AttackIQ Introduces DORA Automated Assessments
August 06, 2024

AttackIQ announced the launch of testing aligned with the Digital Operational Resilience Act (DORA).

This empowers financial institutions in the European Union (EU) to gain important visibility to help support their compliance with DORA.

DORA mandates robust cybersecurity measures for financial institutions to withstand and recover from cyberattacks and operational disruptions. Key requirements include establishing ICT risk management frameworks, reporting ICT incidents, and conducting regular testing of ICT systems. AttackIQ has released new DORA assessments to simplify compliance testing by providing:

- Automated Threat Emulation: The DORA assessments execute the top tactics, techniques, and procedures (TTPs) employed by adversaries known to target financial services organizations. These TTPs reflect the latest intelligence and threat research into the top methods used by EU financial sector adversaries.

- Actionable Insights: The DORA Assessment Report provides comprehensive recommendations and mitigation strategies for any testing scenario that was not prevented. Recommendations are derived from the extensive knowledge base of the AttackIQ research team, enriched with insights from MITRE ATT&CK standards and industry best practices.

- MITRE ATT&CK Alignment: The DORA assessments align with MITRE ATT&CK, offering actionable insights in a framework leveraged by cybersecurity practitioners worldwide.

“AttackIQ is committed to helping EU financial entities & critical 3rd party providers strengthen their defenses against targeted attacks and achieve DORA compliance with minimal disruption,” said Carl Wright, Chief Commercial Officer of AttackIQ. “Our DORA assessments streamline the process by automating emulations based on real-world attacker behaviors outlined in MITRE ATT&CK.”

AttackIQ offers two test packages, Basic and Advanced, catering to different testing needs. The DORA Basic assessment evaluates essential, minimum functionalities of controls, providing a foundational understanding of their effectiveness. For a more in-depth analysis, the DORA Advanced assessment utilizes more sophisticated and targeted TTPs to go beyond the scope of the Basic tests.

Organizations leverage AttackIQ, to continuously test their security controls against real-world cyberattacks modeled on the MITRE ATT&CK framework. This allows them to identify weaknesses, prioritize security investments, and ensure their defenses are working effectively to prevent breaches and data loss.

AttackIQ DORA Basic and Advanced Testing Packages are now available to customers.

Share this

Industry News

September 16, 2024

Docker is introducing a new way for developers and organizations to access its suite of products – including Docker Desktop, Docker Hub, Docker Trusted Content, Docker Scout, Docker Build Cloud, and Testcontainers Cloud.

September 16, 2024

The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the launch of the OpenSearch Software Foundation, a community-driven initiative that will support OpenSearch and its search software, which is used by developers around the world to build search, analytics, observability, and vector database applications.

September 16, 2024

Copado announced the Copado AI platform encompassing a suite of AI-powered DevOps agents.

September 16, 2024

Kong announced the release of Kong Gateway 3.8, a major update that sets a new standard for API management.

September 16, 2024

Perforce Software announced that its mobile application testing platform, Perfecto, will support Apple's latest iOS version, iOS 18, on Monday, September 16, 2024.

September 12, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader in the latest GigaOm Radar Report for Security Policy as Code.

September 12, 2024

JFrog announced the addition of JFrog Runtime to its suite of security capabilities, empowering enterprises to seamlessly integrate security into every step of the development process, from writing source code to deploying binaries into production.

September 12, 2024

Kong unveiled its new Premium Technology Partner Program, a strategic initiative designed to deepen its engagement with technology partners and foster innovation within its cloud and developer ecosystem.

September 11, 2024

Kong announced the launch of the latest version of Kong Konnect, the API platform for the AI era.

September 10, 2024

Oracle announced new capabilities to help customers accelerate the development of applications and deployment on Oracle Cloud Infrastructure (OCI).

September 10, 2024

JFrog and GitHub unveiled new integrations.

September 10, 2024

Opsera announced its latest platform capabilities for Salesforce DevOps.

September 09, 2024

Progress announced it has entered into a definitive agreement to acquire ShareFile, a business unit of Cloud Software Group, providing SaaS-native, AI-powered, document-centric collaboration, focusing on industry segments including business and professional services, financial services, healthcare and construction.

September 05, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux (RHEL) AI across the hybrid cloud.