Threat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 24.07.2026 09:37 CET30 dossiersMITRE ATT&CK mapping

Topic · Compliance

Regulations and compliance

The European rules governing security and data — and why they're not just red tape.

mediumFeatured dossierDORA, one year on: what it really requires of finance, and why it reaches IT suppliers tooRead the dossier →

Dossiers in this section

2 dossiers

The topic in brief

Three European pillars

The European legal framework rests on interlocking regulations and directives. The GDPR (Reg. EU 2016/679) governs the processing of personal data. NIS2 (Dir. EU 2022/2555) mandates security measures and incident-reporting obligations for operators in critical sectors. DORA (Reg. EU 2022/2554) does the same for the financial sector, with rules on digital operational resilience and critical ICT providers.

From paper to practice

Compliance isn't filling in a form: it's a process. Risk analysis, proportionate technical and organisational measures, incident-notification procedures within set deadlines, governance with top-management accountability. NIS2 in particular shifts compliance from the IT department to the board.

Why it's worth it, not just mandatory

The very measures the rules require — asset inventory, patch management, access control, response plans — are the ones that reduce real risk. Compliance done well isn't a cost separate from security: it is security, written down in a verifiable way.

FAQ

What's the difference between GDPR and NIS2?
GDPR protects personal data; NIS2 mandates cybersecurity measures and incident reporting for operators in critical sectors. Both can apply.
What is DORA?
The Digital Operational Resilience Act (Reg. EU 2022/2554): digital operational resilience rules for the financial sector and its critical ICT providers.