
The DORA regulation, which sets out to strengthen the digital operational resilience of banking and financial sector players, was published in the Official Journal of the European Union on 27 December 2022. From January 2024, financial entities will have one year to comply.
As a reminder, digital operational resilience — the guiding principle of the DORA project led by the European Commission — can be understood as an organisation’s or a company’s ability to keep delivering its services while under a computer attack or during a cyber incident. In concrete terms, DORA proposes a regulatory framework, applicable within companies, to prevent cyberattacks and the IT risks tied to information and communication technologies (ICT).
“There is an urgent need to help companies anticipate, prepare and work on their cybersecurity actively, engaging with them as early as possible. You have to Know in order to Act before you Suffer.”
The main issues at stake in the European DORA regulation
Before DORA arrived, the approach was ‘defensive’ security, protecting yourself after the fact. With the concept of resilience, financial sector companies have to organise themselves from the outset to keep working despite outages, and above all despite cyberattacks. Cybersecurity must now be active if operational resilience is to be reached.
This is a genuine paradigm shift in the field of information systems security.
In DORA’s sights: financial firms…
The new regulation applies to 20 types of financial firm with more than 10 employees and annual turnover and/or an annual balance sheet total of at least 2 million euros, but it also concerns their IT providers — ‘ICT third-party service providers’, in DORA’s wording. They include credit and payment institutions, electronic money institutions, investment firms, crypto-asset service providers, trading venues, management companies, insurance and reinsurance undertakings and their intermediaries, institutions for occupational retirement provision, credit rating agencies, crowdfunding service providers, and managers of alternative investment funds…
In all, tens of thousands of companies are concerned across Europe.

What does it change day to day?
It means running many new tests and taking a broader view of cyber risk. Under this new standard the point is not only to protect systems but to protect data as well. This new perspective will transform the cyber risk management landscape, and there is an urgent need for every profession handling sensitive data (insurers, doctors, lawyers, notaries, accountants and auditors) to adopt this kind of standard too.
In practice, the change means an obligation to run digital operational resilience tests at least once a year, in which open source analysis remains one of the first requirements.
People at the heart of the system
According to CESIN’s 8th annual barometer, published in 2023, 74% of companies name phishing as the main entry vector for the attacks they suffered. People, and the interconnection of entities, therefore remain the key to cybersecurity. People, suppliers and suppliers’ subcontractors have too often been left out of data and information system protection standards. Yet every day a company’s data leaves it — not in bulk as in a ransomware case, but more discreetly, in very small volumes, which taken together yield a great deal of information about a company’s assets: domain and sub-domain certificates, information from and about employees, the very structure of the company (org chart, site addresses, building plans) and sensitive identifying information about staff (payslips, expense claims, personal circumstances), maps of the information system, sales files, invoices, contracts, NDAs and so on. All of it is put at risk by employees, suppliers, customers and their own third parties, to whom the company sends information every day — and sometimes by the sub-sub-subcontractors of all these entities. That is where the danger lies.
In this ocean of data published on the web, the essential thing to grasp is that people are on the front line. Every employee needs to understand the effect they can have on their organisation through the data they handle day to day.

The risk of micro-leaks
Information disclosed in micro-volumes over the years, and regularly circulated on social networks, in the deep web and in the dark web, remains available to consult and feeds those with ill intent.
Through this cyber intelligence, criminals prepare, organise and carry out actions against a company and its various assets. Just as ethical hackers gather information about their targets during a pentest campaign, malicious actors develop strategies and industrialise techniques to collect weak signals and use them to build phishing campaigns, extortion, and to force entry points (SharePoint, web access points and so on) in order to penetrate company systems, spy on them, deceive them, extort them or defame them.
“As ANSSI’s May 2022 report puts it: ‘whether they follow a ransomware attack or plain negligence, whether they are put up for sale by cybercriminals or exposed as part of information operations tied to ideological or political claims, data disclosures are an opportunity for attackers to act’. There is therefore an urgent need to help companies anticipate, prepare and work on their active cybersecurity, engaging with them as early as possible. You have to Know in order to Act before you Suffer.” says Victor Raffour, Deputy Chief Executive of Aleph.
Aleph, the solution for protecting your assets and getting ahead of the European DORA regulation
The first requirement is to put analyst and security teams in place and equip them to map the company data circulating outside the company — and, as with any risk, to plan the response to a cyberattack so that services stay resilient.
“Companies guard against fire risk by fitting smoke detectors; they are also required to train their teams to qualify the alert when a detector goes off. In the same way, analyst teams working on cyber risk have to ignore the organisation’s internal silos in order to protect it, because in cyber every department can hand over the key to a door through which an attacker will bring the building down from the inside.” Victor Raffour continues.
As a software publisher specialising in indexing and searching data across the clear, deep and dark webs, Aleph is doubly concerned by the regulation. Aleph allows financial firms both to supervise and monitor their strategic assets (their own, or those entrusted to them) available in open sources across the clear, deep and dark web, and to put the obligations of this new regulation in place on those companies’ behalf.
Aleph makes two pieces of software available to its clients, along with the associated service offerings.
How can Aleph help you prepare for the DORA regulation?
- Aleph Search Dark: the benchmark search and analysis engine for the dark and deep webs, and the most powerful on the market. Emails and passwords, identity documents, payslips, tax returns, bank cards and IBANs, information about physical sites, information about clients covered by banking secrecy (business plans, NDAs…) and about the company’s key people, forums where violent activists exchange plans to disparage or harm a company or an organisation…: the tool searches for traces and data across the dark and deep webs, maps the communities of those webs, anticipates new threats, identifies clusters of influence and looks for particular structuring elements. It gives a fast understanding of a company’s environment, the better to protect it. It is also used to map existing links of influence and the exchanges between competitors and suppliers.
- Aleph Search Clear: starting from sites of interest already identified, this solution explores the company’s relational environment and discovers and qualifies new specific sources so that their data can be indexed, in order to anticipate strategic and tactical breaks. In concrete terms, it allows Aleph’s clients to supervise their digital pattern on the clear web in near real time and to map their ecosystem: production websites still live, links to SharePoints, fake phishing sites, and so on…
“As a supplier to financial firms, we work continuously on new algorithms so that our clients can be alerted in near real time to the availability of their sometimes most sensitive information in the deep and dark web. I would add that, in accordance with the regulations in force, Aleph publishes search engines with a code of conduct and a formal ethical framework: only white and grey data is indexed by our search engines. We do not take in black data (data obtained through authentication, identity theft or hacking). Our crawler technology lets us guarantee to our clients that no human interaction and no hacking is involved in indexing the data. ” Victor Raffour concludes.