According to The Hacker News, when the EU's Digital Operational Resilience Act became enforceable in January 2025, financial entities responded with an administrative push. The first year was spent building risk governance, assessing third-party service providers, and updating foundational processes.
Now, in year two, the open question is whether a security operations center can actually see an attack. The article frames this as a more demanding test than initial compliance: having policies in place is not the same as having visibility into malicious activity.
Because the source excerpt is limited, it does not provide specific incident examples or metrics. What is clear is that the conversation has moved from meeting deadlines to measuring operational detection.