DORA Gives Risk Quantifiers a Decay Curve

DORA’s fixed control cadences are not just compliance dates. In a quantitative risk model, they are regulatory evidence about how quickly Resistance Strength decays.

The control is not static

Most risk registers get vulnerability management wrong by treating “we have patching” as a binary control statement. That may satisfy a control inventory, but it is a weak input for quantitative cyber risk. In quantitative risk terms, Vulnerability is P(TCap > RS). Threat Capability is not waiting politely for the next governance cycle, and Resistance Strength is not a permanent attribute once a policy exists.

This is why Dark Reading’s 24 August 2026 article, “The Vulnerability Gap: Why Discovery Is Outrunning Repair,” matters for risk quantification. Its core observation is that AI-assisted vulnerability discovery is finding flaws faster than organizations can remediate them, under a tightening regulatory landscape. Translated into quantitative risk language, TCap is rising while RS refresh cadence often stays fixed, so the probability that TCap exceeds RS widens from both ends. That makes control cadence a modeling variable, not an audit footnote.

DORA’s rare numbers

DORA, EU Regulation 2022/2554, was adopted on 14 December 2022 and applies from 17 January 2025. Its ICT risk management technical standard, Commission Delegated Regulation (EU) 2024/1774, was adopted on 13 March 2024 and published in the Official Journal on 25 June 2024. It functions as the DORA cluster’s master controls catalogue across encryption, asset management, operations security, vulnerability and patch management, data and network security, logging, and physical security.

Most of DORA and its technical standards leave frequency to the entity’s own risk assessment. That is why the hard numeric cadences in the ICT risk management standard are so important. For ICT assets supporting critical or important functions, automated vulnerability scanning must occur at least weekly under Article 10(2)(b). Firewall-rule and connection-filter reviews must occur at least every 6 months under Article 13. Access-rights reviews must occur at least annually for ordinary systems and at least every 6 months for critical or important ones under Article 21(e)(iv).

These are not generic good-practice slogans. They are regulator-set maintenance intervals attached to specific control classes. A regulator sets a fixed maintenance cadence only when it believes the control’s effectiveness decays on that timescale. That is the part many risk models miss. In a quantitative risk model, Resistance Strength is the aggregate effect of every control between a threat actor and a loss event. It is not a static checklist score, and it degrades between control refreshes. If the standard says a critical asset needs weekly automated vulnerability scanning, the useful inference is not merely “weekly scanning is compliant.” The stronger inference is that a longer scan interval should be modeled as weaker and more uncertain Resistance Strength.

Put the cadence into the distribution

Consider two otherwise similar critical assets. One is scanned weekly. The other is scanned monthly. A qualitative register may mark both as having vulnerability management. A control maturity assessment may put them in adjacent bands. A quantitative risk model should do something stricter.

The monthly-scanned asset should carry a lower median RS and a wider RS distribution than the weekly-scanned peer. Not because monthly scanning is automatically negligent in every context, but because the control has more time to decay between refreshes while discovery velocity is accelerating. The Dark Reading development makes that assumption load-bearing. If AI-assisted discovery is increasing the rate at which exploitable weaknesses are found, then stale visibility becomes a larger part of the loss-event pathway.

This is the practical modeling move: treat DORA’s fixed cadence as a floor written before discovery accelerated, not as a target. Weekly scanning for critical or important assets is the regulatory minimum in the standard. If the threat environment has shifted toward faster discovery, then a model that treats weekly and monthly scanning as equivalent has smuggled in an optimistic assumption.

The same logic applies to firewall-rule and connection-filter reviews. Article 13’s at-least-every-6-months cadence is evidence that rulebase accuracy, exposure discipline, and connection filtering should not be assumed stable indefinitely. Between reviews, exceptions accumulate, business changes alter traffic assumptions, and legacy connectivity becomes harder to justify. The model does not need a fabricated precision value. It needs a defensible direction: as review cadence stretches beyond the regulatory floor, RS should decline and uncertainty should increase.

Access-rights reviews follow the same pattern. Article 21(e)(iv) distinguishes ordinary systems from critical or important ones, with annual review for the former and every 6 months for the latter. That distinction is useful because it ties cadence to function criticality. The higher the business consequence of compromise, the less tolerance the standard shows for stale entitlement assumptions. In quantitative risk terms, stale access rights can reduce the aggregate Resistance Strength between a threat actor and a loss event, especially where excessive privilege changes the effort required to move from initial access to material impact.

From compliance calendar to risk input

DORA also shows that regulators are willing to set explicit numbers where they believe the tolerance should be narrow. For central counterparties and trading venues, Article 24 sets a maximum recovery time of close to, not longer than, 2 hours for critical functions, and near-zero data loss after a disruptive incident. That is not a vague “commensurate to risk” formulation. It is a regulator-set number for resilience outcomes.

Article 26(2) then enumerates a severe but plausible scenario list: cyberattacks, third-party provider insolvency, physical-site failure, staff unavailability, climate or natural-disaster events, insider attacks, political instability, and widespread power outages. This matters because the standard is not only asking whether controls exist. It is asking whether the organization can reason through adverse scenarios where those controls are stressed, delayed, bypassed, or degraded.

A useful quantitative model connects these pieces. The scenario defines the stress. TCap represents the capability applied against the asset or process. RS represents the aggregate control strength at the time of the event, including decay since the last refresh. DORA’s fixed cadences give the analyst and the organization’s control owners a defensible anchor for that decay assumption.

The conclusion is uncomfortable but useful: a control can be present and still be too stale to deserve full credit. “We have patching” is not a stable quantitative-risk input. “Critical assets are scanned at least weekly, findings are triaged through the vulnerability process, and the modeled RS distribution reflects that refresh interval” is closer to the standard of evidence quantitative risk work needs. The recent acceleration in vulnerability discovery makes this more urgent. If discovery is outrunning repair, then the gap between control existence and control freshness becomes financially relevant. DORA has already supplied rare hard cadences for several controls. Risk models should stop leaving those numbers in the compliance calendar and start using them where they belong, inside the Resistance Strength distribution.