DORA
Finance and insurance
Banks, insurers, brokers, payment institutions and crypto-asset firms have been under DORA since January 2025 — board-level accountability, not a policy document.
WHAT MAKES THIS SECTOR DIFFERENT
Where the pressure actually comes from
DORA is unusual in naming the evidence. It expects a register of ICT third-party arrangements, contractual audit and exit rights with every provider, and threat-led penetration testing for the larger entities. Most of the work is not technical: it is proving that the arrangements you already have say what the regulation requires them to say.
WHICH RULES CATCH YOU
Start here, in this order
NIS2 / ZInfV-1
Slovenia's Information Security Act, in force since 19 June 2025, took the number of obliged organisations from roughly 100 to roughly 1,000. Risk measures, incident reporting, supply-chain security and training, supervised by URSIV.
Read more In force nowDORA
Every EU bank, insurer, broker, payment and crypto firm. ICT risk framework with the board accountable, major incidents classified and reported, a register of every ICT provider, and threat-led penetration testing.
Read more In force nowGDPR / ZVOP-2
The oldest of these and still the most enforced. ZVOP-2 has been the Slovenian implementing act since January 2023, supervised by the Informacijski pooblaščenec. A breach exposing personal data is reportable within 72 hours whether or not ZInfV-1 also catches you — one incident, two clocks, two regulators.
Read moreWHAT WE DO ABOUT IT
The three that matter most here
Chief Information Security Officer
A security executive on subscription: policy, risk register, board reporting and the evidence an auditor asks for — without a six-figure hire.
Read more PenTestPenetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more TPRMaaSThird-party risk management
Your suppliers are your attack surface, and under NIS2 they are also your legal responsibility. We inventory them, rate them and keep watching.
Read more