Resources

Expert insights on NIS2, DORA, and third-party risk management for EU organisations.

NIS225 March 2026 · 12 min read

What Is NIS2? A Complete Guide for EU Organizations

The NIS2 Directive is the most significant EU cybersecurity regulation in a decade. Learn who it applies to, what it requires, and how to prepare — with a practical implementation timeline.

TPRM

Your Vendors All Depend on AWS: The Fourth-Party Concentration Risk Nobody Is Measuring

We scraped the GDPR subprocessor pages of 10 major SaaS vendors. Every single one depends on AWS. 90% use Google Cloud. 80% use Twilio for notifications. Here is what that means for your organisation.

16 April 2026|13 min read
TPRM

When 100 Million Weekly Downloads Get Weaponised: The Axios Attack and Your NIS2 Obligations

North Korea's Lazarus Group compromised the Axios npm package — present in 80% of cloud environments. If you are an EU entity under NIS2, here is exactly what you must do and by when.

15 April 2026|12 min read
NIS2

NIS2 Article 20: What Board Directors Must Do Now

NIS2 Article 20 introduces personal liability for board directors who fail to oversee cybersecurity. Fines up to EUR 10M and management bans are on the table. Here is what auditors will check.

13 April 2026|10 min read
AI in Compliance

How AI Cuts NIS2 Compliance Time by 80%

With 160,000+ entities now in scope, hiring compliance teams is not scalable. AI-driven automation can cut NIS2 evidence collection from weeks to hours — here is how the numbers work.

13 April 2026|9 min read
TPRM

NIS2 Supply Chain Security: The Art. 21(2)(d) Guide

Article 21(2)(d) makes supply chain security a legal obligation for 160,000+ EU entities. Third-party breaches cost USD 4.91M on average. This step-by-step guide covers classification, contracts, and monitoring.

13 April 2026|14 min read
DORA

DORA and NIS2: Double Compliance for Financial Firms

EU banks and insurers must comply with both DORA and NIS2. Deloitte found 46% cite return on investment as the biggest challenge. This guide maps the overlaps, gaps, and evidence reuse strategy.

13 April 2026|11 min read
NIS2

NIS2 in Italy: ACN Registration and Compliance Guide

Italy transposed NIS2 via D.lgs. 138/2024 with unique annual re-registration windows. ENISA data shows 26.3% of Italian public admin incidents go unreported. Here is your complete ACN compliance guide.

13 April 2026|11 min read
TPRM

You Are Not Regulated. You Are Still Exposed: Why Every Company Needs Vendor Risk Management

30% of breaches now involve third parties. 97% of organisations experienced a supply chain incident in 2025. You do not need NIS2 or DORA to need TPRM — you just need vendors. Here is the data-backed case for managing vendor risk before a regulation forces you to.

9 April 2026|14 min read
TPRM

When Your Security Scanner Turns Against You: Supply Chain Lessons from the Trivy Compromise

In March 2026, attackers compromised Trivy, Checkmarx KICS, and LiteLLM in a cascading supply chain campaign that hit 1,000+ enterprise environments. Here is what NIS2 entities can learn about vendor risk, fourth-party exposure, and incident response.

8 April 2026|11 min read
Industry News

NIS2 Enforcement Is Here: First Penalties, Supervisory Trends, and What Auditors Are Actually Checking

2026 marks the year NIS2 enforcement begins in earnest. With supervisory authorities ramping up inspections across Europe, here's what they're prioritizing and how to prepare for your first audit.

5 April 2026|7 min read
NIS2

NIS2 in Germany: BSI Registration, IT-Grundschutz, and Your 2026 Compliance Deadlines

Germany's NIS2 implementation (NIS2UmsuCG) brought ~29,500 companies into scope. BSI registration deadline was March 6, 2026. Here's what German organizations need to know about IT-Grundschutz alignment, KRITIS obligations, and upcoming audit requirements.

4 April 2026|10 min read
DORA

How to Build Your DORA Register of Information: A Step-by-Step Guide

The DORA Register of Information (RoI) is the most operationally demanding requirement for financial entities. This guide walks through the ESA template structure, country-specific submission deadlines, and common pitfalls.

2 April 2026|11 min read
Guides

NIS2 for SMEs: A Realistic Compliance Guide for Companies with 50-249 Employees

NIS2 brought tens of thousands of mid-sized companies into regulatory scope for the first time. This guide addresses SME-specific realities — limited budgets, no dedicated CISO, and the proportionality principle.

1 April 2026|9 min read
Guides

One Control Set, Three Regulations: How to Satisfy NIS2, DORA, and GDPR Without Tripling Your Work

NIS2, DORA, and GDPR overlap more than most organizations realize. This guide shows how to build a unified control framework that satisfies all three — covering incident reporting, risk management, and vendor security.

30 March 2026|14 min read
NIS2

NIS2 vs DORA: Key Differences for EU Organizations

Both NIS2 and DORA strengthen EU cybersecurity, but they serve different purposes. Understand which applies to you, where they overlap, and how to comply with both efficiently.

28 March 2026|8 min read
NIS2

What Is NIS2? A Complete Guide for EU Organizations

The NIS2 Directive is the most significant EU cybersecurity regulation in a decade. Learn who it applies to, what it requires, and how to prepare — with a practical implementation timeline.

25 March 2026|12 min read

Get NIS2 Insights Weekly

Stay ahead of EU compliance requirements. Practical guidance on NIS2, DORA, and third-party risk management delivered to your inbox.