Skip to content

Practice area 06

Information Security & Technology Compliance

The legal and regulatory side of information security: the governance, policies, third-party arrangements and incident obligations that regulators expect to see documented and working.

Discuss your matter

Typical deliverables

  • Regulatory applicability assessment
  • Information security policy set
  • Gap assessment and remediation plan
  • ICT third-party register and contract requirements
  • Incident classification and reporting procedure
  • Management body reporting pack

Overview

Why it matters

Information security has become a regulatory obligation in its own right. EU financial entities are subject to DORA's requirements on ICT risk management, incident reporting and third-party risk; NIS2 extends security and reporting obligations to many digital service providers; and supervisors and banks increasingly ask to see the governance behind a firm's security, not only its certifications.

We work on the legal and regulatory layer: establishing which frameworks apply, writing the governance and policy set, assessing gaps against the applicable requirements, structuring third-party and incident obligations, and preparing the documentation regulators and counterparties review.

This is legal and regulatory compliance work. ROZSUD does not carry out penetration testing, operate security monitoring or engineer technical controls. Where your framework requires technical testing, it is performed by specialist providers; we can define what the regulation requires of that testing and review its results from a compliance perspective.

Scope

What we do

  1. 1.

    Information Security Compliance

    Mapping the security obligations that apply to your business — sector rules, DORA, NIS2, data protection and contractual commitments — and a framework that meets them.

  2. 2.

    Security Governance & Policies

    An information security policy set, roles and responsibilities, management body oversight and reporting lines.

  3. 3.

    Information Security Gap Assessment

    A document- and interview-based assessment of your framework against the applicable regulatory requirements, with prioritised remediation.

  4. 4.

    DORA Compliance

    ICT risk management framework, incident classification and reporting, resilience testing governance and ICT third-party risk for EU financial entities.

  5. 5.

    NIS2 Compliance

    Whether NIS2 applies, registration where national law requires it, risk-management measures and incident reporting under the national transposing law.

  6. 6.

    Third-Party / Vendor Risk

    Due diligence, contractual requirements, registers and exit planning for ICT and other critical service providers.

  7. 7.

    Incident Response Governance

    Incident response procedures, escalation and decision-making, and regulatory notification workflows.

  8. 8.

    Technology Regulatory Compliance

    Regulatory review of technology arrangements — cloud outsourcing, platform changes and new products — before they go live.

Questions

Frequently asked

Do you carry out penetration tests or security monitoring?

No. We cover the legal, regulatory and governance side of information security. Technical testing and security operations are performed by specialist providers; we can define what the regulation requires of that work and review the results from a compliance perspective.

Does DORA apply to us?

DORA applies to a defined list of EU financial entities — including payment and e-money institutions, investment firms and crypto-asset service providers — and reaches their ICT providers through contractual requirements. We confirm applicability and scope before any gap assessment.

Related

  • Privacy compliance and GDPR programmes, notices and DPAs, DPIAs, data mapping and ROPA, transfers, audits and breach response.

  • Licence strategy, applications and regulator engagement for gaming, payments, e-money, investment and crypto-asset businesses.

  • Retained senior counsel for day-to-day legal, regulatory and compliance questions across all your entities.

All 11 practice areas

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.