Strategic cybersecurity: frameworks, risks and compliance

La cybersecurity is no longer a department or a budget line: it’s the operational foundation on which any organisation operating in regulated sectors. I’ve been watching it evolve since the days of the MCSE in IT Security — from perimeter firewalls to AI governance — and the conclusion is always the same: trust is built with risk management that is rigorous, and lost in a single breach.

Strategic cybersecurity: governance and digital operational resilience for regulated sectors (NIS2, DORA, EU AI Act)

Security beyond technology

For years I’ve watched many organisations still treat security as a cost or a technical barrier. My approach is the opposite: strategic cybersecurity is a business enabler. It’s not just about protecting data, but about guaranteeing operational continuity in a regulated environment where an incident means fines, headlines and the loss of the supervisor’s trust.

Regulatory frameworks and compliance: NIS2, DORA, NIST and ISO 27001

For security to be effective, it must align with international standards and meet growing regulatory demands. My approach focuses on implementing and auditing the sector’s most robust frameworks:

  • Marcos NIST e ISO 27001: Implementing information security management systems (ISMS) for defence in depth and mature risk management.
  • Regulation DORA (Digital Operational Resilience Act): Specialisation in digital operational resilience, mandatory for the financial sector and its technology providers.
  • National Security Framework (ENS): Compliance for entities working with public administration in Spain, ensuring the highest protection standards are met.

NIS2: the obligation many discover too late

NIS2 is the European cybersecurity directive that most organisations are discovering with the compliance clock already ticking. It applies to medium-sized and large companies in essential sectors (energy, transport, healthcare, banking, digital infrastructure) and important ones (digital service providers, manufacturing, postal). And to their critical suppliers, which is where most of the surprises are: organisations that thought they were out of scope discover they’re in because they work with a regulated client.

My NIS2 compliance methodology always starts from an gap analysis honest — what you have, what you’re missing, what risks you’re carrying until you cover them — and ends with an implementation plan prioritised by regulatory risk, not by the vendor’s budget. I’ve developed a complete consultant’s guide to NIS2 with deadlines, scope and required measures for those who want to understand the directive before the first meeting.

AI governance: when the EU AI Act meets NIS2 and DORA

The rise of AI presents unprecedented challenges. Adopting the technology isn’t enough; it’s imperative to establish AI governance that ensures integrity, transparency and compliance with the new EU AI Act. I help organisations navigate this transition, making sure innovation doesn’t compromise ethics or corporate security.

What I bring as a security and strategy consultant

What I bring to strategic cybersecurity projects comes from thirty years combining systems administration, technology leadership and project management in banking. Four concrete capabilities:

  1. A holistic view of risk: Identifying vulnerabilities that are not only technical, but also organisational and process-related.
  2. Operational resilience: Designing secure architectures that let the company withstand and recover from incidents.
  3. Business and IT alignment: Translating security needs into measurable business objectives.
  4. Audit and continuous improvement: Constant assessment to adapt to new threats.

The most common types of engagement

  • Initial NIS2/DORA audit: gap analysis documented, with a prioritised risk map and a realistic implementation plan for your organisation.
  • Compliance programme management: leadership of the full programme (gap → design → implementation → reporting to the supervisor) on an interim basis.
  • Ongoing advisory for CTO/CISO: external judgement on a monthly retainer to validate architecture decisions, supplier contracts and incident response.
  • AI governance under the EU AI Act: classifying AI systems by risk level, an internal governance framework, and integration with NIS2/DORA if the organisation is subject to both.

After thirty years in systems and IT projects, what I see again and again is that the most expensive breaches don’t come from a sophisticated attacker: they come from a poorly documented process, an unaudited supplier or a legacy architecture nobody wants to touch. That’s why I always prioritise three things in this order: traceability, segmentation and processes. Technology comes after, and always aligned with real regulatory risk, not the sector’s latest fashion.

Security as an ongoing commitment

Security is never “finished”. In regulated sectors, threats evolve at the speed of software, regulations change every year (NIS2, DORA, EU AI Act) and the supervisor doesn’t accept improvisation. A robust cybersecurity strategy isn’t a project that closes: it’s a living system that is maintained.

What people ask me most about strategic cybersecurity

What’s the difference between NIS2, DORA and the EU AI Act?

NIS2 is the general cybersecurity directive for essential and important sectors. DORA is specific to banks and financial firms: it adds digital operational resilience requirements and reporting to the supervisor. The EU AI Act regulates artificial intelligence systems by risk level. An organisation can be subject to all three at once, and the challenge is integrating them without duplicating effort.

How do I know if NIS2 applies to my organisation?

Mainly by sector and size. If you operate in energy, transport, healthcare, banking, digital infrastructure, manufacturing or digital services, and you exceed 50 employees or €10M in turnover, you’re most likely in scope. Also if you’re a critical supplier to an organisation that is. The initial audit clarifies it within a week.

Do I need an in-house CISO or can I outsource it?

It depends on your organisation’s size and maturity. For mid-sized companies with regulatory risk, an ongoing retainer-style advisory is usually more efficient than an in-house CISO for the first 12-18 months. When operations justify it, I help profile and select the in-house CISO.

Which tools or vendors do you recommend?

None by default. Tool selection comes after the risk analysis, not before — and my judgement is never conditioned by vendor contracts. If a solution fits your regulatory context and architecture, I’ll say so; if it doesn’t, I’ll say that too.

About the consultant

Jose Enrique Ibarra is an AI Project Manager and strategic cybersecurity consultant with more than 30 years leading technology programmes in regulated environments. He helps boards and CISOs translate NIS2, DORA, NIST and ISO 27001 into an executable plan with risk metrics, auditable evidence and clear owners, aligning security with business strategy.

Jose Enrique Ibarra, autor del blog joseenrique.es

Do you need to strengthen your organisation’s strategic resilience?

If your organisation operates in a regulated sector and you need to align cybersecurity with NIS2, DORA or EU AI Act compliance, let’s talk. The first call is 30 minutes, no obligation: you tell me the challenge, I tell you whether I can help and how. A reply within 48 hours.