Zero Trust in banking: practical architecture for regulated environments
How to apply a Zero Trust architecture in banking step by step and why the never trust, always verify model fits with DORA and NIS2.
IT Security and Digital Privacy
Cybersecurity is no longer optional. In a world where identity dissolves among algorithms, it is a fundamental necessity. That is why here you will find practical guides on cybersecurity, data protection and digital privacy.
Understanding IT security goes beyond antivirus. It is about regaining sovereignty over your information. It also means making informed decisions in a constantly changing technological environment.
From risk management to data protection, we explore this discipline as a way of life —not just as a technical subject.
If your organisation is affected by the NIS2 directive or you need an executable strategic cybersecurity plan, that is your starting point.
How to apply a Zero Trust architecture in banking step by step and why the never trust, always verify model fits with DORA and NIS2.
What ISO 22301 is, how to move from the business continuity plan to the real drill and how it relates to DORA and NIS2 in critical sectors.
What non-human identities are, why AI agents drive up their number and how to govern their access to reduce security risk.
A comparison of the incident notification deadlines in GDPR, NIS2 and DORA and how to set up a single response process that meets all three frameworks.
What prompt injection is, how it affects generative AI applications in the enterprise and what layered defences to apply to mitigate the risk.
How I approach AI and cybersecurity consultancy in Almería for companies in regulated sectors, focusing on compliance, risk and deliverable IT projects.
How to manage the regulatory overlap between DORA, NIS2, GDPR, the EU AI Act and the ENS to comply once and demonstrate several, without duplicating effort or documentation.
What the National Security Framework (ENS) is, who it obliges, its categories and how to face the audit without paralysing the project, explained by an AI Project Manager.
NIS2 penalties 2026: amounts, real cases, the most punished mistakes and a 90-day plan to reduce your organisation’s exposure to the national authority.
Secure enterprise RAG: reference architecture, data-leak risks and EU AI Act compliance. A practical guide to taking Retrieval Augmented Generation to production without surprises.
The AI Omnibus postpones high risk to December 2027, but it does not postpone the AI asset inventory. How to build the living register and life cycle your compliance must close before August 2026.
AI cybersecurity banking DORA: why AI does not fill the cyber-expert deficit, it shifts it. An analysis of the real limit under DORA.
Utilizamos cookies propias y de terceros para analizar el uso del sitio y mejorar tu experiencia. Puedes aceptarlas todas, rechazarlas o configurarlas. Las cookies de análisis solo se activan si las aceptas.
Administre sus preferencias de cookies a continuación:
Las cookies esenciales habilitan funciones básicas y son necesarias para el correcto funcionamiento del sitio web.
Cookies que el sistema de comentarios de WordPress establece cuando un visitante deja un comentario en el blog y marca expresamente la casilla "Guardar mi nombre, correo electrónico y web en este navegador para la próxima vez que comente". Solo se establecen tras esa acción explícita del usuario; no se cargan al simplemente navegar por el sitio.
URL del servicio: joseenrique.es (opens in a new window)
Cookies necesarias para el funcionamiento del banner de cookies y para registrar las preferencias del usuario respecto a cada categoría. Gestionadas por los plugins WPConsent (banner) y WP Consent API (estándar oficial de WordPress que permite la interoperabilidad entre plugins respecto al consentimiento del usuario).
Las cookies de estadísticas recopilan información de forma anónima. Esta información nos ayuda a comprender cómo utilizan nuestro sitio web los visitantes.
Servicio de analítica web de Google Ireland Limited (ID de medición GT-PJWCNX24) integrado mediante el plugin Site Kit by Google. Recopila información de forma anonimizada sobre el tráfico del sitio para apoyar decisiones de mejora continua. Las cookies se cargan únicamente tras el consentimiento expreso del usuario, y antes de ello se aplica Google Consent Mode v2 con todos los almacenamientos en estado "denied".
URL del servicio: policies.google.com (opens in a new window)
Puede encontrar más información Política de Cookies y Privacy policy.