
Kayne and Tom talk about DORA and its applicability. Learn where DORA applies, how you may need to be concerned about DORA even if you think you don’t and why DORA is causing confusion in US companies. Kayne and Tom try an unusual option to drink and we come close on the scoring. Reference Documents: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2554 https://hyperproof.io/resource/comprehensive-guide-dora/
Beer: Excelsior Imperial Apple by Schilling Cider House ▬ Contents of this episode ▬▬▬▬▬▬▬▬▬▬ 0:00 - Intro 0:17 - Beer background 3:39 - What is DORA? 4:10 - Does DORA affect US-based businesses? 6:53 - Why are US-based businesses confused about DORA? 9:43 - What are the key compliance requirements under DORA? 17:40 - How should US companies prepare for DORA's resilience testing requirements? 21:00 - Does DORA pose unique challenges compared to existing US cybersecurity regulations? 25:50 - Does DORA affect third-party risk management? 34:44 - What steps should US companies take to ensure compliance by the 2025 deadline? 38:03 - How does DORA interact with other EU regulations like NIS2, and what does this mean for US companies? 40:18 - Beer reviews The Drafting Compliance series: To lighten the dark corners of compliance, hosts Kayne and Tom as share with you Hyperproof's journey to becoming FedRAMP moderate, an overall roadmap to achieve FedRAMP compliance in a year, and the tips and tricks they learn along the way. As if compliance isn't fun enough, the hosts also try out a new beer each episode and rate it on a scale from 1-10.