Stylised illustration of a Loxada device
Secure Remote Access

Secure Remote Access for DORA Compliance

The EU’s Digital Operational Resilience Act sets out how financial entities must manage ICT risk and keep critical services running through disruption. Loxada helps address one part that most programs underplay: the security of the networks staff, contractors, and board members actually connect from.

The Problem

DORA (the Level 1 Regulation, (EU) 2022/2554) places obligations on financial entities and their ICT providers, with the operative detail set out in the technical standards beneath it, principally the RTS on ICT risk management (Commission Delegated Regulation (EU) 2024/1774). Together they require financial entities to manage ICT risk across their environment, including the access points their people use.

Most DORA programs concentrate on internal systems, third-party oversight, and incident reporting. Fewer account for how staff, contractors, and board members connect remotely to sensitive systems, from home networks, serviced offices, or hotels. That leaves a gap in the ICT risk picture.

An encrypted-connectivity client (a VPN) protects traffic in transit, but it assumes the local network beneath it is safe. A compromised home router, a misconfigured serviced-office network, or a spoofed hotel hotspot can all sit under that assumption, even where the device has endpoint protection and remote-desktop tools.

This isn’t an inference about DORA’s intent. The technical standard addresses it directly. Its requirements on network security management call for financial entities to encrypt network connections passing over corporate, public, domestic, third-party, and wireless networks, and to operate network access controls that prevent connections from any unauthorized device or any endpoint that doesn’t meet the entity’s security requirements. Alongside that, it requires security measures ensuring that teleworking and the use of private endpoint devices don’t adversely affect the entity’s ICT security.

Domestic networks are named in the text. For a distributed workforce, that is the uncontrolled network edge, described in the regulation itself.

Stylised illustration of a Loxada device

Loxada’s Solution

Loxada offers a practical, low-overhead way to strengthen the access-control and secure-connectivity aspects of a DORA program. Our managed secure routers create an isolated work network and route traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet, keeping it clear of the local network entirely. They are pre-configured and centrally managed, and need no technical knowledge from the user.

Secure connectivity from any location. Staff can work from home, client offices, hotels, or co-working spaces without exposing the organization to the surrounding network.

Hardware-enforced network separation. Devices behind a Loxada secure router are isolated from the local network, even if that network is compromised.

Automatic updates and configuration integrity. Firmware is centrally managed and updated using cryptographically signed packages; users can’t modify the device, and it returns to a secure state after a reset.

Blocks known malicious domains. Requests to domains on Loxada’s aggregated blocklist of known-bad domains are dropped before they resolve.

Subscription-linked control. Access can be revoked centrally by ending the device subscription, removing the need for manual tracking.

This gives compliance and IT teams a consistent, controllable way to secure external access, aligned with DORA’s emphasis on control and operational continuity. Deployment is fully auditable, with monthly security reports and device-status visibility.

Benefits and Scenarios

DORA applies to approximately 22,000 financial entities across the EU and has been directly applicable since January 17, 2025. Loxada provides immediate, practical coverage for access-layer challenges that are otherwise hard to close:

Home-based finance and risk staff handling trading data, internal systems, or client records, connecting from known-good networks.

Senior executives and board members, who often sit outside day-to-day IT onboarding, given a consistent secure access point.

Third-party contractors and remote partners, extended a controlled access method without overloading internal IT.

Business continuity, maintaining a fallback route for critical staff during partial outages or isolation events.

Stylised illustration of a Loxada device

Turning an Uncontractable Dependency Into a Defined ICT Service

Here is the part that matters most for DORA. A staff member’s home or hotel network is a dependency the financial entity relies on but cannot contract with, audit, or control. Under DORA’s third-party logic, that’s an awkward gap: a real dependency with no accountable provider behind it.

Loxada changes the shape of that dependency. By placing a managed secure router at the point of connection, the uncontrolled local network is replaced with a defined service from a named provider, one that can be recorded, described, and audited as part of the entity’s ICT third-party arrangements. An unmanageable dependency becomes a documented, controllable one.

Loxada provides ICT services to the financial entity and is therefore an ICT third-party service provider in DORA’s terms, able to be recorded in the entity’s register of information and governed by contract under DORA’s third-party provisions.

Build DORA Resilience from the Network Edge Outward

Talk to us about how Loxada can support the access-control and secure-connectivity aspects of your DORA program, without complicating your IT stack..