ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Advancing compliance maturity in an age of DORA & NIS2

On 24 July 2025, Teiss Talk host Thom Langford, was joined by Satyam Rastogi, Director of Information Security & DevOps, BAMKO; Mike Johnson, Global Cyber Threat & Incident Response Manager, Verifone; and Madison Dreshner, Principal of IT Risk and Compliance solutions, AuditBoard.


Views on news


Meta says it won’t sign the European Union’s artificial intelligence code of practice agreement, warning that “Europe is heading down the wrong path on AI.” The code published by the EU on July 10th is a voluntary set of guidelines to help companies follow the AI Act’s rules around general-purpose AI before they come into effect in a few weeks. This comes ahead of AI Act rules coming into force on August 2nd that require general-purpose AI providers to be transparent about training and security risks for their models, and abide by EU and national copyright laws. The EU can fine companies that violate the AI Act up to seven percent of their annual sales. While META wants to join the genAI race, they still may not see clearly the use cases where they could leverage the technology. Another way of looking at this news is that while META is taking a stand here against the EU regulation, they may still comply with it eventually. 


DORA and NIS2


Even companies that don’t have a presence in the markets under DORA’s and NIS2’s scope may be affected by them as suppliers of businesses operating in the area. One of the main compliance challenges is to align NIS2 and DORA as pieces of legislation radically different from the ones previously mandated by the EU. Other obligations include red teaming and reporting an incident within 24 hours. DORA doesn’t distinguish between a traditional IT (e.g., a server running out of memory) and a cyber incident. In case of a serious cyber incident, you still might not know in the first 24 hours what exactly has happened. The legislation paints all financial institutions with the same brush. 


Being less prescriptive, SEC cybersecurity reporting in the US has a slightly different approach from DORA, offering broad and generic statements without going into specifics regarding how to achieve compliance. DORA overlaps with general data legislation such as GDPR to a large extent, while the payment industry already has PCI to comply with. DORA mandates businesses to report an incident in the country where the most clients are impacted, which means that in countries that come second or third in terms of impact may not be notified about the incident. Detailed notification about an incident is expected to get a bit of a leeway later from 24 to 72 hours or so. New regulation also puts too much pressure on CISOs, which might in the long term result in less professionals choosing this career path. 


The EU could have taken a different approach by amending existing regulation rather than creating a completely new piece that overlaps with others up to 80-90% and thus adding new ingredients to the alphabet soup of frameworks. What makes a risk-based approach trickier is that it’s harder to justify a security investment until an incident actually has happened. CISOs can transfer risk by explaining to the board what controls need to be in place to minimise risk and refrain from taking the blame if management refuses to invest in some of them. AI can be leveraged for 3P compliance to meet the requirements of the EU AI Act, DORA and NIS2. 

The panel’s advice

  • The EU AI legislation still looks like a blunt, new object that’ll probably need more chiselling.
  • Voluntary regulations never work as companies don’t see the point of compliance if they are not mandated to follow the rules.
  • As is always the case with new regulations, DORA is bound to get new iterations following implementation.
  • If you have ISO 27,001, you are 60% covered and only need to add a couple more programmes.
  • There is no reason to get scared by DORA and NIS2, as on closer inspection you are likely to find that most of the controls they mandate are already in place. 

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543