Are you prepared for DORA and NIS2, the EU regulations fundamentally reshaping the cybersecurity landscape? For many organisations in the financial and critical infrastructure sectors, navigating these new frameworks presents a significant challenge, moving beyond a simple checklist to demand true operational resilience.
In this episode of Cyber Talks by Devoteam, host Rui Shantilal is joined by Ine Segers, Global Head of GRC Practice at Devoteam. Drawing on deep expertise in cybersecurity and regulation, Ine decodes the complexities of DORA and NIS2, offering a clear roadmap for turning regulatory obligations into a strategic advantage.
3 lessons you will learn from this episode
1. DORA & NIS2 are non-negotiable board-level imperatives
These aren’t just IT guidelines; they are comprehensive EU regulations that mandate a high level of cybersecurity maturity. The regulations are designed to force board-level engagement by introducing severe penalties for non-compliance, including fines up to €10 million or 2% of global turnover and personal liability for board members. This elevates cybersecurity from a technical issue to a critical business and governance priority.
2. The goal is true resilience, not just compliance
The central purpose of both DORA and NIS2 is to enhance an organisation’s digital operational resilience—its ability to withstand, respond to, and recover from cyber incidents and other operational disruptions. Simply checking a box is not enough. Organisations are required to implement robust processes for ICT risk management, incident reporting, operational testing, and third-party risk management to prove they can maintain critical functions during a crisis.
3. A strategic, centralised approach is crucial for success
Effectively implementing these regulations is a complex challenge that requires a structured, organisation-wide effort, not just an IT project. Key steps include embedding the requirements into a formal change management program, performing a gap analysis, and creating a strategic roadmap. Using a GRC (Governance, Risk, and Compliance) platform is highly recommended to centralise controls, manage policies, and facilitate audits, turning a complex web of requirements into a manageable system.
Do you prefer to listen to podcasts?
We’ve got you covered! Listen to the first episode of Cyber Talks about DORA and NIS2 on all podcast platforms.
Meet our guest
Ine Segers is Devoteam’s Global Head of GRC Practice. She leads a team of consultants and engineers who deliver innovative and tailored solutions to protect clients’ digital assets and infrastructures. Ine has been awarded the TOP 3 Leading ICT Lady 2024 #DataNews Award: She goes ICT.
Meet our host
Rui Shantilal is Devoteam’s Cyber Trust VP and has been interested in technology for as long as he can remember. He focuses on resilience-driven cybersecurity, leveraging a client-centric approach, AI and cloud security to position Devoteam as an industry leader.
Cyber Talks: Shape the future of Cybersecurity
Are you ready to explore the future of cybersecurity?
Join us on Cyber Talks by Devoteam, a videocast in which industry experts, thought leaders, and practitioners share their insights, experiences, and strategic perspectives.
Hosted by Rui Shantilal, VP of Devoteam Cyber Trust, each episode delves into key cybersecurity topics—from Offensive Security and DORA Compliance to Third-Party Risk Management and IAM. Whether you’re a seasoned security leader, a CISO navigating complex challenges, or an aspiring cybersecurity professional, this series is your
gateway to exclusive industry knowledge.
Be part of the conversation. Shape the future of cybersecurity with us. Discover all episodes here.


