DORA and NIS2 in Plain English: What Every Board Must Do Now, According to Professor Kai London
By the Daneborg Times Technology Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com Two regulations have quietly become the most consequential items on many European boardroom agendas: the Digital Operational Resilience Act (DORA) and the second Network and Information Security Directive (NIS2). They are long, technical and easy to delegate into a compliance backwater. That, warns Professor Kai London , a senior CISO and board advisor, would be a serious mistake. “These are not IT paperwork exercises,” he says. “They put personal accountability for cyber resilience on the board itself.” “DORA and NIS2 mark the moment cyber stopped being something the board hears about after the fact, and became something the board is answerable for. The regulators have moved the question from ‘did you have a policy?’ to ‘can you prove it worked?’” What DORA actually asks DORA applies to the European financial sector and the technology providers th...