Regulatory obligation translated into engineering decisions: what the rules actually require of a technology function, and what that costs to build.
171 articles, most recent first within each group.
European Union
- Charging Parity and Reachability for SEPA Instant: Re-Pricing and Capacity Planning
- Post-Quantum Code Signing and PKI: Migrating to ML-DSA
- The EHDS Opt-Out Mechanism: Building Patient Preference Into Every Secondary-Use Query
- Vendor AI Act Flow-Down: The Contractual and Technical Attestations to Demand From Model and Tool Suppliers
- NIS2 and the CRA for a Device Maker: When You're Both a Regulated Entity and a Regulated Product
- T+1 Across EU, UK and Switzerland: One Coordinated Cutover, Three Rulebooks
- Settlement Fails and CSDR Penalties Under T+1: Instrumenting the Exception Queue
- Standing Settlement Instructions as Master Data: Cleaning SSIs Before T+1
- Redaction Pipelines for DSAR Exports: Releasing One Subject's Data Without Another's
- The European Cybersecurity Alert System: What Cross-Border SOCs Mean for Your Threat Intel
- Scrubbing PII From LLM Logs Before They Persist
- CRA Due Diligence on Your Suppliers: Pushing Secure-by-Design Down the Component Chain
- Bulk Active Directory Cleanup With PowerShell: Finding and Disabling Stale Accounts
- FRTB in the EU: Preparing for the 1 January 2027 Market-Risk Go-Live
- Am I a CIRCIA Covered Entity? Scoping Critical-Infrastructure Reach Across 16 Sectors
- CRA Annex I: What 'Secure by Design' Actually Requires You to Prove
- The EU's SEAL Framework: Cloud Sovereignty Is Now a Score, Not a Slogan
- What 'Products With Digital Elements' Actually Means Under the CRA
- NIS2 vs CRA: Why 'Entity' and 'Product' Obligations Don't Merge Into One Programme
- The EU Data Act Gave You the Right to Leave Your Cloud Provider — Check Your Contract
- Compliance Evidence Should Be Generated, Not Assembled
- Audit Readiness as a Continuous State, Not a Preparation Cycle
- Agentic AI in Regulated Finance: Why Governance Keeps Most Firms on Deterministic Rails
- Sovereign-by-Design: Architecting for European Jurisdiction From Day One
- The CLOUD Act vs GDPR: The Unresolved Conflict Behind Sovereign Cloud
- The Right to Erasure in a System With Backups and Event Logs
- CRA for Open-Source Stewards: Understanding the New Steward Category
- DPIAs: When You Actually Need One
- Living SBOMs and VEX: Why Static 'Paper SBOMs' Fail in Production
- The AI Controls Matrix: 243 Control Objectives Across 18 Domains
- Time Travel and Snapshots as Compliance Tools: GDPR Deletes in the Lakehouse
- CRA Annex I Is a Risk Assessment, Not a Checklist
- SEAL and CADA: How the EU Is Turning Cloud Sovereignty Into a Measurable Score
- How to Prove DORA Compliance to a Supervisor
- NIS2 Essential Entities: The Obligations the Highest Tier Actually Carries
- EHDS EHR Certification: The Real Timeline, and Why It Is a Data-Model Problem
- The Taxonomy the DSA Already Requires You to Build
- The DORA Contract Clauses Most Vendor Paper Doesn't Have
- Disaster Recovery: RTO and RPO as Business Decisions, Not Technical Ones
- GDPR as an Architecture Constraint, Not a Legal Footnote
- The CRA Deadline That Arrives Before the One Everyone Is Watching
- E-Signature Selection: Legal Validity Across Jurisdictions
- Contact Centre Platform Selection for a Regulated Firm
- GDPR-Aligned HR Tooling for EU Firms
- CRM Data Residency and GDPR in Dynamics 365
- HCM Selection for a Multi-Jurisdiction Group
- Azure for a Regulated EU Financial Entity
- Access Certification for Regulated Entitlements
- HR Data Privacy Across GCC and EU
- Cloud-Native SIEM for a Microsoft Estate
- CIAM Governance and Consent
- Regulatory Sandboxes: The Delayed National Obligation
- DORA in Steady State: ICT Risk, Incident Reporting and TLPT
- Entra vs Okta for a Microsoft-First Regulated Firm
- Compliance Convergence: AI Act + DORA + NIS2 as One Programme
- Operational Resilience Testing and Impact Tolerances
- SBOMs and Cryptographic BOMs as Audit Artefacts
- Choosing a SIEM Under DORA Logging Duties
- Open Banking, Open Finance and Embedded Payments
- Mid-Market GRC Selection Without the Enterprise Price
- Global Payroll: The Compliance Minefield
- IAM as the Control Plane for DORA and NIS2
- DORA Critical Third-Party Oversight: What Designation Means for You
- Choosing a GRC Platform for DORA Compliance
- Building a DORA Control Library in ServiceNow
- Cloud Concentration Risk and Your Exit Plan
- Cyber Resilience Act and Crypto-Agility: The Product Duty Nobody Priced In
- NIS2 Enforcement Is Waking Up: A Reading for In-Scope Firms
- Post-Quantum Cryptography: The Board Reading
- GDPR Records of Processing: Why Most Tech Functions Get the Architecture Wrong
- DORA Incident Reporting: Architecture and Operating Model
- ICT Risk Management for IFSC Firms: A Reading of the Central Bank's Recent Guidance
- Technology Risk in Fund Administration: Where CSSF Inspections Actually Land
- Technology Due Diligence on an Irish SaaS Target: What US and EU Buyers Should Check
- DPC GDPR Enforcement Patterns: Six Technology Failures That Trigger Action
- Outsourcing IT from Irish Regulated Firms: The Concentration Risk You're Not Measuring
- DORA Article 6 ICT Risk Management Framework: A Practical Reading
- NIS2 Technology Implications: Essential and Important Entities
- The EU Cyber Resilience Act: what the 2026 deadline means for anyone who ships software
- DORA is live. What your technology function needs to do now.
- Your cyber insurer just sent a 14-page questionnaire. What now?
- Your regulator asked where your data lives. Could you answer?
- When your regulator starts asking about your technology
- What GDPR actually means for a company that handles client data and isn't sure
- NIS2: the EU cybersecurity directive that's now being enforced
- VAT in the Digital Age: the e-invoicing mandate your finance systems aren't ready for
- The UK Cyber Security and Resilience Bill: what it means for your business
- The UK Data (Use and Access) Act: what's changing in UK data protection
- The European Accessibility Act: why your digital products now have to be accessible
Operational Resilience
- Maritime Cyber: From Compliance to Resilience, Beyond MSC.428(98)
- The Board's Cyber-Incident Reporting Map: CRA, NIS2, DORA and Sector Rules in One View
- Backups Aren't Backups Until You've Restored One
- APRA CPS 230: A Proof Standard Wearing a Policy Standard's Clothes
- Secrets Management: Why Vault Is a Governance Decision
- Email Security: Proofpoint vs Mimecast and the Phishing Reality
- DLP Selection Without Killing Productivity
- Vulnerability Management at Scale
- UEM/MDM: Governing Devices Across a Hybrid Workforce
- Cloud Security Posture for a Regulated Estate
- IAM for a Lean Regulated SME
- Merging IT and HR Provisioning Safely
- When Your Security Vendor Is Breached: Managing the Fallout
- Privileged Access: The Audit Finding You'll Get
- Automated Compliance: What Vanta and Drata Do and Don't Cover
- Open-Source SIEM: The True Operating Cost
- IAM Selection for High-Assurance Environments
- Vendor and Third-Party Concentration Risk
- Harvest Now, Decrypt Later: Which of Your Data Is Already Exposed
- Cryptographic Inventory: The Mandatory First Step
- Supply-Chain Risk Lessons From SolarWinds
- Ransomware-as-a-Service and the Payment/Disclosure Dilemma
- Building a DORA Resilience Programme for a Luxembourg-Regulated Entity
- CSSF Cloud Computing Guidance: What "Critical or Important Function" Actually Means
- DORA for Maltese Financial Institutions: Six Questions Your Board Should Be Asking
- MiCA Article 68 Operational Resilience: A Technology Function's Reading
- DORA Threat-Led Penetration Testing (TLPT): What Firms Must Actually Commission
- DORA Critical Third Party Designation: A Reading for Both Sides
- DORA for Irish Financial Services: A Practical Reading for Boards
- Central Bank of Ireland Operational Resilience Requirements: A Technology Checklist
- DORA for Luxembourg Funds and Fund Services: A Board-Level Briefing
DORA
- Outsourcing IT Under MFSA Rule Book Chapter 3: Concentration Risk in Small Vendor Markets
- Technology Due Diligence on a Luxembourg Fund Services Target
- MFSA's ICT and Security Risk Management Framework: What Your Tech Function Must Demonstrate
- CASP Authorisation: The Technology Evidence Regulators Actually Want
- CSSF Circular 22/806: A Practical Technology Reading for ICT Outsourcing
Platform Selection
- Pressing Your Vendors for PQC Roadmaps: A Due-Diligence Checklist
- Microsoft 365 vs Google Workspace for a Regulated Firm
- Tax Automation and the Compliance Case
- Code Security Tooling: SAST, SCA and the Pipeline
- Enterprise GRC Selection for a Regulated Group
- GRC Tooling for a First Internal Audit Function
Dependency Management
- Automated Cryptographic Inventory: Generating a CBOM From Your Estate
- Third-Party Risk Concentration in US Banking: Measuring Cloud and Core-Provider Dependence
- Living SBOMs in the Pipeline: Generating, Signing and Attesting Provenance
- Generating and Diffing SBOMs Across Releases With Syft
- Essential Eight to Maturity Level Two: A Build Programme, Not a Checklist
- Validating JWTs Correctly: Signature, Issuer, Audience, Expiry and the JWKS Rotation Trap
- Security Questionnaires: How to Answer Them Honestly
- Supply Chain Risk: The Dependencies You Didn't Choose
- How long would it take to recover your systems after a ransomware attack?
- Your server hasn't been patched in two years. What that actually means for your business.
More in this area
- Sanctions Screening Re-Architected for Instant Payments: Daily Lists, Not Per-Transaction
- CCPA Cybersecurity Audits: Preparing for the First Auditable Period Beginning January 2027
- FinCEN's Investment Adviser AML Rule: Building a BSA/AML Program From Zero by 2028
- A CIS-Aligned Windows Server Hardening Baseline You Can Actually Apply and Verify
- Keyless Deploys to Azure: Federated Credentials From GitHub Actions via OIDC
- Don't forget the shipping decarbonisation vote everyone stopped tracking in 2025
- Why did my restic snapshot silently skip files?
- Signing Webhooks Properly: HMAC Signatures, Timestamps and Replay Protection
- Don't forget to file this on the 30th — ETS allowance surrender for the 2025 reporting year
- Don't forget to check whether your HSM, VPN and TLS terminators just went uncertified
- Don't forget to test the path from your dev team to ENISA before you need it
- Don't forget to rewrite the deadline slide you built for the board last year
- Don't forget to name your CRA reporting contact — the 24-hour early-warning clock starts 11 September
- Don't forget to disclose your chatbot — Article 50 lands 2 August and it was not deferred
- Storing Credentials Properly in PowerShell: SecretManagement and SecretStore
- GENIUS Act Reserve Attestation: Building the Monthly Proof a US Stablecoin Issuer Now Owes
- API Keys That Aren't a Liability: Hashing, Prefixes, Scoping and Rotation
- CMMC Phased Rollout: Getting to Level 2 Certification Before It Appears in Your Contract
- CIRCIA Is Coming: Building the 72-Hour Incident and 24-Hour Ransom-Payment Reporting Muscle
- One Control Environment, Many Frameworks: Crosswalking AI RMF, ISO 42001 and CSF
- Private and On-Prem Sovereign AI: Running Models Without Surrendering Jurisdiction
- Starlink at Sea: How Connectivity Ended the Isolation That Protected Ships
- AI Model Risk Is Operational Risk: Extend Your ORM Framework, Don't Rebuild It
- IACS UR E26/E27: Designing Cyber Resilience Into Newbuild Vessels
- Residency Is Not Sovereignty: Why Where Your Data Sits Isn't the Question
- MiCA vs MGA: How Crypto and Gaming Regulators Differ on Technology Controls
- Why your cyber insurance renewal suddenly became a technology problem
- A customer just asked for your SOC 2 report. Now what?
- A key customer has asked to audit your technology. What happens next?
- The five questions your first enterprise customer will ask