Regulated function · NIS2, DORA and national law
Information security and cybersecurity officer for essential and important entities, financial entities and public bodies, performed externally or in support of the internal officer.
Key facts
Under Article 20 of NIS2, management bodies approve the cybersecurity risk-management measures, oversee their implementation and must follow training.
Article 21 requires appropriate and proportionate measures, including policies, incident handling, business continuity and supply-chain security.
Significant incidents require an early warning within 24 hours, a notification within 72 hours and a final report within one month.
DORA requires financial entities to assign ICT risk management to a control function with an appropriate level of independence.
NIS2 places the responsibility for cybersecurity on management bodies, but the measures it requires need someone to coordinate them day to day. National rules often give that person a formal status. Portugal's cybersecurity framework has long provided for a security officer and a permanent point of contact with the national authority, and Spain's National Security Framework (Esquema Nacional de Seguridad) requires public-sector systems to have a security officer separate from the system officer. In the financial sector, DORA assigns ICT risk to an independent control function.
governance and policy: the information security policy and an information security management system aligned with ISO/IEC 27001;
risk management: risk assessment and implementation of the Article 21 measures, proportionate to the entity;
incident response: procedures, playbooks and support in meeting the 24-hour, 72-hour and one-month reporting deadlines;
supply-chain security: security requirements for suppliers and ICT service providers;
training: cybersecurity training for management bodies and awareness for staff;
audits and evidence: internal audits, indicators and reports for the management body and the authorities;
authority liaison: coordination with the national cybersecurity authority and the CSIRT.
Where national law allows the function to be performed externally, we act as information security officer under a service contract, with a named lead professional and a deputy. Where the role must be held internally, we support the designated person with methodology, documentation, monitoring and training.
A single incident may be both a personal data breach under the GDPR and a significant incident under NIS2. We coordinate the information security officer and the Data Protection Officer so that both assessments and notifications are made on time and consistently.
Essential: governance, policy, risk register and incident procedure, with quarterly reporting;
Advanced: adds the Article 21 implementation plan, supplier security and management training;
Comprehensive: adds the management system, internal audits and authority liaison.
Fees are set in a tailored proposal, according to the size, sector and classification of the entity.
Related: Cybersecurity (NIS2) · Digital Operational Resilience · Data Protection Officer · Compliance Officer · Whistleblowing Officer
General information as at October 2026; it does not constitute legal advice.
Get a free scoping and gap analysis, or request a proposal for the officer function.