Skip to main content

regulatory-update

  • DORA Compliance in 2026: What Financial Sector CISOs Must Have in Place Now

    DORA Compliance in 2026: What Financial Sector CISOs Must Have in Place Now

    The EU Digital Operational Resilience Act became applicable in January 2025 across financial services. Enforcement and supervisory scrutiny are intensifying in 2026. This briefing covers the obligations that matter most, the gaps regulators are finding, and how to prioritise.

    regulatory-update
  • NIS2 Directive: What CISOs Must Have in Place as EU Enforcement Intensifies

    NIS2 Directive: What CISOs Must Have in Place as EU Enforcement Intensifies

    The EU's NIS2 Directive has been national law across member states since October 2024. Enforcement is accelerating in 2026. This briefing covers the obligations CISOs must meet, the personal liability exposure for management, and how to prioritise if you are behind.

    regulatory-update
  • DORA ICT Third-Party Risk: What Financial Services CISOs Must Have in Place Before the First Supervisory Reviews

    DORA ICT Third-Party Risk: What Financial Services CISOs Must Have in Place Before the First Supervisory Reviews

    The Digital Operational Resilience Act's ICT third-party risk management requirements impose specific contractual, oversight, and incident reporting obligations on financial entities and their critical ICT providers. With DORA fully in effect and supervisors beginning substantive reviews, here's what CISOs need to have in place — and where the most common gaps are.

    regulatory-update
  • UK Cyber Security and Resilience Bill: What CISOs Need to Know Before It Becomes Law

    UK Cyber Security and Resilience Bill: What CISOs Need to Know Before It Becomes Law

    The UK Cyber Security and Resilience Bill will extend mandatory incident reporting to a wider set of organisations, expand the regulated sector scope beyond NIS, and introduce new board accountability obligations. With parliamentary progress accelerating in 2026, this briefing covers what the legislation requires, how it differs from NIS2, and what UK security leaders should be doing now.

    regulatory-update
  • NIS2 Personal Liability: What Boards and CISOs Must Understand Before October 2026

    NIS2 Personal Liability: What Boards and CISOs Must Understand Before October 2026

    NIS2 creates direct personal liability for management body members when cybersecurity failures occur at covered organisations. With enforcement ramping up in October 2026, here is what boards and CISOs need to know about their individual exposure, obligations, and how to document their oversight.

    regulatory-update
  • NIS2 Enforcement Is Underway: What Early EU Penalties Mean for Your Organisation

    NIS2 Enforcement Is Underway: What Early EU Penalties Mean for Your Organisation

    EU member states have begun issuing formal NIS2 enforcement actions. Germany has issued 47 formal notices, France has ordered remediation across energy and transport, and personal liability for senior executives is now active. What CISOs need to bring to the board.

    regulatory-update
  • CIRCIA Is Live: What the 72-Hour Reporting Rule Means for Your Organisation

    CIRCIA Is Live: What the 72-Hour Reporting Rule Means for Your Organisation

    The Cyber Incident Reporting for Critical Infrastructure Act final rule took effect in May 2026, establishing mandatory 72-hour incident reports and 24-hour ransomware payment disclosure for covered entities. Here's what CISOs need to have in place before an incident.

    regulatory-update
  • NIS2 Directive: The CISO's Compliance Roadmap by Sector

    NIS2 Directive: The CISO's Compliance Roadmap by Sector

    What CISOs must implement under the EU's NIS2 Directive -- sector-specific obligations, board accountability requirements, and the cost of non-compliance.

    regulatory-update