Continuous testing for DORA's ICT risk and resilience rules
Hadrian maps your internet-facing ICT assets, validates which exposures an attacker can exploit and runs pentests on demand. Your team gets current findings and reports for Articles 8, 24 and 25.
CA Indosuez used Hadrian's continuous asset discovery to find risks from M&A activity and to align with DORA requirements.
DORA requirements Hadrian supports
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025. It covers 20 types of EU financial entities, including banks, payment and e-money institutions, investment firms, crypto-asset service providers and insurers, plus the ICT third-party service providers that serve them.
Identify and map ICT assets and risks
Identify all information and ICT assets, map how they connect, and keep inventories up to date after every major change. Identify sources of ICT risk and assess cyber threats and vulnerabilities on a continuous basis.
Atlas builds and maintains an inventory of your internet-facing assets, technologies and services from the outside in. Passive scans run every hour, and changes to an asset trigger new tests.
An exported inventory of internet-facing assets and the technologies on each, plus dated findings raised when assets changed.
Monitor the security of ICT systems continuously
Continuously monitor and control the security and functioning of ICT systems, and keep the impact of ICT risk low with the right security tools, policies and procedures.
Atlas monitors your external attack surface around the clock and validates which exposures can be exploited, so your team works on confirmed issues on internet-facing systems.
A current list of validated exposures on internet-facing systems, each with severity and business context.
Remediate test findings and confirm the fix
Set procedures to prioritize, classify and remedy every issue that testing reveals, and a way to confirm each one is fully fixed. Test the ICT systems and applications that support critical or important functions at least once a year.
Findings come with severity, reproduction steps and remediation guidance, and can be sent to Jira or ServiceNow. Hadrian retests risks once they are marked resolved, and Nova retesting is included at no extra cost.
Per-finding records showing when the issue was found, who owned it, how it was fixed and the retest result.
Run a range of security tests, including pentests
Your digital operational resilience testing program should include appropriate tests, such as vulnerability assessments and scans, network security assessments, scenario-based tests and penetration testing.
Atlas runs continuous, event-driven tests against your external attack surface. Nova runs scoped pentests of web apps and APIs on demand, and Hadrian maps the Nova report to DORA Article 25.
Nova pentest reports with an executive summary, methodology, risk ratings, reproduction steps and remediation guidance.
Threat-led penetration testing for identified entities
Financial entities identified by their competent authority must run threat-led penetration testing (TLPT) at least every three years. TLPT covers critical or important functions on live production systems and uses testers that meet Article 27.
Your TLPT stays with your TLPT provider. Between TLPT cycles, teams use Atlas to keep an up-to-date view of internet-facing systems and Nova to find and close exposures before the test starts.
A current external asset inventory and a record of the validated exposures you closed before the TLPT window.
Manage ICT third-party risk
Manage ICT third-party risk as part of your ICT risk management framework. Identify the processes that depend on ICT third-party service providers and the connections to providers that support critical or important functions.
Atlas fingerprints the third-party technologies and services on your external attack surface and shows the exposures vendors add to it. Secure Share sends a single risk to a third party without giving them platform access.
A list of third-party technologies on your internet-facing assets, and the vendor-related risks you shared and closed.
Hadrian supports these DORA requirements for your external attack surface. It does not certify DORA compliance or replace TLPT.
An ICT asset inventory that keeps itself current
DORA asks you to identify every ICT asset, map how they connect and update your inventories when things change. Atlas discovers your internet-facing assets the way an attacker would. Passive scans run every hour, and any change starts new tests. Shadow IT and acquired assets land in the same inventory.
Resilience testing that runs between test cycles
Article 25 lists vulnerability scans, network security assessments and penetration testing among the tests to run. Atlas tests your external attack surface continuously and validates each exposure before your team sees it. Nova adds scoped pentests of web apps and APIs, and most tests finish within 24 to 48 hours.
Fix, retest and keep the record
Article 24 asks you to prioritize, classify and fix issues found in testing, then confirm they are fully addressed. Every Hadrian finding has reproduction steps and remediation guidance. When a risk is marked resolved, Hadrian retests it, and the risk timeline shows who owned it and when it closed.
More from customers
Crédit Agricole Personal Finance & Mobility
A financial services provider that must comply with regulations such as DORA now tracks 5,000+ assets in real time, with 15 teams on role-based access.
Worldstream
A Dutch cloud infrastructure provider and ICT third-party service provider under DORA uses Hadrian for continuous outside-in visibility and validated findings.
No single tool can. DORA compliance depends on your governance, ICT risk management framework, incident reporting, third-party arrangements and testing program as a whole. Hadrian supports the parts that concern your external attack surface: identifying internet-facing ICT assets (Article 8), monitoring their security (Article 9) and testing them (Articles 24 and 25). Your auditors and competent authority judge whether your program meets the regulation.
No. DORA defines TLPT as a controlled, bespoke, intelligence-led red team test of critical live production systems, run by testers that meet Article 27. Teams use Hadrian alongside it. Atlas keeps an up-to-date view of your internet-facing systems, and Nova runs pentests on demand, so known external exposures are found and fixed before the TLPT starts.
Each Nova report has an executive summary, methodology, risk ratings, reproduction steps and remediation guidance. Hadrian's offensive security team validates every finding before delivery. Hadrian maps the report to DORA Article 25, as well as to SOC 2, ISO 27001 and NIS2, so it can go to engineering, leadership and auditors.
Yes. Article 2(1)(u) brings ICT third-party service providers into DORA's scope, and your financial-sector customers must manage the risk you bring under Article 28. Expect them to ask about your own security testing. Worldstream, a Dutch cloud infrastructure provider that serves as an ICT third-party service provider under DORA, uses Hadrian for continuous, validated visibility of its external attack surface.
NIS2 treats DORA as a sector-specific act for financial entities. Recital 28 of NIS2 says DORA's provisions on ICT risk management, incident reporting, resilience testing, information sharing and ICT third-party risk apply instead of the equivalent NIS2 provisions. Article 4 of NIS2 sets out how that works.
See your external ICT risk the way an attacker does
Book a demo to see how Atlas and Nova map, test and validate your internet-facing assets, and what your team can hand to auditors and supervisors.