Breaking
December 3, 2024

NIS2 & DORA: Staying ahead of the curve | usagoldmines.com

With less than a month away before the updated landmark Network and Information Security (NIS2) Directive deadline, organizations across the EU are preparing for the new regulation to come into full force on the 17th October. However, it doesn’t stop there. On the 17th January 2025, the new Digital Operational Resilience Act (DORA) will also come into effect for financial organizations and the sector’s third-party IT suppliers.

Organizations across the EU, and those based elsewhere that do business with the region’s entities, are facing increasing pressure to align with these regulatory requirements. The convergence of these frameworks looks to impact over 170,000 European organizations in total — with 150,000 organizations affected by the NIS2 and estimates suggesting over 22,000 financial entities and ICT service providers impacted by DORA.

What are NIS2 and DORA?

NIS2 aims to provide comprehensive EU-wide legislation on cybersecurity. It expands the scope of the NIS Directive and introduces stricter security requirements for 18 sectors of business. Similar to the General Data Protection Regulation (GDPR), NIS2 will work to bridge cybersecurity measures and approaches across organizations to help fortify European digital infrastructure.

DORA is a sector-specific directive for financial institutions, targeting their approach to operational risk. DORA has two clear objectives. Firstly, to tighten IT risk management across the financial services sector. Secondly, to harmonize current IT risk management regulations already in existence across EU member states.

DORA leaves no room for discretion at the member state level, while NIS2 is a directive that allows countries to develop rules based on their specific national needs.

Compliance strategies for NIS2 and DORA

While it might seem a lot to put on businesses that are already struggling in a rocky economic situation, regulations such as these are brought about in response to the growing threat landscape, and implementing the changes required will bring new opportunities to enhance cyber resilience and overall security posture. To take advantage of these opportunities and stay ahead of the incoming regulations, below are nine compliance strategies organizations must adopt:

Comprehensive risk assessment: Organizations should conduct a thorough risk assessment that covers the requirements of both NIS2 and DORA. This should include identifying critical assets, assessing potential threats, and evaluating the impact of various risk scenarios. A unified risk assessment approach helps in identifying common vulnerabilities and developing a streamlined mitigation strategy.

Education and training: Due to limited resources, organizations often find themselves particularly vulnerable to cyber threats. But even when resources are limited, businesses can implement continuous training and awareness sessions, as well as create and implement well-defined security measures. With this regular training, organizations can foster the necessary culture for compliance and security awareness.

Adopting a shared responsibility model: In recent years, cybercriminals have advanced their tactics, putting businesses under immense pressure to act quickly. A way to address these concerns is to adopt a shared responsibility model to ensure security policies and practices are up to date and applied evenly across organisations – leaving no stone unturned. An active compliance strategy starts with clearly defined roles, responsibilities and objectives documented within corporate policy, in line with the NIS2 and DORA directives.

Integrated incident reporting: Organizations need to put in place a coherent, unified incident response plan to meet the requirements of both NIS2 and DORA, given they both mandate incident reporting mechanisms. This includes streamlining communication channels effectively, transparent communications with consumers and ensuring timely reporting to relevant authorities.

Making cybersecurity a core value: Security leaders must work hard to demystify cybersecurity and demonstrate how a few behavioral changes can protect the whole organization in line with NIS2 and DORA. It is the responsibility of senior leadership teams to embed security and privacy across data-related initiatives from the start.

Cross-framework governance: Firms must consider creating dedicated compliance teams or integrating responsibilities into existing risk management functions to oversee compliance in accordance with multiple frameworks. In creating a clear governance structure, organizations can maintain consistency – avoiding duplication of efforts and ensuring accountability.

Cyber resilience testing: There is no compliance without regular testing of systems and processes. Organisations must develop a comprehensive testing schedule that includes penetration testing, red teaming and business continuity exercises to meet the requirements of both NIS2 and DORA. Organizations must align their testing procedures with the frameworks’ requirements to ensure a more resilient security posture.

Leveraging technology: To facilitate compliance management, firms must utilize and imbed technological solutions into their overall security strategy. This includes data-led solutions for risk assessment, incident management and resilience testing. To ensure more accurate reporting, automated solutions must be considered to help streamline processes and reduce manual efforts.

Developing trust and transparency: For trust to exist, organizations must, in line with NIS2 and DORA, share how the business handles data and personal information including how it is secured. Providing this information will go a long way in empowering wider cybersecurity initiatives. A robust security response extends far beyond data protection, it encompasses regulators, employees, consumers and more. Therefore, ongoing compliance can mean the difference between a necessary evil and a trusted partner.

Turning compliance challenges into opportunities

As the deadlines for NIS2 and DORA approach, adopting a unified approach to risk management, incident reporting, resilience testing, technology and more, can help organizations navigate the regulatory landscape effectively. The goal is not just to comply with these frameworks but to leverage them as catalysts for enhancing overall security posture and operational resilience.

We’ve listed the best network monitoring tools.

This article was produced as part of TechRadarPro’s Expert Insights channel where we feature the best and brightest minds in the technology industry today. The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/news/submit-your-story-to-techradar-pro

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Missed Cyber Monday? Get 45% off this hot OLED monitor anyway | usagoldmines.com
Apple just pushed a key smart home feature into 2025 | usagoldmines.com
Your Apple Music Replay 2024 Is Live Jake Peterson | usagoldmines.com
The rumored foldable iPhone could save a stagnant folding phone market, according to a new report ja...
Russian censorship is getting tougher – and Tor needs your help chiara.castro@futurenet.com (Chiara ...
3 new Paramount Plus movies with over 94% on Rotten Tomatoes that you won't want to miss in December...
Corrupted Microsoft Word files used to launch phishing attacks | usagoldmines.com
Nintendo Switch Online will get the NES version of Tetris next week | usagoldmines.com
US plan to protect consumers from data brokers faces dim future under Trump Jon Brodkin | usagoldmin...
The Raspberry Pi 5 now works as a smaller, faster kind of Steam Link Kevin Purdy | usagoldmines.com
A new ‘File Search’ feature is coming to the Windows 11 taskbar | usagoldmines.com
Google smart speakers are starting to sound like Gemini | usagoldmines.com
NZXT accused of ‘predatory scam’ gaming PC rental program | usagoldmines.com
How to solve RAM problems with Windows memory diagnostics | usagoldmines.com
8BitDo’s new extra-green Xbox keyboard gives me 2001 vibes | usagoldmines.com
iPhone SE Now Over 1,000 Days Old as New Model Edges Closer Hartley Charlton | usagoldmines.com
Samsung Cyber Week Sale Has Year's Best Prices on Monitors, TVs, Fridges, and More Mitchel Broussard...
MOVEit breach chaos continues, data on hundreds of thousands leaked from Nokia, Morgan Stanley | us...
Google’s AI podcast creator NotebookLM could be coming to the Gemini app on your phone | usagoldmin...
Cheerios effect inspires novel robot design Jennifer Ouellette | usagoldmines.com
China hits US with ban on critical minerals used in tech manufacturing Ashley Belanger | usagoldmine...
The makers of Arc show off new AI-driven ‘smart browser’ called Dia | usagoldmines.com
Watch Intel talk about Arc Battlemage GPUs on The Full Nerd today! | usagoldmines.com
This Smartwatch and Fitness Tracker for Kids Is 22% Off Right Now Pradershika Sharma | usagoldmines....
Creature Commandos is full of social outcasts and grieving misfits, but the voice actor for Rick Fla...
Code written by OpenAI and praised by GitHub may not be as good as Github says | usagoldmines.com
How businesses can break barriers to entry in integrating AI into operations | usagoldmines.com
Lessons in cybersecurity from the Internet Archive Breaches | usagoldmines.com
Javascript files loaded with RATs hits thousands of victims | usagoldmines.com
New website shows you how much Google AI can learn from your photos Paresh Dave, wired.com | usagold...
Fix your spotty home Wi-Fi signal with this simple $27 gadget | usagoldmines.com
Intel’s $249 Arc B580 is the GPU we’ve begged for since the pandemic | usagoldmines.com
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com
The 4TB Samsung 990 Pro SSD with heatsink just dropped to 40% off | usagoldmines.com
Samsung’s 49-inch 240Hz ultrawide monitor is cheaper now than it was on Black Friday | usagoldmines...
How to Connect Windows or macOS to Your Roku David Nield | usagoldmines.com
Apple Podcasts Reveals 2024 Show of the Year Joe Rossignol | usagoldmines.com
Microsoft plans to make searching in Windows 11 better - I just hope it doesn't screw it up | usago...
Indiana Jones and the Great Circle's official launch trailer showcases new gameplay ahead of release...
Intel announces its new Battlemage graphics cards, and they might just be the 1440p budget champions...
Microsoft’s claim that Arm-based Copilot+ PCs are “fastest, most intelligent Windows PCs” is debunke...
Everything new on Paramount Plus in December 2024 | usagoldmines.com
Linux devices are being hit by LogoFAIL vulnerability, Bootkitty installed | usagoldmines.com
Stop Live Activities Taking Over Your Apple Watch Face Tim Hardwick | usagoldmines.com
Apple Fails to Block $995M UK App Store Commission Lawsuit Tim Hardwick | usagoldmines.com
Apple Raises Indonesia Investment Offer to $1B Amid iPhone Ban Tim Hardwick | usagoldmines.com
3 new movies on Max with over 90% on Rotten Tomatoes | usagoldmines.com
Insta360 Flow 2 Pro spotted on sale, even though the iPhone gimbal hasn’t launched yet | usagoldmin...
AI reckons it can do all jobs, even those thought previously 'safe' | usagoldmines.com
Two decades after Enron’s bankruptcy, the company is back as a crypto firm? Eric Berger | usagoldmin...
Dell G15 review: A ‘retro’ laptop that’s all about performance | usagoldmines.com
Windows Copilot+ PCs aren’t there yet: 8 must-change upgrades for 2025 | usagoldmines.com
Jaguar's striking Type 00 concept is a bold statement of intent, but it needs more to restore its pa...
The iPhone 17 Pro and Pro Max could get a display upgrade and avoid a frame downgrade | usagoldmine...
AI impact is only minor in many workplaces, employees believe | usagoldmines.com
Apple Music Replay beats Spotify Wrapped to the recap punch – here's how to get it | usagoldmines.c...
Got an older iPhone? WhatsApp won’t work on it for much longer alexblake.techradar@gmail.com (Alex B...
AMD RX 8800 XT could match RTX 4080’s performance – and easily outgun Nvidia’s GPU for ray tracing ...
PC Gaming Show: Most Wanted 2024 airs this week, here's how to watch it | usagoldmines.com
Raw milk producer optimistic after being shut down for bird flu detection Beth Mole | usagoldmines.c...
Apple Music Replay 2024 Experience Now Live Tim Hardwick | usagoldmines.com
Yes, Star Wars: Skeleton Crew's starship has a name – and its co-creator says 'there is a story mean...
UK is being hit by more cyberattacks than ever before, NCSC warns | usagoldmines.com
Sony announces its PlayStation 30th Anniversary sale, offering discounts on hundreds of games | usa...
Samsung's Galaxy S25 launch event might include its long-awaited smart glasses reveal hamish.hector@...
The next Samsung Galaxy Watch could feature a more secure, adjustable strap stephen.warwick@futurene...
Google just made it easier to move all your photos from iPhone to Android | usagoldmines.com
The Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7 could be even bigger than their predecessors | usag...
PS5 is getting classic themes and boot sequences for PlayStation's 30th anniversary, but only for a ...
Pat Gelsinger retires as CEO of Intel after poor company performance | usagoldmines.com
Have your say: how was your Black Friday shopping experience? marc.mclaren@futurenet.com (Marc McLar...
The OnePlus 13 is officially going global in January | usagoldmines.com
Your new favorite app is on sale for Cyber Week | usagoldmines.com
Apple Vision Pro Launching in Taiwan on December 17 Eric Slivka | usagoldmines.com
Star Wars: Skeleton Crew is a thrilling galactic misadventure that reminds Star Wars that it's still...
The winner of Cyber Monday is this Hulu and Disney Plus bundle for just $2.99 a month, and it's endi...
Can desalination quench agriculture’s thirst? Lela Nargi, Knowable Magazine | usagoldmines.com
Apple's 2026 Foldable iPhone Could Reinvigorate Stalling Market Juli Clover | usagoldmines.com
This AI app claims it can calculate the day you'll die erichs211@gmail.com (Eric Hal Schwartz) | usa...
NYT Strands today — hints, answers and spangram for Tuesday, December 3 (game #275) marc.mclaren@fut...
Quordle today – hints and answers for Tuesday, December 3 (game #1044) marc.mclaren@futurenet.com (M...
NYT Connections today — hints and answers for Tuesday, December 3 (game #541) marc.mclaren@futurenet...
Elon Musk loses bid to reinstate massive Tesla pay plan, now worth $101B Jon Brodkin | usagoldmines....
Paid Version of Animal Crossing: Pocket Camp Now Available Juli Clover | usagoldmines.com
Apple Sued for 'All-Seeing Eye' Employee Device Monitoring Policy Juli Clover | usagoldmines.com
Build a 1080p gaming PC for $585 with these Cyber Monday deals | usagoldmines.com
Over 500 PlayStation Games Are Now on Sale Jake Peterson | usagoldmines.com
How to Choose Between the Ring or Blink Video Doorbell Amanda Blum | usagoldmines.com
The Best Gaming Headphones Are Over Half Off for Cyber Monday Mark Knapp | usagoldmines.com
The Oura Ring Is at Its Lowest Price Yet for Cyber Monday Beth Skwarecki | usagoldmines.com
Certain names make ChatGPT grind to a halt, and we know why Benj Edwards | usagoldmines.com
The Baddest, Loudest Party Speaker I’ve Reviewed Is $250 Off for Cyber Monday Daniel Oropeza | usago...
Beats Debuts (PRODUCT)RED Solo 4 Headphones, But You Won't Be Able to Buy Them Eric Slivka | usagold...
AI characters find religion in Minecraft erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines.com
Ryan Gosling's $20 Casio watch is now even cheaper at Amazon (yes, really) axel.metz@futurenet.com (...
Researchers finally identify the ocean’s “mystery mollusk” Elizabeth Rayne | usagoldmines.com
3 things I always buy on Cyber Monday | usagoldmines.com
Five Ways to Maximize Your Travel Loyalty Benefits Before the End of the Year Emily Long | usagoldmi...
Coinbase Onramp Now Supports Buying Crypto With Apple Pay Juli Clover | usagoldmines.com
Elon Musk asks court to block OpenAI conversion from nonprofit to for-profit Jon Brodkin | usagoldmi...

Leave a Reply