SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
All articles

DORA Pillar 5: Information & Intelligence Sharing, Voluntary, but a Maturity Signal

DORA's fifth pillar (Article 45) encourages financial entities to share cyber threat information and intelligence among trusted communities. It's voluntary, but participating is a clear sign of a mature resilience programme.

Denis Sota · · 2 min read

DORA’s fifth pillar (Article 45) is the shortest and the only voluntary one: it encourages financial entities to exchange cyber threat information and intelligence, indicators of compromise, tactics, techniques and procedures, alerts, within trusted communities of their peers. You won’t be penalised for not participating, but doing it well is one of the clearest signals of a mature resilience programme.

General guidance, not legal advice. Confirm specifics with your competent authority.

Why a “voluntary” pillar still matters

Threat actors reuse infrastructure and techniques across targets. When one financial entity sees an attack and shares the indicators, every peer that receives them can detect or block the same campaign faster. DORA recognises this collective-defence value and, importantly, makes clear that such sharing must happen within trusted arrangements and in line with data-protection rules, so it doesn’t become a back door for leaking sensitive information.

What participating looks like in practice

  • Join a trusted community, a sector ISAC (e.g. financial-services information sharing and analysis centres), a national CSIRT arrangement, or a vetted peer group.
  • Consume and act, ingest shared indicators into your monitoring and detection so the intelligence actually changes what you block and alert on.
  • Contribute back, share sanitised indicators from your own incidents, within your legal and confidentiality constraints.
  • Govern it, define what may be shared, with whom, and under what handling rules (e.g. traffic-light protocol), and keep it compliant with GDPR.

Information sharing is most useful when it plugs into a system that already knows your exposure. Threat intelligence about a vulnerability being actively exploited is only actionable if you can immediately answer “are we running the affected software?” Multi-source exploited-vulnerability intelligence mapped to your real inventory, what SentriKat does, turns an external alert into a specific, prioritised action instead of a notification you file away.

Start here

Identify the relevant sector ISAC or trusted community for your jurisdiction and join it, wire its feeds into your detection, and write a one-page sharing policy (what, with whom, handling rules). Low effort, and it visibly raises the maturity of your DORA programme.

Curious how you score across all five DORA pillars? The free, anonymous NIS2/DORA readiness check gives you an indicative per-pillar result in about five minutes.

Ready to automate your vulnerability management?

Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.

Request a Demo