Skip to content

DORA

DORA Article 10: detection, and the exact numbers that make an incident "major"

Article 9 was about keeping attackers out. Article 10 accepts that some get in, and asks whether you would notice. It is short, but it connects to the most consequential numbers in the whole regulation: the thresholds in RTS 2024/1772 that decide when an incident stops being an internal matter and becomes something you must report to your supervisor. Today, detection and classification.

DORA on one page — now interactive

The oversight post ended with DORA on one page: a table matching each Level 1 article to the Level 2 standard that makes it concrete. A table is a decent start. But the DORA package isn't really a table — it's a graph. Fourteen legal acts, 215 articles, and a web of implements-links and cross-references that a table flattens out. So I built the version you can actually navigate.

DORA Article 6: the framework on paper, and the RTS that makes it real

Article 5 put the management body on the hook. Article 6 describes the thing they are on the hook for: the ICT risk management framework. And here is where most DORA write-ups stop too early, because Article 6 is only half the text you need. The other half lives in a delegated regulation most people have never opened. Today I want to connect the two.

DORA Article 5: what the management body actually signs up for

DORA gets treated like an IT project. Article 5 says otherwise. It is the first substantive article of the regulation, it is about governance, and it puts the board on the hook before a single firewall rule is mentioned. Today I want to walk through what Article 5 requires, what the defined terms actually mean, and what this looks like in practice.