Cybersecurity (NIS-2 AND DORA)

Strong cybersecurity is crucial to protect data, business operations, and public trust in today’s digital world. The European Union’s NIS-2 Directive and the Digital Operational Resilience Act (DORA) impose new regulations to enhance resilience and IT security, particularly in the financial sector. Sorainen provides solutions to help organizations in the Baltics comply with NIS-2 and DORA, ensuring legal compliance and operational continuity. By collaborating with cybersecurity experts, IT, and management teams, Sorainen ensures that businesses adopt best practices for a secure, resilient organization.

Our services include:

Gap analysis

We can assist in identifying gaps between current operations and the new requirements, advising on the necessary adjustments, and providing risk assessment to mitigate potential legal liabilities.

Compliance policies and contractual assistance

We can assist in drafting or revising internal policies and procedures to meet requirements, including cybersecurity frameworks, incident reporting, and operational risk management.

Cyber incident management

We can assist in responding to cyber incidents or operational disruptions, including developing a timely and legally compliant incident reporting process. We can also help communicate with national regulators. Read more here.

Vendor risk management

We can assist in drafting, reviewing, and negotiating contracts with third-party vendors, ensuring cybersecurity obligations are embedded in supplier agreements.

Training and awareness programs

We can assist in developing training programs for employees and management to raise awareness of legal requirements and best practices for operational resilience, cybersecurity, and incident management. We can brief the board of directors and senior management on the legal implications and how it affects the organization’s operations.

Monitoring and auditing

We can provide continuous legal monitoring to ensure ongoing compliance with legal acts, help facilitate internal audits, and assist in preparing for external audits or investigations.

Mergers and acquisitions (M&A)

We can conduct cybersecurity due diligence during M&A transactions, ensuring that potential acquisitions comply with cyber requirements, identifying any cybersecurity liabilities that may arise from the transaction, and later assisting in integrating compliance requirements into post-merger operations.

Dispute resolution and litigation

In cases where cybersecurity incidents lead to disputes or lawsuits, we can provide legal representation in court or during arbitration proceedings. If regulators take enforcement actions due to non-compliance, we can defend the organisation against fines, penalties or corrective measures.

Keep yourself updated with Cybersecurity (NIS-2 AND DORA) service news.

Join our newsletter

Subscribe to our newsletter!