Services / Advisory
Regulatory Advisory
Which rules actually apply to you, and what each one obliges you to do.
The problem
A customer says DORA. An investor says NIS2. A prospect in Germany says the AI Act. You have no idea which of these apply to a company your size, in your sector, and what each one actually demands in practice. The cost of guessing wrong is either a scramble or a year of work you never needed to do.
The method.
Determine applicability, in writing
Scoping analysis per regime: which entity, which activity, which jurisdiction, which threshold. DORA applies to financial entities and their critical ICT providers; NIS2 turns on sector and headcount; the EU AI Act turns on the risk class of the system and your role as provider or deployer. Most companies are in scope for fewer regimes than they fear and for one they had not noticed.
Translate obligations into controls
Each in-scope regime is decomposed into concrete duties (incident reporting windows, register of information, supplier contract clauses, technical documentation, logging retention) and mapped onto the ISO 27001 and SOC 2 controls you already run, so the same evidence serves several masters.
Produce the delta
The only work that matters is what the new regime adds on top of what you already have. We publish the delta as a scoped work plan with effort estimates, owners and statutory dates, and we say plainly which obligations you already meet.
Handle the contractual chain
Review the security and regulatory clauses your customers push at you, and the ones you must push at your own suppliers (DORA subcontracting terms, GDPR Article 28 processor clauses, exit and audit rights) so the obligations that get signed are the ones you can actually perform.
Maintain a regulatory watch
Named regimes are tracked for change: implementing acts, technical standards, guidance from the Israeli Privacy Protection Authority, supervisory expectations. You receive changes that affect you, with the required action, and nothing else.
What is regulatory advisory in cybersecurity?
Regulatory advisory is the practice of determining which security and privacy regulations apply to a specific organisation, translating each obligation into concrete technical and organisational controls, and tracking changes to those regulations over time. It is a compliance discipline, not a legal service.
Does NIS2 or DORA apply to an Israeli technology company?
It can. NIS2 and DORA apply on the basis of activity and market rather than incorporation: an Israeli company can be pulled into scope as an ICT service provider to a European financial entity, as an essential or important entity operating in the EU, or contractually through its customers, who pass the obligations down. Applicability has to be assessed per entity and per contract.
What is the difference between regulatory advisory and legal services?
Regulatory advisory determines which frameworks apply, what controls they require, and how to implement and evidence those controls in your systems and processes. It does not provide legal opinions, contract drafting or representation. Where a question turns on interpretation of law, it belongs with your lawyers, and we work alongside them.