Logo bconnex

Cybersecurity regulations in the EU in 2025: understanding NIS2, DORA, and ISO 27001

28 May 2025

Cybersecurity in 2025 – What’s changing and how to stay compliant 

Cyber threats are evolving, and regulations are tightening, especially in the EU. In 2025, new cybersecurity standards like NIS2 and DORA, and updates on existing ones like ISO 27001:2022 bring stricter compliance requirements for businesses across the EU. 

These regulations illustrate the European Union’s commitment to strengthening digital security and data protection, forcing businesses in various sectors to adapt to new legal obligations in the coming years.

Some companies are already well aware of these regulations; others may not have them on their radar yet, but non-compliance isn’t an option. Whether you manage IT security directly or oversee your company’s tech infrastructure, it’s crucial to understand how these frameworks impact your business and what steps you need to take. 

What’s at stake? 

  • Stronger cybersecurity requirements across multiple sectors 
  • Increased liability for businesses, including IT service providers 
  • Stricter incident reporting rules and security audits 

How can you prepare for NIS2, DORA, and 27001:2022 compliance? Discover practical steps in this article! 👇🏻

In this article :  

  1. NIS2 directive: strengthening cybersecurity for essential businesses
  1. The DORA regulation: cyber-resilience for the financial sector (and its service providers!) 
  1. ISO 27001: ISMS, a universal security foundation
  1. GDPR: still a key regulation for data protection in 2025 
  1. Cybersecurity compliance in 2025: NIS2, DORA & ISO 27001 at a glance 
  1. The importance of compliance and cyber resilience for your business 

NIS2 directive: strengthening cybersecurity for essential businesses 

Adopted in November 2022, the NIS2 Directive (Network and Information Security Directive 2) aims to strengthen cybersecurity across critical sectors, including energy, transportation, healthcare, and digital infrastructure. 

NIS2 had to be transposed into national legislation by October 2024. By March 2025, most EU member states have finalized this transposition, making the directive's requirements immediately enforceable for affected businesses. 

Companies must now comply with the new requirements, particularly in terms of risk management and incident reporting. 

What sectors are impacted by the NIS2 directive? 

  • Essential sectors: energy, transportation, healthcare, digital infrastructure, etc.
  • Important sectors: telecommunications, waste management, digital services, etc.
  • IT service providers may also be affected if they work with these industries  

Key obligations under NIS2:

  • Implementation of cybersecurity risk management measures
  • Mandatory reporting of serious incidents within 24 to 72 hours
  • Regular audits and security controls to ensure compliance of security measures 

In practical terms, the NIS2 directive advocates the integration of cyber resilience into the supply and lifecycle management of IT equipment, as well as internal awareness-raising and training to ensure proactive compliance. 

For bconnex and its brands, this also implies being compliant, in order to meet the requirements of our customers subject to NIS2, as they will also demand a high level of security from their service providers. 

💡 Key cybersecurity statistics:

  • In 2022, the Italian National Cybersecurity Agency reported 1,094 cyberattacks, a significant increase due to geopolitical tensions, particularly the Ukraine conflict 
  • In 2023, the pro-Russian group NoName057(16) conducted DDoS attacks against Dutch ports and Belgian government websites, temporarily disrupting services 

The DORA regulation: cyber-resilience for the financial sector (and its service providers!) 

Coming into force on January 17, 2025, the DORA (Digital Operational Resilience Act) regulation requires EU financial entities to implement robust risk management measures for information and communication technologies (ICT). Companies must now comply with DORA requirements to ensure their operational resilience in the face of cyber threats. 

What sectors are affected by the DORA regulation? 

  • Banks, insurance companies, fintechs, asset managers, etc.
  • IT service providers working with these entities 

Key obligations of the DORA regulation: 

  • Implementation of a strict IT risk management framework
  • Regular resilience testing to identify and correct vulnerabilities
  • Increased monitoring of IT subcontractors, including mandatory auditability

The DORA regulation thus complements the NIS2 directive, since it targets a specific sector (the financial sector) with specific requirements. Compliance with one helps prepare for the other. 

Let's not forget that the DORA regulation doesn't just concern financial institutions: their IT service providers must also align themselves with these cyber-resilience requirements. Subcontractor compliance is becoming a key criterion for contracts with banks and insurance companies. That's why at bconnex, we also make it a point to comply with DORA regulations! 

💡 Key cybersecurity statistics:

  • In February 2025, the NoName057(16) group claimed responsibility for attacks on Italian bank websites, highlighting the continuing vulnerability of the financial sector to cyber threats 
  • Nearly 50% of employees have fallen victim to a cyber-attack or scam, highlighting the need for greater operational resilience in financial institutions 

ISO 27001: ISMS, a universal security foundation 

The international standard ISO 27001, revised in 2022, provides a framework for the secure management of information systems (ISMS - Information Security Management System). Although not an EU regulation, it is widely adopted by European companies to comply with regulatory requirements, including those of DORA and NIS2. 

Organizations certified to the 2013 version have a transition period until October 2025 to migrate to the new version. 

The 27001:2022 standard applies to any organization managing sensitive data, and requires in particular:  

  • Updating controls to reflect technological developments and new threats
  • Identifying and managing cyber risks via a robust ISMS
  • Definition of clear policies and processes (access management, backups, encryption, etc.)
  • Awareness-raising and ongoing training of teams
  • Increased alignment with other standards, such as ISO/IEC 27701 (privacy management) and ISO/IEC 27018 (protection of personal data in the cloud) 

ISO 27001 also emphasizes the commitment of management and the integration of information security into the organizational culture. 

Adopting the ISO 27001 standard enables proactive management of cyber risks and ensures compliance with NIS2 and DORA requirements. Its certification is a differentiating asset for any company concerned about cybersecurity - including bconnex 😉 

💡 ISO 27001:2022 in figures:

  • According to the Global Cybersecurity Index 2024, European countries such as Portugal, Sweden and Spain scored above 99/100, reflecting strong adherence to security standards such as ISO 27001 

GDPR: still a key regulation for data protection in 2025 

Implemented in May 2018, the GDPR (General Data Protection Regulation) remains one of the world's most stringent and comprehensive data protection frameworks. While it has been in force for several years, it is far from outdated. 

With the rise of cyber threats, stricter compliance requirements, and increasing penalties, the GDPR continues to shape how businesses handle personal data. Whether companies operate within the EU or process data of EU citizens, ensuring compliance is still critical in 2025. 

Despite the growing focus on new cybersecurity regulations like NIS2 and DORA, the GDPR remains at the core of data security and privacy. Companies must continue to align their security policies, risk management, and incident response strategies with GDPR obligations to avoid costly fines and reputational damage. 

Let's not forget either that a good technical security framework (NIS2/DORA/ISO) reinforces the protection of personal data (GDPR).

💡 ISO 27001:2022 in figures:

In September 2024, Meta was fined 91 million euros for storing user passwords in clear text  

In December 2024, Meta was fined another 251 million euros for a data breach that occurred in 2018, affecting 29 million users 

Between November 2023 and January 2024, UK consumers lost over £11.5 million to online fraud, with an average loss of £695 per victim 

Cybersecurity compliance in 2025: NIS2, DORA & ISO 27001 at a glance 

Cybersecurity 2025 regulation overview table: this table summarizes the information given above in the article.

What are the objectives, the date of entry into force, and the key obligation of NIS2, DORA, ISO 27001, and GDPR? Who is affected, and what does this imply?

Conclusion: the importance of compliance and cyber resilience for your business 

Cybersecurity is becoming a strategic requirement for all sectors. The NIS2 directive and DORA regulations impose strict obligations, including on IT service providers. ISO 27001 (even in the EU) and GDPR remain essential pillars for structuring cyber resilience. 

At bconnex, we are committed to this dynamic, in particular with:  

  • Proactive compliance to guarantee the security of our customers' data and that of our own information system 
  • Continuous monitoring and adaptation to new requirements 
  • Supporting our customers in their cybersecurity initiatives 

Sources 

bconnex assists you in managing IT assets' cybersecurity 

At bconnex, we're committed to improving and securing the connected user experience. Of course, this also means supporting our customers in managing the cybersecurity of their IT assets. 

  • We're experts in cybersecurity, and can support you in your cybersecurity strategy and solutions (UEM, EMM, MDM, MTD, and EDR solutions, etc.)
  • We are specialists in solutions such as Ivanti Neurons (ex MobileIron), Microsoft Intune, Hexnode, Samsung Know Manage, WorkspaceOne, and more 
  • Bconnex is also France's first Lookout Managed Services Provider (MSP) partner, which means we can provide you with a complete Lookout managed mobile cybersecurity solution (platform configuration, services, etc.) 

Some readings for you

bconnex

Offer a single point of entry for the secure and responsible provision and management of the user work environment
Be connected
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram