Why DORA Is Exposing the Biggest Weakness in IT Governance
For years, organisations have treated asset registers as operational necessities rather than strategic instruments. They existed to support procurement, software licensing, infrastructure management, or occasional audits. As long as there was “a list somewhere,” many organisations assumed they had visibility and control.
DORA is changing that assumption completely.
Since the Digital Operational Resilience Act became applicable in January 2025, many financial institutions and ICT providers are discovering an uncomfortable reality: their asset data is incomplete, inconsistent, outdated, or fundamentally unreliable. And for the first time, this is no longer just an operational inconvenience, it is becoming a regulatory and resilience risk.
The issue is not whether organisations have an asset register. The issue is whether they can trust it.
The Illusion of Visibility
Many organisations believe they have mature visibility because they have:
- a CMDB
- endpoint management tooling
- procurement records
- cloud inventories
- discovery solutions
- or spreadsheets maintained by different teams
But DORA is exposing a critical problem: most of these systems operate in silos, with different owners, inconsistent standards, and conflicting data.
An asset may appear:
- in one system but not another
- under the wrong owner
- without a business criticality classification
- without vendor linkage
- without lifecycle information
- or still listed long after decommissioning
This creates what can best be described as an illusion of governance. On paper, the organisation appears in control. Operationally, it often is not.
Why DORA Changes the Stakes
Before DORA, inaccurate asset data usually resulted in:
- operational inefficiencies
- licensing issues
- slower audits
- or occasional security concerns
Now the consequences are much broader. Under DORA, organisations are expected to demonstrate operational resilience across:
- ICT risk management
- third-party oversight
- incident response
- business continuity
- vulnerability management
- and critical service mapping
Every one of these domains depends on reliable asset intelligence. If an organisation cannot confidently answer:
- what assets exist
- where they are
- who owns them
- which services they support
- which vendors are involved
- and whether they are critical
then resilience becomes theoretical rather than operational. DORA effectively elevates asset quality to a critical governance priority.
The Emerging Problem of “Compliance Theatre”
One of the more concerning developments since DORA’s implementation is the rise of what could be called compliance theatre. Many organisations have invested heavily in:
- policy creation
- governance frameworks
- reporting structures
- and compliance documentation
But documentation alone does not create resilience. A beautifully written policy does not help during:
- a ransomware attack
- a major outage
- a third-party supplier incident
- or regulatory scrutiny following operational disruption
When incidents occur, organisations fall back on operational truth: their actual visibility, ownership, dependencies, and control. And this is exactly where weak asset governance becomes visible.
The organisations that struggle most under DORA are often not the ones lacking policies.
They are the ones lacking trustworthy operational data.
The Asset Register Has Become a Strategic System
Traditionally, IT Asset Management was often viewed as:
- administrative
- procurement-focused
- or primarily financial
That perspective is rapidly becoming outdated. Under DORA, the asset register is evolving into something much more important: a resilience intelligence layer.
A mature asset register now supports:
- operational resilience
- cyber response
- risk management
- regulatory reporting
- vendor oversight
- and executive decision-making
This changes the role of ITAM entirely. Instead of asking: “Do we know what we own?”; Organisations increasingly need to ask: “Can we make resilience decisions based on our asset data?”. That is a much higher standard.
The Real Challenge Is Data Trust
The future challenge is not collecting more data. Most organisations already have enormous amounts of IT data. The challenge is trust.
Can leadership trust:
- the ownership information
- the lifecycle status
- the criticality ratings
- the dependency mapping
- and the vendor relationships connected to those assets?
Because during operational disruption, uncertainty becomes risk. An inaccurate asset register slows:
- incident response
- vulnerability remediation
- impact assessment
- and regulatory communication
In fast-moving incidents, even small inaccuracies create cascading problems.
Why Automation Alone Will Not Solve This
Many organisations assume the answer is simply “more tooling.”. But automated discovery alone does not create governance maturity. Discovery tools can identify devices and services, but they often cannot reliably determine:
- business ownership,
- operational criticality,
- contractual dependencies,
- regulatory relevance,
- or lifecycle accountability.
Technology can collect information. Governance determines whether that information becomes reliable intelligence. This is why organisations now need closer alignment between:
- ITAM
- Security
- Risk
- Compliance
- Procurement
- and Service Management
DORA is forcing these disciplines to converge.
The Organisations That Will Mature Fastest
The organisations that will succeed under DORA are unlikely to be those with the largest compliance programmes. They will be the organisations that:
- continuously validate asset data
- integrate operational and governance processes
- establish accountability
- reduce data fragmentation
- and treat asset intelligence as a resilience capability rather than an administrative requirement
In practice, this means moving away from static annual audits and toward continuous operational validation. Because resilience is not a document. It is the ability to maintain control during uncertainty.
Final Thought
DORA may be remembered not only as a resilience regulation, but as the moment organisations realised how dependent they are on trustworthy asset intelligence. The uncomfortable truth is that many organisations still do not fully understand their own digital estate.
And in an environment where operational resilience must be demonstrated, not merely documented, that gap is becoming impossible to ignore. The question is no longer:
“Do you have an asset register?”.
The real question is: “Would you trust it during a crisis?”







