Regulatory Cyber Resilience

Cyber regulation, translated into an operating model.

NIS2, DORA, the Cyber Resilience Act, and the UK's Cyber Security and Resilience Bill place enforceable obligations on your organisation and its management body. We turn those obligations into governance, controls, and evidence that hold up under supervisory scrutiny, across UK and EU jurisdictions from a single engagement team.

What this covers

One control framework, every obligation.

NIS2 Readiness and Implementation

Your board has been briefed on NIS2, and nobody has yet established your scope, the size of the gap, or where to begin.

Applicability, gap assessment, management body governance, the ten risk control domains, incident processes against the notification timelines, supply chain security, and the evidence model, taken through from assessment to delivery.

NIS2 Programme Design

You have your readiness findings, and now the gaps have to become a costed, sequenced programme your board will fund and your teams can deliver.

Translation of diagnostic and gap findings into a delivery programme: workstreams, ownership, milestones, dependencies, investment profile, and the governance and evidence model that carries it through to business as usual.

DORA ICT Risk Support

As a financial entity, you must show supervisors an ICT risk framework that functions in practice.

Governance, critical and important function mapping, third party ICT risk, resilience testing governance including threat-led penetration testing readiness, cloud risk, and remediation oversight.

Cyber Security and Resilience Bill Readiness

The Cyber Security and Resilience Bill will reshape UK obligations, and if you are in scope you need to know what will change and what to prepare.

Assessment of scope, critical suppliers, governance, reporting, resilience, and the organisational changes the Cyber Security and Resilience Bill will demand, aligned with any parallel EU obligations.

Cyber Resilience Act Advisory

Your products with digital elements must meet CRA obligations on a fixed timeline, and your product, engineering, and legal teams each own a piece of the answer.

Product risk governance, secure development responsibilities, vulnerability handling, supplier duties, and the technical documentation and evidence the conformity route requires.

Supply Chain and Third Party Cyber Risk

NIS2 and DORA both place supplier security obligations on you, and your contracts do not yet reflect them.

Supplier criticality assessment, contractual security provisions, concentration risk, due diligence, and the ongoing monitoring process that survives handover to business as usual.

Cross Regulatory Control Frameworks

Several regulations apply to you at once, and running a separate programme for each would multiply your cost and fragment your evidence.

Mapping of common obligations across the regulations and standards that apply to you, into one control framework and one body of evidence.

Where to start

Two defined starting points.

Fixed scope, defined outputs, senior delivery. Each establishes your position before any programme commitment.

5-day engagement

NIS2 Readiness Diagnostic

Establishes your scope, governance readiness, control maturity, incident notification capability, and supply chain exposure before any programme investment is made.

What you receive
  • Provisional scope statement by entity, sector, and jurisdiction
  • Governance readiness assessment against the management body's obligations
  • Maturity map across all ten security obligation areas
  • Incident notification capability assessment against the regulatory timelines
  • Supply chain exposure map for material supplier relationships
  • Programme readiness brief written for the management body
Request a diagnostic
Fixed scope

Critical Supplier Cyber Risk Review

Establishes which of your supplier relationships carry material cyber risk, where the concentration sits, and what the contracts and due diligence need to change.

What you receive
  • Supplier criticality and dependency view
  • Concentration risk assessment
  • Due diligence findings for priority suppliers
  • Control and contract recommendations
Request a supplier review
In depth

The regulations, briefly.

NIS2

Enforceable across the EU since October 2024. Applies to essential and important entities across 18 sectors, with fines up to €10 million or 2% of global turnover for essential entities and personal liability for the management body.

The obligations concentrate in three places: the management body must approve and oversee the security measures, ten domains of security measures are required, and incidents must be notified on a 24-hour, 72-hour, and one-month timeline.

  • Scope varies by Member State transposition
  • Management body accountability, including training
  • Ten security obligation domains
  • 24-hour early warning capability
  • Supplier contract obligations
  • UK and EU Member State coverage in one engagement

DORA

Applies to financial entities and their critical ICT service providers since January 2025. Supervisors expect a functioning ICT risk management framework, incident classification and reporting, digital operational resilience testing, and managed third party ICT risk.

Significant entities face threat-led penetration testing obligations. Contracts with ICT providers must contain specific provisions, and registers of information must be maintained and reportable.

Cyber Resilience Act

Applies to products with digital elements placed on the EU market. Vulnerability reporting obligations apply from September 2026 and the full Regulation from December 2027. Manufacturers carry the heaviest obligations: essential requirements, technical documentation, conformity assessment, CE marking, and vulnerability handling for the support period.

Importers and distributors carry lighter but real obligations, and either can be treated as a manufacturer by placing a product under their own name or making a substantial modification.

The Cyber Security and Resilience Bill

The Cyber Security and Resilience Bill will strengthen the UK's cyber resilience regime for essential services and critical suppliers. Organisations operating on both sides of the Channel face overlapping but not identical obligations.

We advise on the Cyber Security and Resilience Bill alongside EU obligations in a single engagement, so group-wide programmes reflect both without duplication.

Common questions

Frequently asked questions.

Start the conversation

Not sure where your organisation stands?

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.