The Register previewed a SANS webinar I led on European cybersecurity regulation: Cybersecurity regulation is stepping up.
The session ran on September 16, 2024, sponsored by SANS, and broke down three regulatory frameworks that were reshaping how security teams operate:
- NIS2: the EU’s expanded network and information security directive
- DORA: the Digital Operational Resilience Act for the financial sector
- TIBER-EU: the framework for threat intelligence-based ethical red teaming
The theme throughout was that effective compliance takes more than ticking boxes. These frameworks demand real shifts in how security operations run: understanding what they actually require, using them to reshape the security landscape rather than bolt on paperwork, and building genuine cyber resilience. I also shared some survey findings from the run-up to the session.
If regulation is pushing your organization to mature its security operations, that pressure is best treated as an opportunity to do the fundamentals properly, not as a checklist to satisfy and forget.