The EU’s Digital Operational Resilience Act sets out how financial entities must manage ICT risk and keep critical services running through disruption. Loxada addresses one part that most programs underplay: the security of the networks staff, contractors and board members actually connect from.
DORA (the Level 1 Regulation, (EU) 2022/2554) places obligations on financial entities and their ICT providers, with the operative detail set out in the technical standards beneath it, principally the RTS on ICT risk management (Commission Delegated Regulation (EU) 2024/1774). Together they require financial entities to manage ICT risk across their environment, including the access points their people use.
Most DORA programs concentrate on internal systems, third-party oversight and incident reporting. Fewer account for how staff, contractors and board members connect remotely to sensitive systems, from home networks, serviced offices or hotels. That leaves a gap in the ICT risk picture.
An encrypted-connectivity client protects traffic in transit, but it assumes the local network beneath it is sound. A compromised home router, a misconfigured serviced-office network or a spoofed hotel hotspot can all sit under that assumption, even where the device has endpoint protection and remote-desktop tools.
This is not an inference about DORA’s intent. The technical standard addresses it directly. Its requirements on network security management call for financial entities to encrypt network connections passing over corporate, public, domestic, third-party and wireless networks, and to operate network access controls that prevent connections from any unauthorized device or any endpoint that does not meet the entity’s security requirements. Alongside that, it requires security measures ensuring that teleworking and the use of private endpoint devices do not adversely affect the entity’s ICT security.
Domestic networks are named in the text. For a distributed workforce, that is the uncontrolled network edge, described in the regulation itself.
Loxada offers a practical, low-overhead way to strengthen the access-control and secure-connectivity aspects of a DORA program. Our managed secure routers create an isolated work network and route traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet, keeping it clear of the local network. They are pre-configured, centrally managed, and require no technical knowledge from the user.
This gives compliance and IT teams a consistent, controllable way to secure external access, aligned with DORA’s emphasis on control and operational continuity. Deployment is fully auditable, with monthly security reports and device-status visibility.
DORA applies to approximately 22,000 financial entities across the EU and has been directly applicable since January 17, 2025. Loxada provides practical coverage for access-layer challenges that are otherwise hard to close:
This is the part that matters most for DORA. A staff member’s home or hotel network is a dependency the financial entity relies on but cannot contract with, audit or control. Under DORA’s third-party logic, that is an awkward gap: a real dependency with no accountable provider behind it.
Loxada changes the shape of that dependency. Placing a managed secure router at the point of connection replaces the uncontrolled local network with a defined service from a named provider, one that can be recorded, described and audited as part of the entity’s ICT third-party arrangements. An unmanageable dependency becomes a documented one.
Loxada provides ICT services to the financial entity and is therefore an ICT third-party service provider in DORA’s terms, able to be recorded in the entity’s register of information and governed by contract under DORA’s third-party provisions.