Regulatory Compliance, Risk, and Liability in the AI Security Era
Originally reported viaENISA / SecurityWeekSix months after the NIS2 Directive's enforcement deadline, the first wave of enforcement actions is emerging. Germany's BSI has issued formal warnings, France's ANSSI has conducted surprise audits of critical infrastructure operators, and the Netherlands published a binding order against a financial services provider. Meanwhile, the SEC's cyber disclosure rules have produced the first CISO-level personal liability cases in the US.
The three gaps regulators are citing most
First: incident notification timelines — NIS2 requires significant incidents to be reported within 24 hours, but most organisations lack documented procedures to notify authorities within that window. Second: supply chain security — regulators are scrutinising third-party risk management programmes. Third: business continuity testing — organisations have documented BCPs but have not tested them within the required 12-month cycle.
Where organisations are succeeding
Most NIS2-scoped organisations Furix has assessed have made solid progress on asset inventory, vulnerability management, and access control. Continuous monitoring is stronger than regulators anticipated, largely driven by SIEM investments made post-GDPR. The gap between technical capability and procedural readiness remains the defining challenge.
- Document and test your 24-hour incident notification procedure. Assign a named individual responsible for contacting your national CSIRT.
- Conduct a formal supply chain risk assessment covering your top 20 technology vendors.
- Schedule a tabletop exercise within the next 60 days if you haven't done one in the past year.
- Map your technical controls to NIS2 and DORA requirements and document evidence.
- Contact Furix to generate a compliance gap report from your existing posture data.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.