
NIS2 and DORA moved cyber and operational resilience from good practice to legal obligation, with management bodies personally accountable. Both regulations ask for the same underlying capability: know your critical services, manage your risks, control your third parties, be able to respond, and be able to prove it.
I translate the regulatory text into a plan your teams can execute, reusing the ISO 27001 and ISO 22301 work you may already have in place instead of starting again.
How we get you ready
- Applicability and scoping review: whether NIS2, DORA or both apply, and to which entities and services
- Gap analysis against the regulatory requirements and the relevant ISO 27001 / ISO 22301 controls
- Governance and accountability: management body oversight, roles, reporting lines and evidence trail
- Incident detection, handling and the strict regulatory notification timelines, tested through exercises
- ICT third-party and supply chain risk management, including register of information and contractual clauses
- A prioritised, costed remediation roadmap with owners and realistic deadlines
Grounded in hands-on work with NIS2, DORA, NIST, COBIT, ISO 27001, ISO 22301, GDPR and Cyber Essentials Plus across regulated and international organisations.