Privacy compliance and GDPR programmes, notices and DPAs, DPIAs, data mapping and ROPA, transfers, audits and breach response.
Practice area 06
Information Security & Technology Compliance
The legal and regulatory side of information security: the governance, policies, third-party arrangements and incident obligations that regulators expect to see documented and working.
Discuss your matterTypical deliverables
- Regulatory applicability assessment
- Information security policy set
- Gap assessment and remediation plan
- ICT third-party register and contract requirements
- Incident classification and reporting procedure
- Management body reporting pack
Overview
Why it matters
Information security has become a regulatory obligation in its own right. EU financial entities are subject to DORA's requirements on ICT risk management, incident reporting and third-party risk; NIS2 extends security and reporting obligations to many digital service providers; and supervisors and banks increasingly ask to see the governance behind a firm's security, not only its certifications.
We work on the legal and regulatory layer: establishing which frameworks apply, writing the governance and policy set, assessing gaps against the applicable requirements, structuring third-party and incident obligations, and preparing the documentation regulators and counterparties review.
This is legal and regulatory compliance work. ROZSUD does not carry out penetration testing, operate security monitoring or engineer technical controls. Where your framework requires technical testing, it is performed by specialist providers; we can define what the regulation requires of that testing and review its results from a compliance perspective.
Scope
What we do
- 1.
Information Security Compliance
Mapping the security obligations that apply to your business — sector rules, DORA, NIS2, data protection and contractual commitments — and a framework that meets them.
- 2.
Security Governance & Policies
An information security policy set, roles and responsibilities, management body oversight and reporting lines.
- 3.
Information Security Gap Assessment
A document- and interview-based assessment of your framework against the applicable regulatory requirements, with prioritised remediation.
- 4.
DORA Compliance
ICT risk management framework, incident classification and reporting, resilience testing governance and ICT third-party risk for EU financial entities.
- 5.
NIS2 Compliance
Whether NIS2 applies, registration where national law requires it, risk-management measures and incident reporting under the national transposing law.
- 6.
Third-Party / Vendor Risk
Due diligence, contractual requirements, registers and exit planning for ICT and other critical service providers.
- 7.
Incident Response Governance
Incident response procedures, escalation and decision-making, and regulatory notification workflows.
- 8.
Technology Regulatory Compliance
Regulatory review of technology arrangements — cloud outsourcing, platform changes and new products — before they go live.
Industries
Where we apply it
- iGaming & GamingB2C operators, B2B suppliers, platforms, aggregators and affiliates.

- Fintech & PaymentsPayment and e-money institutions, PSPs and acquirers, payment facilitators and embedded finance.

- Crypto & Digital AssetsCASPs and VASPs, exchanges, custodians, wallets, token projects and crypto payments.

- Forex & InvestmentsForex and CFD brokers, investment firms, trading and investment platforms.

- Digital Platforms & MarketplacesOnline marketplaces, platform operators and intermediary business models.

- Technology BusinessesSoftware, SaaS, data-driven and ICT businesses operating across borders.

Questions
Frequently asked
Do you carry out penetration tests or security monitoring?
No. We cover the legal, regulatory and governance side of information security. Technical testing and security operations are performed by specialist providers; we can define what the regulation requires of that work and review the results from a compliance perspective.
Does DORA apply to us?
DORA applies to a defined list of EU financial entities — including payment and e-money institutions, investment firms and crypto-asset service providers — and reaches their ICT providers through contractual requirements. We confirm applicability and scope before any gap assessment.
Related
Related practice areas
Platform, white-label, B2B supply, SaaS, affiliate and outsourcing agreements drafted for regulated environments.
Licence strategy, applications and regulator engagement for gaming, payments, e-money, investment and crypto-asset businesses.
Retained senior counsel for day-to-day legal, regulatory and compliance questions across all your entities.
Discuss your matter with a senior advisor.
Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.
