It is estimated that 150,000 European organisations are affected by the Network and Information Systems Directive (NIS2), approximately ten times more than with NIS1. With NIS2 only four months away and the January 2025 deadline for Digital Operational Resilience Act (DORA) compliance looming, organizations across various sectors are under increasing pressure to align with these EU regulatory requirements. The convergence of these frameworks presents challenges and opportunities for enhancing security resilience, but how can organizations strategically navigate this landscape to ensure compliance and build robust security measures?
NIS2 and DORA in a nutshell
NIS2 is the new European cybersecurity directive aimed at strengthening the security of network and information systems across the European Union. It builds on the original NIS Directive, expanding its scope and introducing stricter security requirements for 18 sectors. It is the most comprehensive EU cybersecurity legislation to date. With cyberattacks becoming more frequent and sophisticated, pressures to address multi-cloud IT environments and an increasingly complex regulatory landscape, it is clear why NIS1 is expanding to NIS2.
On the other hand, DORA is a sector-specific directive for financial institutions, targeting their approach to operational risk. It introduces rules for managing all aspects of operational resilience, particularly emphasising protection, detection, containment, recovery, and repair capabilities against ICT-related incidents.
DORA is a regulation, leaving no room for discretion at the member state level, while NIS2 is a directive that allows countries to develop rules based on their specific national needs.
The compliance challenge
The simultaneous implementation of NIS2 and DORA requires organizations to navigate a complex regulatory environment. Each framework has its own set of requirements, yet there is significant overlap, particularly in areas related to risk management, incident reporting, and resilience testing. The challenge lies in integrating these requirements into a cohesive strategy that not only ensures compliance but also enhances overall security resilience. How does one achieve this? Below are some thoughts on how to manage this via a unified compliance strategy.
Building a unified compliance strategy for NIS2 and DORA
Comprehensive risk assessment
Conduct a thorough risk assessment that covers the requirements of both NIS2 and DORA. This should include identifying critical assets, assessing potential threats, and evaluating the impact of various risk scenarios. A unified risk assessment approach helps in identifying common vulnerabilities and developing a streamlined mitigation strategy.
Integrated incident reporting
Both NIS2 and DORA mandate robust incident reporting mechanisms. Organizations should establish a unified incident response plan that meets the requirements of both frameworks. This includes setting up efficient communication channels, defining incident thresholds, and ensuring timely reporting to relevant authorities.
Cyber resilience testing
Regular testing of systems and processes is crucial for both NIS2 and DORA compliance. Organizations should develop a comprehensive testing schedule that includes penetration testing, red teaming, and business continuity exercises. By aligning testing procedures with the requirements of both frameworks, organizations can ensure a more resilient security posture.
Cross-framework governance
Establish a governance structure that oversees compliance with multiple frameworks. This could involve setting up a dedicated compliance team or integrating responsibilities into existing risk management functions. Clear governance helps in maintaining consistency, avoiding duplication of efforts, and ensuring accountability.
Training and awareness
Continuous training and awareness programmes are essential to keep staff informed about regulatory requirements and best practices. Regular training sessions and updates help foster a culture of compliance and security awareness across the organization.
Leveraging technology
Utilise technology solutions that facilitate compliance management. This includes tools for risk assessment, incident management, and resilience testing. Automated solutions can help streamline processes, reduce manual efforts, and ensure accurate reporting.
A critical boardroom issue
Both NIS2 and DORA place significant emphasis on the accountability of senior management. NIS2, in particular, requires member states to ensure that management bodies approve cybersecurity risk-management measures, oversee their implementation, and participate in specialised cybersecurity training. Managers may now be personally liable for infringements, making cybersecurity and resilience critical boardroom issues. The delegation of these tasks to third parties will likely be restricted, necessitating direct and active involvement from management bodies.
As the deadlines for NIS2 and DORA approach, organizations must take proactive steps to ensure compliance while building robust security resilience. By adopting a unified approach to risk management, incident reporting, resilience testing, governance, training, and technology, organisations can navigate the regulatory landscape effectively. The goal is not just to comply with these frameworks but to leverage them as catalysts for enhancing overall security posture and operational resilience.
By addressing the requirements of NIS2 and DORA in an integrated manner, organizations can turn compliance challenges into opportunities for strengthening their security framework and ensuring long-term resilience in an increasingly complex threat landscape.
The author
Simon Fisher is Senior Advisory Services Consultant at Orange Cyberdefense






