Practical, sourced articles on NIS2 and DORA duties, reporting chains and how a crisis exercise actually runs: no gate, no fluff, every claim traceable.
Germany’s NIS2 act has been in force since 6 December 2025 and the registration deadline has passed. Five things managing directors and boards need to settle now: from registration to exercise evidence.
A crisis exercise from the inside: Verdus Cyber’s manufacturing scenario, with phases, injects, decision points, and what the debrief actually measures at the end.
Three regimes, one incident: the reporting clocks under NIS2 (§32 BSIG), GDPR Articles 33/34 and DORA, who must notify whom by when, and how to rehearse the chain before it counts.