Article · published 13 September 2026
Both deal with cybersecurity, resilience, incidents and suppliers. The practical difference is who they cover, how detailed the obligations are and which authority supervises them.
Read the article →
Article · published 13 September 2026
Lex specialis is not a switch that turns NIS2 off. It resolves an overlap: where two valid rules govern the same entity and the same subject, the more specific rule displaces the general one only for that overlapping part.
Read the article →
Article · published 13 September 2026
DORA does not replace GDPR and is not lex specialis in relation to it. DORA focuses on the digital operational resilience of the financial entity; GDPR protects people and their personal data. When the same system, provider or incident engages both, both regimes must be assessed.
Read the article →
Article · published 13 September 2026
Threat-led penetration testing (TLPT) is DORA’s most advanced testing layer. It is not an annual penetration test, a vulnerability scan or a requirement for every financial entity.
Read the article →