Home Tags NIS2

Tag: NIS2

Spreadsheet vendor risk is a regulatory time bomb

Third-party risk management (TPRM) processes designed for 30 vendors do not slowly weaken as portfolios double. They fail at a specific and predictable point,...

Why DORA, NIS2 and ISO 27001 make tech risk a legal...

For EU-regulated firms, technology risk management is no longer simply good operational practice. It is a legal obligation, and DORA, NIS2 and ISO 27001...

Why your ‘compliance system’ might be the wrong model

Ask three different people what a "compliance management system" is and expect three different answers, because the term genuinely carries three separate meanings, each...

GRC framework or three silos? The distinction regulators now demand

Governance, risk, and compliance sound like a single discipline, but inside most organisations they still operate as three separate functions reporting up three separate...

Why most risk management frameworks fail supervisors

A risk management framework is often treated as a single, purchasable thing. In reality, the phrase splits into two distinct categories: frameworks an organisation...

The identity problem

Identity has become one of the most important fault lines in modern financial crime. As financial services move further into digital channels, the question...

The security models behind DORA and ISO 27001 compliance

Compliance teams at European financial institutions are under growing pressure to prove that their security controls do more than satisfy a checklist. As regulators sharpen...

Why disconnected GRC leaves boards exposed to regulators

Governance, risk and compliance, better known as GRC, are three disciplines that have traditionally operated in isolation, despite serving the same underlying objective. Increasingly,...

Vendor risk software: the compliance gap procurement tools can’t fill

Vendor management software and vendor risk management software are often bundled together in FinTech and RegTech conversations, but they solve fundamentally different problems. According to...

Why compliance automation has a hard ceiling

Compliance teams have leaned hard into automation, connecting cloud consoles, identity providers, endpoint tools and code repositories to pull evidence on a schedule rather...

50,000+ RegTech leaders get exclusive industry stories delivered every week