Skip to content
LegAIchain

Cybersecurity & NIS2

Legal and organisational support for meeting security obligations and getting certified against recognised standards. We help you scope NIS2 duties, put an information security management system in place, and prepare for the audits that back it up. Where DORA also applies, we align the two so you are not running parallel programmes.

What this covers

  • NIS2 scoping to establish whether you are an essential or important entity
  • NIS2 risk-management, governance and incident-reporting obligations
  • ISO/IEC 27001 implementation: gap analysis, ISMS documentation and Statement of Applicability
  • ISO/IEC 27001 certification support and audit preparation
  • DORA alignment for financial entities and their ICT providers
  • Security policies, procedures and access-control frameworks
  • Incident response plans and reporting workflows to competent authorities
  • Business continuity and disaster-recovery documentation
  • Penetration-test coordination and remediation tracking
  • Supply-chain and third-party ICT risk assessments
  • Management-body accountability and security training obligations
  • Vulnerability-handling and patch-management procedures
  • Interaction between security duties and personal data breach rules
  • Vendor security clauses and audit rights in ICT contracts

More in Legal

Let's talk about your project.