{"id":4392,"date":"2026-04-10T14:46:35","date_gmt":"2026-04-10T12:46:35","guid":{"rendered":"https:\/\/www.cybreg.cz\/why-excel-is-not-enough-dora-requires-real-software\/"},"modified":"2026-04-17T22:40:33","modified_gmt":"2026-04-17T20:40:33","slug":"why-excel-is-not-enough-dora-requires-real-software","status":"publish","type":"post","link":"https:\/\/www.cybreg.cz\/en\/why-excel-is-not-enough-dora-requires-real-software\/","title":{"rendered":"Why Excel is not enough: DORA requires real software"},"content":{"rendered":"\n<p>The <strong>Digital Operational Resilience Act (DORA)<\/strong> is fundamentally changing the approach to <strong>ICT risk<\/strong> management and <strong>cyber security<\/strong>. Whereas previously a&nbsp;combination of documents, spreadsheets and one-off audits could suffice, today <strong>a continuous, managed and demonstrable system<\/strong> is expected. <\/p>\n\n<p>It is in this context that <strong>Excel<\/strong>, as widespread and practical as it is, is no longer enough.<\/p>\n\n<p>Excel is often the first step. It&#8217;s&nbsp;fast, accessible and most people know how to use it. For basic <strong>asset<\/strong> records or a&nbsp;simple <strong>risk<\/strong> list, it can work. The problem arises when an organization starts to meet the actual requirements of DORA. These are not based on a&nbsp;one-off spreadsheet, but on a&nbsp;<strong>long-term sustainable process<\/strong>. <strong>DORA compliance<\/strong> is not a&nbsp;project that is completed once. It is a&nbsp;<strong>living mechanism<\/strong> that <strong>is constantly<\/strong> adapting to changes in the IT environment, organizational structure and current threats.     <\/p>\n\n<p>In such an environment, the limitations of Excel quickly become apparent. Data becomes outdated, individual files diverge and no one is sure which version is correct. There is no <strong>single source of truth<\/strong>. As soon as one asset, process or risk changes, that change needs to be reflected in multiple places, which often does not happen in practice.   <\/p>\n\n<p>This is where <strong>specialized software<\/strong> like <strong>cybreg<\/strong> starts to make sense. It&#8217;s&nbsp;not just about record keeping, it&#8217;s&nbsp;about <strong>management<\/strong>. Find out more about the approach here: <a href=\"https:\/\/www.cybreg.cz\/en\/dora\/\">cybreg.dora<\/a>  <\/p>\n\n<h2 class=\"wp-block-heading\">From registration to management<\/h2>\n\n<p>One of the typical problems in Excel is that the organization doesn&#8217;t really know exactly what to protect. <strong>Assets, processes and their links<\/strong> exist, but they are not systematically linked. In cyberreg, these relationships are modelled directly in the system. Each asset has an owner, a&nbsp;value and a&nbsp;link to specific processes. This makes it possible to immediately see which parts of the organization are <strong>critical<\/strong> and what the impact of their failure would be.   <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"859\" height=\"530\" data-id=\"4306\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/asset.jpg\" alt=\"\" class=\"wp-image-4306\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/asset.jpg 859w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/asset-300x185.jpg 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/asset-768x474.jpg 768w\" sizes=\"(max-width: 859px) 100vw, 859px\" \/><\/figure>\n<\/figure>\n\n<p><\/p>\n\n<p>Another typical scenario is working with risks. In Excel, risks are often recorded in isolation and their evaluation is manual. As soon as, for example, the value of an asset or the probability of a&nbsp;threat changes, everything needs to be recalculated. In cybreg, <strong>risks<\/strong> are <strong>linked to assets and processes<\/strong> and the system automatically calculates their resulting level based on <strong>impact and probability<\/strong>.   <\/p>\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"863\" height=\"530\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/risk.jpg\" alt=\"\" class=\"wp-image-4299\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/risk.jpg 863w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/risk-300x184.jpg 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/risk-768x472.jpg 768w\" sizes=\"(max-width: 863px) 100vw, 863px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">Proof instead of chaos<\/h2>\n\n<p>Another big difference from Excel is the work with evidence and auditing. Tables often lack a&nbsp;clear history of changes and traceability. When auditing, information is then difficult to track down in emails or older versions of files. Cybreg, on the other hand, keeps a&nbsp;complete <strong>audit trail<\/strong>, including <strong>document versioning<\/strong>, change measures and accountabilities. Every change is traceable and <strong>demonstrable<\/strong>.    <\/p>\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"543\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35-1024x543.jpg\" alt=\"DORA evidence\" class=\"wp-image-4310\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35-1024x543.jpg 1024w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35-300x159.jpg 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35-768x407.jpg 768w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35-1536x815.jpg 1536w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-15.54.35.jpg 1976w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">One reality instead of multiple Excel<\/h2>\n\n<p>At the same time, in practice, organisations do not address just one regulation. <strong>DORA<\/strong> often overlaps with <strong>NIS2<\/strong>, <strong>ISO 27001<\/strong> or <strong>GDPR<\/strong>. In Excel, this means duplication and constant overwriting of data. Cybreg allows you to record one <strong>measure<\/strong> and map it to multiple <strong>regulatory frameworks<\/strong> at the same time. This significantly reduces the <strong>administrative burden<\/strong> and increases <strong>data consistency<\/strong>.   <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"902\" height=\"553\" data-id=\"4313\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/ramce.jpg\" alt=\"\" class=\"wp-image-4313\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/ramce.jpg 902w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/ramce-300x184.jpg 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/ramce-768x471.jpg 768w\" sizes=\"(max-width: 902px) 100vw, 902px\" \/><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\">Driving instead of tracking<\/h2>\n\n<p>Another major difference is seen in areas where active management, not just record keeping, is needed.<\/p>\n\n<p>A typical example is <strong>supplier management<\/strong>. DORA places great emphasis on <strong>third parties<\/strong> and their risks. Cybreg connects suppliers to assets and processes and allows to identify, for example, <strong>concentration risk<\/strong> when multiple critical areas depend on one supplier.  <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"589\" data-id=\"4325\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-16.14.38-1024x589.png\" alt=\"\" class=\"wp-image-4325\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-16.14.38-1024x589.png 1024w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-16.14.38-300x173.png 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-16.14.38-768x442.png 768w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-at-16.14.38.png 1323w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/figure>\n\n<p><strong>Incident management<\/strong> works in a&nbsp;similar way. Instead of static spreadsheet records, it offers cybreg management of the entire process, including statuses, responsibilities and asset relationships. <\/p>\n\n<h2 class=\"wp-block-heading\">Real-time overview<\/h2>\n\n<p>DORA requires the ability to provide evidence of current status at any time. Not just the detail, but the big picture. <\/p>\n\n<p>Cybreg offers <strong>dashboards and reports<\/strong> that show the status of risks, the implementation of measures or the level of compliance in real time. In addition, reports can be generated in formats required by the regulator, for example for the <strong>CNB<\/strong>. <\/p>\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"932\" height=\"488\" src=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/dashboard.jpg\" alt=\"\" class=\"wp-image-4319\" srcset=\"https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/dashboard.jpg 932w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/dashboard-300x157.jpg 300w, https:\/\/www.cybreg.cz\/wp-content\/uploads\/2026\/04\/dashboard-768x402.jpg 768w\" sizes=\"(max-width: 932px) 100vw, 932px\" \/><\/figure>\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n<p>Although DORA does not prescribe a&nbsp;specific technology, it clearly shows that <strong>tables are not enough<\/strong>. Organizations need a&nbsp;<strong>system<\/strong> that connects data, enables <strong>collaboration<\/strong>, provides <strong>traceability<\/strong>, and can respond to changes in real time. <\/p>\n\n<p>Excel remains a&nbsp;good starting point. However, once an organisation moves towards the actual implementation of DORA, it becomes more of <strong>a hindrance than a&nbsp;solution<\/strong>. <\/p>\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Digital Operational Resilience Act (DORA) is fundamentally changing the approach to ICT risk management and cyber security. Whereas previously a&nbsp;combination of documents, spreadsheets and one-off audits could suffice, today a&nbsp;continuous, managed and demonstrable system is expected. It is in this context that Excel, as widespread and practical as it is, is no longer [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":4320,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[55],"tags":[66],"class_list":["post-4392","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-homepage"],"_links":{"self":[{"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/posts\/4392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/comments?post=4392"}],"version-history":[{"count":1,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/posts\/4392\/revisions"}],"predecessor-version":[{"id":4393,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/posts\/4392\/revisions\/4393"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/media\/4320"}],"wp:attachment":[{"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/media?parent=4392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/categories?post=4392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybreg.cz\/en\/wp-json\/wp\/v2\/tags?post=4392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}