
NIS2, Decoded: Scope, Obligations, and Personal Liability
TL;DR: NIS2 comes down to three questions. Are you in scope - and if so, are you an "essential" or an "important" entity? What does it require - chiefly the Article 21 risk-manage…
Compliance strategy and regulatory guidance written by practitioners
Articles
Regulatory guidance and compliance strategy from those doing the work
An Irish energy operator, water utility or transport network sits in an odd position right now. The cybersecurity obligations it will be held to are effectively settled, its regul…

TL;DR: NIS2 comes down to three questions. Are you in scope - and if so, are you an "essential" or an "important" entity? What does it require - chiefly the Article 21 risk-manage…

firm doing its third-party risk properly might feel reassured by variety. It uses dozen different AI-enabled tools from dozen different vendors - no single supplier it depends on…

You signed contract with vendor. You did your due diligence on that vendor. What you did not sign, and could not do diligence on, is the contract between your vendor and the compa…

Two vendors cost the same, and one of them can bring the firm down. Telling them apart is not question of price or size - but price and size are how most firms sort their vendors,…
).jpeg)
When supervisor opens review, the document they are most likely to ask for by name is also the one most likely to be incomplete in way that is easy to prove: the register of every…

Procurement due diligence was built to assess stable thing. Is the vendor financially sound, is the software secure, does the contract protect us, where does the data sit. Answer…

The vendors most likely to cause problem are not the ones you are onboarding. They are the ones you cleared eighteen months ago, filed, and have not looked at since. Onboarding ge…

TL;DR: Your third-party risk programme was built for world where vendor was stable, known quantity you assessed once year. That world is gone. Every vendor is quietly becoming an…
Find answers to common questions about our content and updates
Monthly updates on regulatory changes, compliance trends, and platform releases
By subscribing you agree to our Terms and Conditions and Privacy Policy
