CyberElements
Back

Cybersecurity Compliance: What you need to know

CyberElements,

Share via

The cost of not following compliance for cyber security can far exceed the price of following it.

Neil Armstrong

Compliance can appear to be a hassle, or a set of checklists and boxes to tick — a single framework can easily run to 300 pages. But frameworks are important because they are there to help: they translate business risk into guidelines that keep your organisation secure against cyberthreats. If compliance seems complex, dealing with a breach is much more complicated.

Who is concerned by compliance for cyber security?

With the rise of cyber threats, compliance now concerns almost all sectors and organisations of all sizes. Here are a few examples of regulations.

  • HIPAA, for the healthcare sector, to protect patients’ data.
  • PCI-DSS, for financial organisations and ecommerce companies, securing card information.
  • The General Data Protection Regulation (GDPR), for any company handling European citizens’ personal data.
  • NIS2, DORA and NIST CSF 2.0, which are covered below.

Why do we need compliance?

  • Data protection and security enhancement. Complying with regulatory requirements ensures that organisations are taking the measures needed to secure critical data, preventing breaches that could result in tremendous financial loss and reputational damage.
  • Legal requirements. Most cybersecurity regulations are mandatory, or will be soon. Not complying can have serious consequences for organisations, including fines and legal action.
  • Customer trust. Complying with regulatory requirements reassures customers and partners, helping your organisation build trust by protecting their data and privacy.
  • Cyber insurance. Beyond legal requirements, cyber insurance companies require compliance with regulations to avoid high policy costs. Failing to comply can result in claims being denied.

Let us break down the recent directives and frameworks.

NIS2

The NIS2 directive was published in January 2023 by the European Union to update the original Network and Information Security directive of 2016. The new directive enforces stricter security requirements and covers a wider range of industries, including any third party and service provider supporting them. Failing to comply can have substantial consequences, up to €10M or 2% of the organisation’s revenue. By October 2024 all EU countries were to integrate NIS2 into their laws, and to submit a list of their “essential” and “important” entities to the Commission before April 2025.

Main measures

  • New sectors were added to the essential and important entities, whether public or private: digital providers, waste and water management, food, critical chemical manufacturing such as pharmaceutical and medical, space, postal services, social media platforms, public administrations and so on.
  • All organisations with 50 or more employees are concerned by NIS2. However, each European country can decide whether a specific small organisation must comply, and each country can create its own essential entities. Entities already under measures equivalent to NIS2 are not concerned.
  • The distinction between Essential Operators of Services and Digital Service Providers is no longer valid; there are now two categories of entity, essential and important.
  • The reinforcement of supply chain security and supplier relationships, by requiring risk assessments from the countries concerned in collaboration with ENISA.
  • The NIS2 directive does not apply where other sector-specific directives are more stringent than it is.

Since NIS2 does not cover all the security applications for the financial sector, DORA — the Digital Operational Resilience Act — comes in to improve and harmonise security requirements among EU members, becoming the directive to take into consideration for that sector.

The Digital Operational Resilience Act (DORA)

The first draft of DORA was published in September 2020 within the framework of the Digital Finance Package by the European Commission. DORA entered into force in 2023, expecting entities to comply by January 2025 and to follow guidelines covering risk management, resilience testing and third-party security — mandating financial organisations to have full control over their suppliers in an attempt to secure the entire supply chain.

Consequently, even though the DORA regulations are aimed at European companies, any international supplier that works with the EU will also have to comply.

Main measures

DORA relies on five main pillars to address the cybersecurity of the financial sector.

  • ICT risk management, in which DORA holds financial institutions’ management entities responsible for managing cyber risks by controlling and monitoring their ICT systems.
  • Incident reporting. In addition to managing risk, institutions’ managements are required to notify authorities about major ICT-related incidents. This pillar sets out the procedure for informing the European Supervisory Authorities in the case of an incident.
  • Digital resilience testing, which requires financial institutions to assess their readiness for threats by bringing in an external independent party for testing at least once a year.
  • Information sharing, contributing to raising awareness among financial institutions and enhancing the spread of best prevention and recovery practices.
  • ICT third-party risk management. Given the rise of supply chain attacks, DORA focuses on third-party risk management by requiring specific clauses in legal contracts about access and data security, as well as the right of audit and inspection. An up-to-date register of these contracts must be maintained.

The NIST Cybersecurity Framework 2.0

The National Institute of Standards and Technology (NIST) establishes worldwide standards that are highly recognised in the industry. Cyber insurance companies rely on them to define their policies and requirements, and the Irish National Cyber Security Centre uses the NIST frameworks as a foundation for its cyber regulations for the public sector.

NIST released a draft of CSF 2.0 in August 2023, making significant changes to versions 1.0 and 1.1. It broadened the sector scope, similarly to DORA, covering organisations of all sizes in all geographical locations. It also added one more function to the five existing ones — Identify, Protect, Detect, Respond and Recover — which is Govern.

The 6 functions of CSF 2.0

CSF 2.0 functionCSF 2.0 categories
Govern (GV)
  • Organisational Context
  • Risk Management Strategy
  • Roles and Responsibilities
  • Policies and Procedures
Identify (ID)
  • Asset Management
  • Risk Assessment
  • Supply Chain Risk Management
  • Improvement
Protect (PR)
  • Identity Management, Authentication, Access Control
  • Awareness and Training
  • Data Security
  • Platform Security
  • Technology Infrastructure Resilience
Detect (DE)
  • Adverse Event Analysis
  • Continuous Monitoring
Respond (RS)
  • Incident Management
  • Incident Analysis
  • Incident Response Reporting and Communication
  • Incident Mitigation
Recover (RC)
  • Incident Recovery Plan Execution
  • Incident Recovery Communication

How CyberElements can help you comply with CSF 2.0

  • Continuous monitoring and adverse event analysis. The session monitoring and real-time analysis feature of the CyberElements platform allows you to set security postures against which any suspicious activity is detected and automatically stopped.
  • Technology infrastructure resilience (PR.IR-02): the organisation’s networks and environments are protected from unauthorised logical access and usage. Policy-based access control backed with multi-factor authentication and just-in-time access makes sure the right user gets access to the resources needed, limiting any unnecessary access.
  • Platform security (PR.PS-01): configuration management practices are applied, covering least privilege and least functionality. The CyberElements platform is based on a double barrier architecture with no ongoing flow to the network, volatile tunnels and on-demand port opening — a Zero Trust approach giving the user the least privilege possible.
  • PR.PS-04 and PR.PS-08: log records are generated for cybersecurity events and made available for continuous monitoring, and supply chain security practices are integrated and their performance monitored throughout the product and service life cycle. The key features here are session recording in a video format and granular logs that can be searched and saved for further use.
  • Identity management, authentication and access control: access to physical and logical assets is limited to authorised users, processes and devices, and is managed commensurate with the assessed risk of unauthorised access. With a set of Identity and Access Management features — identity-based access policies, single sign-on and a password vault — CyberElements allows organisations to secure credentials with advanced technologies.
  • Supply chain risk management: the organisation’s supply chain risks are identified, assessed and managed consistently with its priorities, constraints, risk tolerances and assumptions. CyberElements, as a Zero Trust PAM solution, secures third-party access whether remote or on premises. You can give temporary access to a highly monitored session for a third party, and thanks to password rotation and automatic injection your credentials are never exposed to any of your service providers.

CyberElements is the security platform for business performance. It has been designed to cover your security needs without compromising user experience. Compliance for cyber security should not be a hassle but a lever for business performance, where security goes hand in hand with a better user experience, encouraging workforces to apply the appropriate security measures.

Tags

  • Articles
  • ZTNA
  • PAM
  • IGA
  • Authentication & SSO
  • Defence & Critical Infrastructure
  • Healthcare
  • Industrial & Manufacturing
  • MSPs
  • Public Sector
  • Financial Services
  • Audit & Compliance

Let’s secure your access together