DORA Year Two: Can Your SOC Actually See the Attack?

As we mark the second anniversary of DORA, a critical security framework designed to help organizations fortify their defenses against sophisticated cyber threats, a growing body of evidence suggests that many Security Operations Centers (SOCs) are still struggling to see the attack in real-time. A new wave of research has uncovered 11 compelling case studies, each highlighting the devastating consequences of identity exposure and its role in facilitating active attack paths.

At its core, DORA aims to bridge the gap between traditional security measures and the reality of modern threat landscapes. By mapping cross-domain privilege escalation routes, organizations can identify critical choke points where breaches often occur. However, despite these best intentions, a disturbing trend has emerged: many SOCs are still unable to detect attacks in their earliest stages, allowing malicious actors to exploit vulnerabilities before they can be addressed.

One key factor contributing to this problem is the sheer complexity of modern identity management systems. With an ever-increasing number of users, devices, and applications, it’s becoming increasingly difficult for organizations to maintain a clear understanding of who has access to what, and under what conditions. This lack of visibility creates a perfect storm for attackers, who can exploit seemingly minor vulnerabilities to gain unfettered access to sensitive systems.

In the field of cybersecurity, the concept of “identity exposure” refers to the unintentional disclosure of sensitive information about users or entities within an organization’s system. This might involve exposing login credentials, API keys, or other privileged data that could be used to bypass security controls and launch targeted attacks. The consequences can be catastrophic: once identity exposure occurs, attackers often have a clear path to escalate privileges, move laterally across the network, and ultimately achieve their objectives.

The 11 case studies cited in this research paint a sobering picture of the devastating impact of identity exposure on organizations worldwide. From financial institutions to healthcare providers, each scenario highlights the ease with which malicious actors can exploit vulnerabilities in identity management systems to breach security perimeters and wreak havoc on sensitive data.

So what does this mean for your organization? The takeaway is clear: if you’re relying solely on traditional security measures to detect and respond to threats, you’re likely leaving yourself vulnerable to attack. By adopting a more proactive approach to security – one that prioritizes real-time visibility into identity exposure and privilege escalation routes – you can significantly reduce the risk of breach and protect your most sensitive assets.

Ultimately, DORA’s success will depend on our collective ability to adapt to the evolving threat landscape and stay ahead of sophisticated attackers. By acknowledging the limitations of traditional security measures and embracing a more holistic approach to cybersecurity, we can work together to build stronger, more resilient defenses that truly meet the challenges of modern threats.


Source: The Hacker News — 2026-09-22