Article · published 13 September 2026
Both deal with cybersecurity, resilience, incidents and suppliers. The practical difference is who they cover, how detailed the obligations are and which authority supervises them.
Read the article →
Article · published 13 September 2026
Lex specialis is not a switch that turns NIS2 off. It resolves an overlap: where two valid rules govern the same entity and the same subject, the more specific rule displaces the general one only for that overlapping part.
Read the article →
Article · published 13 September 2026
DORA does not replace GDPR and is not lex specialis in relation to it. DORA focuses on the digital operational resilience of the financial entity; GDPR protects people and their personal data. When the same system, provider or incident engages both, both regimes must be assessed.
Read the article →
Article · published 13 September 2026
Threat-led penetration testing (TLPT) is DORA’s most advanced testing layer. It is not an annual penetration test, a vulnerability scan or a requirement for every financial entity.
Read the article →
Practical guide
Start with the legal entity, its actual activity and its enterprise data. Then check the exceptions and national law. A customer asking about NIS2 creates a reason to investigate, but does not establish direct legal scope. The useful result is a documented decision and a list of unresolved facts.
Read the article →
Practical guide
A policy describes the intended way of working. Evidence shows what happened within a defined scope and period. A useful DORA review connects the requirement, owner, control, record and corrective action. Begin with one important service and follow that chain before collecting documents across the organisation.
Read the article →
Practical guide
Treat each substantive answer as a claim needing an owner, scope and supporting record. A reusable evidence file prevents contradictory answers and repeated collection work. It also helps sales and technical teams distinguish what exists today from an improvement that has only been planned.
Read the article →
Practical guide
Collect a failed message and identify the service that sent it before changing settings. Delivery problems can involve authentication, reputation, mailing practices or the recipient’s filtering. A passing technical check is useful evidence, but cannot guarantee inbox placement. Diagnose one sending path at a time and preserve a baseline for comparison.
Read the article →
Practical guide
Define which tools may be used, what data may enter them and who checks the result before it affects a customer or business decision. Apply those rules to actual use cases. A short policy becomes useful when employees can recognise their task and know the approved way to complete it.
Read the article →
Practical guide
A completed backup job does not establish that a business service can be restored. Check whether the copies remain accessible after account compromise, whether the recovery environment is usable and whether dependencies are included. The decisive test is an agreed business operation completed safely with recoverable data.
Read the article →
Practical guide
Assess the path from a relevant attack scenario to a usable signal and an authorised response. A SIEM collects and analyses security events, but its presence does not establish coverage. Test what it can see, who investigates and what happens when the normal responder is unavailable.
Read the article →
Practical guide
Agree in advance who may investigate, contain and restore access, under which conditions and with what record. Monitoring permission and authority to interrupt a service are different decisions. A response plan becomes usable when a deputy can apply it without inventing the approval process during the incident.
Read the article →
Practical guide
A workaround is a signal to investigate both the behaviour and the work process. Ask what the employee was trying to complete, where the approved route failed and which risk the workaround created. Improve the route, explain the control and retain accountability. Repeating the policy alone rarely explains the obstacle.
Read the article →
Practical guide
Start with the business services you cannot afford to lose and the credible scenarios that threaten them. Compare proposed measures by the risk they address, their dependencies and the effort needed to operate them. A useful priority list explains the decision and gives each action an owner and a verification method.
Read the article →