NIS2 Directive
An EU law setting minimum cybersecurity and incident-reporting requirements for essential and important entities across critical sectors.
The NIS2 Directive is the EU's updated network and information security law, replacing the original 2016 NIS Directive. It expands the list of covered sectors (energy, transport, banking, health, digital infrastructure, public administration, certain manufacturing, and more), imposes specific cybersecurity risk-management measures, and sets strict incident-reporting deadlines with meaningful penalties for non-compliance. Each EU member state transposes it into national law, so exact obligations vary slightly by country.
NIS2 & ISO 27001 Compliance →ISO 27001
An international standard for information security management systems, and the most widely recognized security certification.
ISO 27001 defines requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). Certification is issued by an accredited external body after an audit and requires ongoing surveillance audits to maintain. In practice, ISO 27001-aligned controls also cover much of what NIS2 technically requires, which is why the two are often addressed together.
NIS2 & ISO 27001 Compliance →GDPR
The EU's General Data Protection Regulation, setting rules for how organizations collect, use, and protect personal data.
GDPR applies to any organization processing the personal data of EU residents, regardless of where the organization itself is based. It requires a lawful basis for processing, gives individuals rights over their data (access, correction, deletion), and mandates breach notification to authorities within 72 hours of becoming aware of a qualifying breach. Penalties can reach up to 4% of global annual revenue.
NIS2 & ISO 27001 Compliance →SOC 2
An audit framework and report attesting that a service organization's controls meet defined trust criteria: security, availability, confidentiality, and privacy.
SOC 2 is issued by an independent auditor following AICPA's Trust Services Criteria, commonly requested by enterprise customers evaluating a vendor's security posture before signing a contract. A Type I report assesses controls at a point in time; a Type II report assesses their operating effectiveness over a period (usually 6-12 months), which most enterprise buyers require.
NIS2 & ISO 27001 Compliance →PCI DSS
A security standard required for any organization that stores, processes, or transmits credit card data.
The Payment Card Industry Data Security Standard is mandated by card brands (Visa, Mastercard, etc.), not a government regulation, but non-compliance can result in fines and loss of card-processing privileges. Requirements cover network security, access control, encryption of cardholder data, and regular vulnerability scanning. Scope and validation requirements scale with transaction volume.
NIS2 & ISO 27001 Compliance →GRC (Governance, Risk & Compliance)
The combined discipline of setting security policy (governance), managing exposure (risk), and meeting legal/regulatory obligations (compliance).
GRC treats governance, risk management, and compliance as one connected program rather than separate silos, since a policy decision affects risk exposure, which affects what compliance frameworks require. Organizations use GRC platforms to track controls, evidence, and audit findings across multiple frameworks (NIS2, ISO 27001, GDPR) at once instead of managing each in isolation.
NIS2 & ISO 27001 Compliance →Data Protection Officer (DPO)
A designated role responsible for overseeing an organization's data protection strategy and GDPR compliance.
GDPR requires a DPO for public authorities and organizations whose core activities involve large-scale monitoring or processing of sensitive data; many other organizations appoint one voluntarily. The DPO monitors compliance, advises on data protection impact assessments, and serves as the contact point for both data subjects and supervisory authorities. The role can be filled internally or outsourced.
NIS2 & ISO 27001 Compliance →Business Continuity Plan (BCP)
A documented plan for keeping critical business functions running during and after a disruptive incident.
A BCP identifies critical processes, the resources they depend on, and the steps needed to maintain or quickly resume them after a disruption, whether that's a cyberattack, natural disaster, or supplier failure. It's broader than a disaster recovery plan, which focuses specifically on IT systems recovery. NIS2 and ISO 27001 both expect essential entities to maintain and test one.
Incident Response →Disaster Recovery Plan (DRP)
A documented, technical plan for restoring IT systems and data after an outage or destructive event.
A DRP defines specific recovery procedures, responsible teams, and target recovery times for IT infrastructure, applications, and data, typically as a subset of a broader business continuity plan. Its two central metrics are RTO (how fast systems must come back) and RPO (how much data loss is acceptable). Untested DRPs are a common failure point; a plan that's never been rehearsed often doesn't work as written.
Incident Response →Risk Assessment
The structured process of identifying, analyzing, and prioritizing security risks based on likelihood and potential impact.
A risk assessment inventories assets, identifies threats and vulnerabilities affecting them, and estimates the likelihood and business impact of each risk materializing, producing a prioritized list that guides where security investment goes. NIS2, ISO 27001, and GDPR all require some form of ongoing risk assessment, not a one-time exercise, since the threat landscape and business environment both change.
NIS2 & ISO 27001 Compliance →Breach Notification
The legal obligation to inform regulators and, in some cases, affected individuals after a qualifying data breach.
Under GDPR, organizations generally must notify their supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals' rights; affected individuals must also be notified if the risk is high. NIS2 imposes its own, often stricter and sector-specific, incident-reporting deadlines (an early warning within 24 hours in many transpositions). Missing these windows is itself a compliance failure, separate from the breach.
Incident Response →Cyber Insurance
An insurance policy covering financial losses from cyber incidents, such as breach response costs, business interruption, and liability claims.
Cyber insurance typically covers incident response and forensics costs, legal fees, regulatory fines (where insurable), business interruption losses, and third-party liability claims. Insurers increasingly require evidence of specific controls, such as MFA, EDR, and tested backups, before issuing or renewing a policy, and can deny claims if those controls weren't actually in place at the time of the incident.
Chain of Custody
The documented, unbroken trail showing who handled a piece of digital evidence, when, and how, from collection through to use in legal proceedings.
Chain of custody proves that evidence wasn't tampered with or altered between collection and presentation, which matters enormously if a security incident ends up in court, regulatory action, or an insurance claim. A break in the chain (evidence handled by someone unauthorized, or without a documented record) can render otherwise solid forensic findings inadmissible or easily challenged.
Incident Response →