DORA (Regulation (EU) 2022/2554) has applied to EU financial entities since January 2025, covering banks, insurers, investment firms, payment institutions, and crypto-asset providers. It demands demonstrable ICT risk management, incident detection, and recovery capability. DNS underpins every digital channel a financial entity operates, and ZoneWatcher provides the monitoring evidence DORA supervisors expect.
DNS in Your ICT Risk Framework
A financial entity's DNS records route customers to online banking, connect payment APIs, and direct transaction traffic between systems. A hijacked record redirects customers to a credential-harvesting clone. A misconfigured one takes a trading platform offline. DORA's ICT risk-management framework explicitly covers the network infrastructure these scenarios run through — and expects you to detect them promptly, not discover them from customer complaints.
Relevant DORA Articles
Article 8 — Identification
Financial entities must identify and classify all ICT-supported assets and their dependencies. ZoneWatcher automatically discovers and inventories DNS records across every provider you use, keeping a current register of the DNS layer your critical functions depend on.
Article 10 — Detection
DORA requires mechanisms to promptly detect anomalous activities. ZoneWatcher continuously checks your DNS records, nameservers, WHOIS data, and TLS certificates, alerting your team the moment something deviates — with AI risk scoring to separate routine changes from ones that need attention.
Articles 11 & 12 — Response, Recovery, and Backup
Entities need response and recovery plans backed by tested backup capability. ZoneWatcher maintains complete zone snapshots exportable as BIND or CSV, so a damaged or deleted record set can be restored from known-good data — evidence of recovery capability for the DNS layer.
Article 17 — ICT-Related Incident Management
DORA requires a process to detect, manage, and notify ICT-related incidents, with classification and reporting deadlines for major ones. ZoneWatcher's real-time alerts feed directly into that process, and the change history supports the root-cause analysis DORA expects in final incident reports.
Third-Party Risk Without Blind Spots
DORA's third-party risk provisions (Article 28 onward) make you responsible for the ICT services you outsource — and DNS hosting is exactly that. ZoneWatcher monitors your records independently of any single provider, so you're not relying on a vendor to tell you their own platform was compromised. If credentials at a registrar or DNS host are abused, the resulting record changes surface in your alerts immediately.
Evidence for Supervisors and Auditors
A current, automatically maintained inventory of DNS assets across providers
A timestamped audit trail of every change, with before and after values
Proof of continuous detection capability and configured alerting channels
Exportable zone backups demonstrating recovery readiness
Point-in-time PDF reports for board reporting and supervisory reviews
A note on certifications
This guide explains how ZoneWatcher helps your organization prepare for its own audit against this framework. It is not a claim that ZoneWatcher holds this certification. For details on how we secure ZoneWatcher itself, see our security overview.
Ready to protect your DNS?
Start your free trial today and get full access to all monitoring features.