Zero Trust Implementation: Best Practices and Lessons Learned
Zero Trust in Practice: US audits offer organizations clear lessons on network segmentation, data protection, legacy systems, and identity management.

NIS-2 and DORA are reshaping cybersecurity and operational resilience requirements across Europe. From risk management and incident reporting to access control, business continuity, and third-party risk, both frameworks are prompting organizations to take a closer look at how their IT environments are secured and managed.
With the rollout of NIS-2 and DORA (the Digital Operational Resilience Act), he European Union has significantly strengthened cybersecurity and operational resilience requirements for organizations across critical sectors. The impact extends beyond regulatory compliance: organizations need to assess how they manage cyber risk, protect critical systems, respond to incidents, maintain business continuity, and manage risks introduced by third parties. For IT and security teams, this means taking a closer look at existing processes and infrastructure — from network architecture and access controls to monitoring, incident response, and secure remote access.
Start by using the BSI’s NIS-2 Applicability Assessment to see if your business falls into one of the 18 covered sectors.
Because NIS-2 is an EU Directive, member states translate it into domestic law individually. In Germany, for example, the implementation act took effect on December 6, 2025. However, adoption on the ground remains an ongoing process, and many businesses have lagged behind official registration deadlines. Many companies have not yet registered, even though the deadline has already passed.
DORA works differently: As an EU Regulation — much like the GDPR — it took effect automatically across all member states on January 17, 2025, without requiring separate national legislation. For the financial industry, compliance became mandatory overnight.
Relying on a single perimeter fence around an open network is no longer viable. Both frameworks expect organizations to adopt micro-segmentation. By separating office workstations, operational technology (OT), and core databases, IT teams can contain an intrusion immediately. Even if a user account is compromised, the attacker cannot pivot freely across the entire enterprise.
At the same time, teams must ensure complete visibility into system activity. IT departments must record every relevant security event — whether it originates inside the office or comes through remote VPN tunnels.
When a breach happens, teams cannot afford confusion. Both regulations mandate written, battle-tested response plans detailing who triages alerts, who investigates the root cause, and how to quarantine affected systems in real time.
The design of your network and remote access tools directly influences how fast your team can react. In addition, organizations must maintain proven backup and recovery procedures to restore operations quickly.
Crucially, cybersecurity is now a boardroom responsibility. Senior leaders and executive boards must personally review and approve risk policies. Under NIS-2, leadership can face personal liability for material oversights. If an incident does occur, thorough operational records are your best proof of due diligence.
Internal controls alone are not enough. Third-party contractors, software vendors, and cloud providers can introduce dangerous blind spots, as recent high-profile supply chain incidents have shown.
Organizations must vet their suppliers carefully: What security baselines do vendors maintain? How quickly do they notify partners when an issue occurs? If a critical vendor suffers an outage, how will it disrupt your core business?
Adapting to NIS-2 and DORA starts with an honest look at your current posture: How severely would a sudden network outage affect your customers? What is the true business cost of a data breach? Where are your current blind spots in identity and access?
Effective compliance is rarely achieved through isolated tools. Instead, it relies on the smooth coordination of network segmentation, thorough logging, rapid incident handling, and third-party oversight. Centralized, secure VPN platforms provide a reliable foundation to help teams meet these requirements efficiently while keeping daily operations running smoothly.
What penalties apply for noncompliance with NIS-2 or DORA?
Under the German implementation of NIS-2, fines for essential entities can reach up to €10 million or 2% of global annual turnover, whichever is higher. For important entities, penalties reach up to €7 million or 1.4%. Under DORA, individual national regulators have the authority to impose administrative penalties and operational sanctions.
Are small and medium-sized businesses exempt from NIS-2?
NIS-2 generally exempts micro and small businesses that employ fewer than 50 people and report annual revenue under €10 million However, exceptions apply regardless of size to specialized providers that play critical digital roles, such as DNS providers, trust service partners, and public telecommunications networks.
How does an ISO 27001 certification relate to these frameworks?
While neither regulation explicitly requires ISO-27001 certification, maintaining a certified Information Security Management System (ISMS) satisfies many core requirements around documentation and risk assessment. However, organizations must still ensure they address framework-specific mandates, such as strict incident notification windows and specialized network controls.
Do financial institutions have to comply with both NIS-2 and DORA?
No. DORA serves as a specialized rule (lex specialis) for the financial sector and takes precedence over general NIS-2 provisions. Regulated financial entities follow DORA as their primary cybersecurity framework
Can an existing VPN help achieve compliance?
Yes. A centrally managed VPN that provides encrypted connections, granular role-based access, and detailed session logging directly fulfills several operational requirements. To achieve full compliance, it should be paired with broader measures like network segmentation, automated alerting, and documented incident-handling policies.