Two years into NIS2 transposition and with DORA now part of day-to-day supervision for financial entities, the conversation in the boardroom has changed. It is no longer about whether an organisation is in scope — many more are than expected, often through the supply chain — but about whether they can demonstrate their controls, their incident reporting, and their oversight of critical suppliers.
Both regimes place accountability with senior management. A useful set of questions for your next board meeting:
- Do we have a current, owned risk assessment, and who signs it off?
- Can we meet the incident-reporting timelines, and have we ever rehearsed the notification?
- Do we hold register-level visibility of critical ICT third parties, including their concentration risk?
- Is there evidence — not just intent — of testing, training and management oversight?
The good news is that the underlying work maps neatly onto ISO 27001, the NIST Cybersecurity Framework and CIS Controls. Organisations with a healthy ISMS are usually closer to compliance than they think; the gap tends to be in evidence and in supplier oversight rather than in technology.
If a readiness gap-analysis against NIS2 or DORA would help focus your next budget cycle, that is exactly the kind of engagement we run.