A single answer to NIS2, DORA, GDPR and the EU AI Act, backed by governance your management body can stand behind. IrisInfosec maps each obligation to a clear control, builds the board reporting and risk register the regulations now expect, and keeps the programme current as the rules and the deadlines move. Lawyer-led, read at source.
Knowing a regulation applies is the easy part. The work is turning its articles into controls your teams can run, evidence an auditor accepts, and reporting a board can approve. That translation is what we do, and it is where a programme led by a lawyer earns its place.
Cyber regulation increasingly names the management body directly: boards are expected to approve cyber risk, oversee it, and in some cases hold personal accountability. Governance is no longer optional housekeeping, it is part of the obligation.
Regulatory compliance and cyber governance
is the work of mapping your cyber obligations to concrete controls and standing up the oversight, policies and reporting that let a board and a regulator both see they are met.
Regulations we map and meet
We start where obligation is sharpest, then carry the same control set into the other
regimes you operate under.
Risk management, incident reporting and supply chain duties for essential and important entities, with management accountability built in.
Digital operational resilience for financial entities: ICT risk, incident classification, resilience testing and third-party oversight.
Lawful basis, data subject rights, breach notification and accountability for any organisation handling EU personal data.
Risk classification and obligations for providers and deployers of AI systems placed on the EU market.
India’s Digital Personal Data Protection Act: consent, notice, data principal rights and obligations for data fiduciaries.
CERT-In, RBI, SEBI and IRDAI directions in India, and HIPAA and CCPA in the US, layered onto the core programme.
Common question
They overlap, and many groups fall under both. Here is how they differ, and how we keep
you from doing the work twice.
| NIS2 | DORA | |
|---|---|---|
| Type | Directive, transposed by each member state | Regulation, applies directly across the EU |
| Who | Essential and important entities, many sectors | Financial entities and their ICT providers |
| Focus | Cyber risk management and incident reporting | Digital operational resilience end to end |
| Third parties | Supply chain security duties | Detailed ICT third-party oversight and registers |
| If both apply | DORA generally takes precedence for financial entities on ICT risk; we map the two to one control set so nothing is duplicated | |
How we work
A measured five-stage approach, scoped to the regulations that actually apply to you.
Confirm which regulations apply by entity, sector and jurisdiction, and where the deadlines fall.
Measure current state against each obligation and rank the gaps by risk and by date.
Translate overlapping articles into one control set, so a single effort satisfies several regimes.
Stand up policies, processes and reporting, and capture the evidence each clause requires.
Board reporting and a maintained register, with a cadence that keeps you current as rules change.
Cyber governance
Several regimes have moved governance from the appendix to the front page. We build the
structures that let your board direct and oversee cyber risk with confidence.
Clear ownership from the board down, with a RACI that holds up under scrutiny.
A risk picture executives can read, approve and act on, not a wall of red and green.
A coherent set of policies and standards, owned and reviewed on a defined cadence.
Risks tracked, treated and reviewed, so the register reflects reality rather than last year.
A control that is documented but never tested is a finding waiting to happen. We pair this programme with independent assessment, so your evidence is verified, not asserted.
Know exactly what applies to you
Tell us your sectors and the markets you operate in. We will confirm which regulations apply and send a prioritised plan with dates.
Questions, answered
Related services