DORA active defense
A cornerstone for EU financial entities: how Threxen’s DORA-aligned tenants run ICT-risk management as a workload, keep the cross-border delegation surface replayable, and bind every incident packet to the regulator’s notification cadence.
DORA — Regulation (EU) 2022/2554 — applies to financial entities and their ICT third-party service providers. Chapter II sets risk-management obligations (Articles 5–16): ICT risk framework (5), ICT-supported business continuity (12), identification of critical functions (8), system protection (9), incident handling (17), crisis management (18), and resilience testing (24–27). Chapter IV sets the contract terms with ICT third-party providers (Articles 28–30), which is the surface most EU entities trip on first. A DORA-aligned Threxen tenant pins Article 9(2) protection as a workload, runs Article 17 incident reporting to the name the regulator expects, and exposes Article 28 audit rights in the trust-surface at /trust so the auditor sees the same perimeter the analyst sees.
Cross-border delegation is what a DORA tenant signs up to. The packet a Threxen tenant emits under attack is the same one the competent authority in the home Member State reads — Art. 23 sets the initial 24-hour notification, the 72-hour intermediate, and the one-month final report, and the packet Threxen emits satisfies all three notifications in a single sealed chain. When the actor’s tooling is downstream of an ICT third-party provider, Article 25(2) concentration risk is named in the same packet; if the third-party is the source of the compromise, Article 28 contractual terms are the surface for attestation.
Active-defense containment under DORA reduces to the articles that bind the regulator: Article 9(2) protection as the live policy the agents act on, Article 12(4) business continuity as the response half of the loop, and Article 18(1) resilience testing as the engine that drives continuous verification. The packet is the on-call artifact — Articles 17 + 19 + 28 in one chain — and the analyst can pivot it back through Art. 5 ICT risk framework without rewriting the incident. The full mapping is at /resources/sector-coverage.
Read this regulator alongside its four peers.
The same four capabilities — host isolation, live credential poisoning, decoy surface, and the hash-chained evidence packet — are mapped onto each named article, requirement, or control of every regulated framework Threxen ships a policy pack for. The comparison matrix is the single page that lays them side by side.
▸ four sibling pillars · one matrix page · biometric-style read-across without re-reading five essays · security & compliance posture on the trust center