← Solutions
CyberTrending

NIS2, DORA and cyber regulation readiness

Work out which cyber regulations apply to you — NIS2, DORA, the UK’s incoming cyber resilience law, UAE rules — and close the gaps with evidence.

Typical timing
8–12 weeks
Engagement
Fixed scope
Delivery framework
User researchDiscoveryAlphaBetaLive

Cyber regulation has widened sharply: NIS2 across the EU, DORA for financial entities and their ICT providers, the UK’s Cyber Security and Resilience Bill, and Gulf frameworks. This package establishes which obligations apply, where you fall short, and delivers the controls and evidence to comply.

  • You operate in or sell to the EU in an essential or important sector
  • Financial services customers are passing DORA requirements down to you
  • Leadership needs to understand personal accountability for cyber risk
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 02 · Discovery2–3 weeks

    Applicability and gap analysis

    • Regulations and entity classification confirmed
    • Controls assessed against each obligation
    • Gaps rated and costed
  2. 03 · Alpha4–8 weeks

    Remediate

    • Governance, risk management and reporting processes
    • Supply-chain and ICT third-party risk controls
    • Incident reporting procedures aligned to deadlines
  3. 04 · Beta1–2 weeks

    Evidence

    • Evidence pack assembled
    • Management body briefing and training
    • Readiness assessment against the obligations

Deliverables

What you keep at the end.

  • Regulatory applicability assessment
  • Gap analysis and remediation plan
  • Updated policies, processes and registers
  • Compliance evidence pack
  • Board and management training

Outcomes

What it is built to change.

  • Clarity on what applies and what does not
  • Reduced regulatory and contractual exposure
  • Leadership able to discharge its accountability