own infrastructure, so nothing sensitive ever leaves your network. Explore how this maps to your obligations in our financial services solutions and security and compliance overviews.

If DORA has moved from a project plan to a live obligation, the network is where you’ll prove it. See it in a demo.

Change the network with confidence.

Book a demo