Category
Cybersecurity & Compliance
NIS2, DORA, the Cyber Resilience Act, and the GDPR create overlapping obligations that redefine who bears liability when systems fail. These articles examine how those obligations interact in practice: across borders, across regulators, and across the contracts that connect supplier to buyer.
Is my subsidiary in scope of NIS2?
Is a small MSP subsidiary in scope of NIS2? The answer depends on group-size calculation, linked enterprises, Recital 16, and national transposition.
Supply chain email fraud: how NIS2, DORA and the GDPR reshape civil liability
How NIS2, DORA, and the GDPR create statutory cybersecurity benchmarks that strengthen civil liability claims after supply chain email fraud.
Supply chain email fraud: which party pays when the supplier gets hacked?
Supply chain email fraud: which party bears the loss when the supplier is hacked? Cross-jurisdictional analysis across the EU, US, and Canada.
The EU AI Act’s operator model: what every company needs to know before deploying AI
The EU AI Act operator model: when companies become providers of AI systems, and what compliance obligations that triggers under Regulation 2024/1689.
Stay in the conversation.
New analysis delivered directly. No noise.