
Advancing Cyber Europe’s Cyber Regulations Come into Force – and What It Means for US Companies
Feb 3, 2025
Chris Hale, Senior Director for Cyber and National Security Law at Cisco, and Emily Lemaire, a Financial Services Regulatory Lawyer at Covington & Burling, delve into the implications of the EU's new cybersecurity regulations. They discuss the Digital Operational Resilience Act's stringent reporting timelines and how compliance is reshaping U.S. approaches. The duo examines whether short reporting requirements might amplify risks and consider how potential billion-dollar penalties influence organizational behavior. A thought-provoking conversation on navigating compliance in a rapidly evolving regulatory landscape!
AI Snips
Chapters
Transcript
Episode notes
Compliance Pressure on ICT Vendors
- ICT vendors face rising pressure to comply with DORA's contractual obligations.
- Some smaller tech providers may need significant compliance improvements to meet DORA.
Contractual Demands on Vendors
- Financial institutions must impose strict contractual terms on ICT vendors, especially for critical functions.
- Vendors should prepare for audits, detailed service reports, and compliance with high security standards.
Bottom-Up Risk Management
- CISOs must document comprehensive risk management processes and enforce strict training and awareness.
- Escalation protocols for incident reporting need to be clearly defined and known throughout the organization.


