Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Tuesday, September 01, 2026

Mercedes-Benz Deadline 2026: ISO 27001 or TISAX Certification Required by September 30


Europe's automotive supply chain has spent a decade tightening its grip on data security, and the next milestone has a hard date attached to it. Mercedes-Benz has confirmed that its dealer and supplier network must demonstrate a certified information security programme either ISO 27001 or TISAX Level 2 by September 30, 2026. For anyone connected to the Mercedes-Benz ecosystem, this is no longer a "nice to have." It is a contractual condition of staying in business with one of the world's most recognisable car makers.

If that sentence made your compliance team sit up a little straighter, good. It should. Let's unpack exactly what is changing, why it matters so much to European suppliers and dealers, and how to get certification-ready before the clock runs out.

Why Mercedes-Benz Is Tightening the Screws on Cybersecurity

The automotive industry has learned some hard lessons about supply chain risk. The 2024 CDK Global ransomware incident, which knocked more than 15,000 dealerships offline across North America, is the case study every OEM security team now references. Attackers rarely go straight for a manufacturer's own network they look for the weakest link, often a smaller partner with looser controls, and use that as a launchpad into the parent company's systems.

Mercedes-Benz's response mirrors what German OEMs have been doing for years through TISAX (Trusted Information Security Assessment Exchange), the automotive industry's shared assessment framework built by the VDA (German Association of the Automotive Industry) and operated by the ENX Association. TISAX already underpins security expectations across Volkswagen Group, BMW, Audi, Porsche and their extended supplier base, and Mercedes-Benz is now applying that same logic verified, independent proof of security — to its own network rather than accepting self-attestations.

What the September 30, 2026 Requirement Actually Says

Mercedes-Benz is not mandating a single rigid path. Organisations in scope can satisfy the requirement in one of two recognised ways:

  • ISO/IEC 27001 certification — the internationally recognised standard for building and operating an Information Security Management System (ISMS), applicable across any industry.
  • TISAX Assessment Level 2 (AL2) — the automotive-specific assessment run through the ENX portal, built on the VDA-ISA control catalogue, which itself draws heavily on ISO 27001/27002 principles with automotive-specific additions such as prototype protection and connected-vehicle data handling.

Either path counts as evidence of a "qualified information security programme." What no longer counts is a checklist, a vendor questionnaire filled out by an internal team, or software that claims compliance without an independent audit trail. The deadline applies at an organisational level, and Mercedes-Benz — like Stellantis, which has set an identical September 30, 2026 deadline for its own supplier base — expects the certificate or TISAX label to be in hand, not "in progress," by that date.

Why This Matters More for European Suppliers Than It Might Seem

It's tempting to read "Mercedes-Benz dealer network" and assume this is a North American story. It isn't, not really. TISAX itself is a distinctly European mechanism, born in Germany and already deeply embedded in the operations of Mercedes-Benz, BMW, Volkswagen, Audi and Porsche's European supply chains. What is happening now is the same discipline being extended further down the chain and applied with a hard, enforced deadline rather than a soft recommendation.

For European Tier 1 and Tier 2 suppliers, marketing agencies handling prototype imagery, logistics partners, and IT service providers touching Mercedes-Benz data anywhere in the value chain, this is a signal worth reading closely: the era of "we'll get to it eventually" is over. Contracts are increasingly being written with certification as a condition precedent, not a follow-up item.

Quick fact: TISAX was established by the VDA in 2017 and is operated by the ENX Association, letting a supplier complete a single assessment and reuse the resulting label across multiple OEM relationships — instead of repeating the audit for every customer.

ISO 27001 or TISAX — Which Should You Choose?

This is the question every compliance lead is currently wrestling with, and the honest answer is: it depends on who you sell to.

  • If your relationships extend beyond the automotive sector — to finance, healthcare, SaaS customers, or public sector contracts — ISO 27001 gives you a globally recognised certificate that opens doors well beyond Mercedes-Benz.
  • If your business is automotive-specific and you already work with, or hope to work with, multiple German OEMs, TISAX lets you complete one assessment and share the resulting label across Mercedes-Benz, BMW, VW Group and others through the ENX portal — avoiding repeated audits for each relationship.
  • Many organisations that already hold ISO 27001 find that TISAX readiness moves noticeably faster, since the risk assessment methodology, policies and core Annex A controls are already built and operating.

Timelines matter here too. Starting from scratch, most organisations need anywhere from four to twelve months to reach a TISAX label or ISO 27001 certificate, with the assessment itself typically booked weeks in advance. With September 30, 2026 on the calendar, the realistic window to start a programme from zero and still land the certification comfortably before the deadline is closing fast.

Getting Certification-Ready Without the Guesswork

The path to either certification generally follows the same shape: a gap assessment against the relevant control catalogue (ISO 27001 Annex A or VDA-ISA), remediation of the gaps that surface, implementation of documented policies and evidence trails, and finally the formal audit through an accredited certification body or an ENX-accredited TISAX audit provider.

Organisations that try to run this entirely in-house often underestimate how much evidence collection and internal alignment it takes to pass a Stage 1/Stage 2 ISO 27001 audit, or a TISAX AL2 assessment, on the first attempt. That is exactly the gap that specialist advisory firms exist to close. VISTA InfoSec's ISO 27001 Advisory & Certification service works alongside internal teams to design the ISMS, run the risk assessment, and prepare for Stage 1 and Stage 2 audits without forcing a generic template onto your business. For organisations that sell specifically into the German and European automotive supply chain, VISTA InfoSec's TISAX Audit & Certification practice in Germany runs VDA-ISA gap assessments, scopes the correct assessment level, and manages ENX portal registration end to end.

If you're still weighing which certification actually fits your business model, this detailed breakdown of TISAX vs ISO 27001 for automotive suppliers is a useful next read it compares governing bodies, scope, cost drivers and typical timelines side by side.


The Bottom Line

September 30, 2026 is not a soft target it's a contractual deadline set by one of the automotive world's most demanding customers, echoed almost identically by Stellantis. Whether your organisation ultimately pursues ISO 27001 or TISAX Level 2, the underlying message from Mercedes-Benz is the same one German OEMs have been sending their supply chains for years: prove it, don't just promise it. Suppliers and dealers who start their gap assessment now will spend 2026 building a defensible security programme. Those who wait may find themselves racing an audit calendar that has already filled up.

Need to know exactly where your organisation stands before September 30, 2026?

Talk to VISTA InfoSec →

Tuesday, May 05, 2026

Hackers Have Upgraded to AI — Has Your Business? Why Traditional Cyber-security Is No Longer Enough in 2026

AI-powered cyberattacks threatening businesses in 2026 - cybersecurity consulting


Picture this: You receive an urgent voice message from your CEO asking you to wire $250,000 to a vendor account before end of day. The voice sounds exactly right the tone, the accent, the urgency, the phrasing. You've spoken to this person hundreds of times. Everything checks out. You make the transfer.


Except your CEO never made that call.


Welcome to the most dangerous cyber-security landscape businesses have ever faced one powered not by a lone genius hacker, but by artificial intelligence that clones voices in seconds, forges identities flawlessly, writes perfect phishing emails, and probes your entire network for weaknesses faster than any human security team can respond.


If your cyber-security strategy was designed even two or three years ago, you are not prepared for what 2026 looks like. And that gap is precisely what cyber-criminals are counting on.

 

The AI Arms Race Your IT Team Is Already Losing

Artificial intelligence has reshaped every industry on the planet and cybercrime is no exception. The same technology powering your recommendation engine, your content tools, and your workflow automation has been weaponized at massive scale by threat actors across the globe. Here's what that looks like on the ground in 2026:


AI-Generated Phishing That Fools Everyone

The phishing email of 2020 was easy to catch bad grammar, generic greetings, suspicious links. The phishing email of 2026 is a different beast entirely. AI tools now crawl a target's LinkedIn activity, company press releases, internal communication patterns, and public social media to craft hyper-personalized messages that are virtually indistinguishable from legitimate ones. Security awareness training built around "spotting typos" is now dangerously outdated.


Deepfake Voice and Video Fraud at Scale

What began as an experimental threat a few years ago has matured into a full-blown enterprise criminal tool. Deepfake audio and video technology has advanced to the point where real-time impersonation of executives, clients, and vendors is accessible to even low-budget attackers. In 2026, finance teams, HR departments, and C-suite assistants are among the most targeted and most vulnerable employees in any organization because they hold authority over money and sensitive data.


Automated Vulnerability Discovery Running 24/7

Human hackers work in shifts. AI-powered attack tools don't sleep. In 2026, threat actors deploy autonomous scanning systems that continuously probe internet-facing assets, cloud environments, APIs, and misconfigured endpoints around the clock identifying exploitable weaknesses in minutes and moving to active exploitation within hours. The window your team must patch and respond has never been narrower.


Self-Mutating Malware That Learns Your Defenses

Traditional antivirus tools work by recognizing known attack signatures. Today's AI-driven malware is specifically engineered to defeat this by rewriting its own code in real time learning from each defensive response it encounters and adapting accordingly. It is, in the most literal sense, malware that studies your defenses and evolves to defeat them. No signature library can keep up.

 

Why This Fundamentally Changes the Equation for Businesses

The cybersecurity approach that worked in 2021 or 2022 the right tools, annual audits, a compliance certificate on the wall is no longer sufficient. Not because those things don't matter, but because the speed, sophistication, and scale of the threat have outpaced them entirely.


Consider where things stand in 2026: Global cybercrime damages have crossed the $10.5 trillion annual threshold that analysts predicted, with AI being the single biggest accelerator of both attack volume and attack success rates. More alarmingly, small and mid-size businesses now account for a disproportionately large share of successful breaches not because they hold the most valuable data, but because they present the path of least resistance while still holding payment records, health data, customer information, and intellectual property that criminals can monetize.


Financial services firms carry payment and transaction data. Healthcare organizations hold protected patient records. Retail businesses process cardholder information daily. Every one of these represents a high-value target and AI has made it faster and cheaper than ever before to exploit them at scale.

 

What a Modern Defense Actually Requires in 2026

This is not a call to panic. It is a very urgent call to evolve. Businesses that update their security posture proactively now will be in a fundamentally stronger position than those that wait for a breach to force the conversation. Here is what genuine protection looks like today:


Penetration Testing That Simulates 2026-Era Attacks

If your last penetration test didn't include AI-assisted attack simulations, social engineering scenarios, or cloud environment exploitation, its results may already be obsolete. Modern penetration testing goes far beyond automated scanning it replicates the actual tools, tactics, and techniques threat actors are using right now, giving you an honest answer about how far an attacker could get inside your environment before being stopped.


Continuous Vulnerability Assessment — Not Annual Snapshots

Scheduling vulnerability scans once or twice a year made sense when threats evolved slowly. In 2026, new vulnerabilities are discovered, disclosed, and actively exploited within days. Continuous vulnerability assessment has become a foundational requirement the difference between knowing about a weakness before attackers do and finding out about it in a breach notification.


Zero Trust — Because Perimeter Security Is Dead

The old model assumed that anything inside your network could be trusted. Zero Trust assumes the opposite every user, device, and application must be verified continuously, regardless of where they connect from. In a world where credentials are stolen through AI-generated phishing and identities are spoofed through deepfakes, Zero Trust architecture is no longer a sophisticated upgrade. It is table stakes.


Security Awareness Training Rebuilt for Today's Threats

Your employees remain the most targeted entry point in your entire organization. But they need to be trained on what attacks look like in 2026 AI-crafted emails, real-time voice cloning calls, deepfake video meetings, and multi-stage social engineering campaigns that unfold over days or weeks. Training content that hasn't been refreshed for the AI era is creating false confidence, not genuine resilience.


Integrated Compliance and Security Governance

Regulatory frameworks including GDPR, HIPAA, PCI DSS, ISO 27001, and SOC 2 are actively evolving to address AI-related risks, data governance obligations, and breach notification requirements. Managing these overlapping and shifting obligations while simultaneously hardening your actual security posture demands deep, cross-framework expertise. Partnering with a specialist cybersecurity consulting firm ensures your compliance program and your security strategy move forward together not in opposite directions.

 

The Question Every Business Leader Must Answer Today

It is no longer "Will we be targeted?" in 2026, that question has essentially been answered for every business that holds data of any value. The only question that matters now is: "When an attack comes, how far will they get?"


That answer depends entirely on the decisions you make before the attack arrives. The organizations that will navigate this AI-powered threat landscape successfully are those investing in intelligent, proactive, and continuously evolving security programs today not those scrambling to respond to breach notifications tomorrow.


AI has permanently rewritten the rules of cybersecurity. The businesses that acknowledge this reality, partner with the right expertise, and build defenses that match the sophistication of modern threats will be the ones still standing and still trusted by their customers in the years ahead.


The rest will become the cautionary case studies that everyone else learns from.

 

Wondering whether your current security posture is genuinely equipped for AI-driven threats in 2026? A thorough security assessment from an experienced cybersecurity consulting team gives you the honest picture and the roadmap to fix what needs fixing before an attacker finds it first.

Monday, April 27, 2026

You Passed the Compliance Audit — But Is Your Business Actually Secure? Here's the Truth, Nobody Tells You




Every year, thousands of businesses celebrate passing their compliance audits. The certificates get framed, the emails go out to stakeholders, and the team breathes a collective sigh of relief. But here's the question no one seems to ask after the confetti settles:

Does passing a compliance audit mean your business is secure?

Spoiler: Not always. And understanding the difference between compliance and security could be the single most important cyber-security lesson your organization ever learns.

 

The Audit Illusion: Why "Compliant" Doesn't Always Mean "Safe"

Compliance frameworks whether it's PCI DSS, HIPAA, SOC 2, or ISO 27001 are built on a snapshot model. An auditor reviews your controls, policies, and configurations at a specific point in time. You pass. You're certified. Everyone moves on.

But cybercriminals don't operate on a 12-month cycle. Threat actors evolve daily. A vulnerability discovered the day after your audit? That's your problem to solve and your compliance certificate won't shield you.

This is what security professionals call the Compliance-Security Gap the dangerous space between what a regulatory framework requires you to do and what your organization needs to do to stay truly protected.

Consider this: According to industry reports, a significant number of organizations that suffered major data breaches were fully compliant with industry standards just months before the incident. Compliance gave them a false sense of security. And it cost them dearly in millions of dollars, lost customer trust, and regulatory penalties.

 

So, What Does True Cybersecurity Look Like?

Real security is continuous, proactive, and adaptive. It isn't a checkbox exercise it's a living program. Here are the key pillars that separate organizations that are merely compliant from those that are genuinely secure:

1. Continuous Vulnerability Assessment & Penetration Testing

Compliance frameworks often require periodic vulnerability scans, but "periodic" isn't enough in today's threat landscape. Organizations that are truly secure conduct penetrationtesting far more rigorously and frequently simulating real-world attacks across their network, applications, and cloud environments before hackers do.

Think of it like a fire drill versus an actual fire. Compliance says, "have a plan." Security says, "test the plan repeatedly, identify its flaws, and fix them before disaster strikes."

2. A Security Strategy That Outlives the Audit

Most compliance programs are built around the audit cycle, not beyond it. A mature organization embeds security into its DNA its culture, its development lifecycle, its vendor relationships, and its leadership decision-making.

This is where the role of a Chief Information Security Officer (CISO) becomes critical. For many smalls to mid-sized businesses, hiring a full-time CISO isn't financially viable. But operating without that strategic security leadership is a gamble no business can afford.

3. Multi-Framework Compliance: The Reality of Modern Business

Here's another hard truth: most businesses don't operate under a single compliance framework. A healthcare SaaS company might need to meet HIPAA, SOC 2, and GDPR simultaneously. A fintech startup handling card payments may need PCI DSS certification and ISO 27001 accreditation.

Managing multiple overlapping frameworks is complex, resource-intensive, and riddled with gaps that individual compliance teams frequently miss. That's not a criticism it's simply the nature of the beast. Organizations that try to manage multi-framework compliance in-house, without seasoned experts, often end up paying far more in remediation costs and audit failures than they would have by engaging a specialist from the start.

 

The Hidden Costs Your CFO Needs to See

Here's where the numbers become impossible to ignore. The global average cost of a data breach in 2024 reached $4.88 million an all-time high. For businesses operating in highly regulated sectors like healthcare, financial services, and retail, the fines alone from non-compliance can be crippling, let alone reputational damage, customer churn, and litigation.

Compare that to the cost of proactive, expert-led cybersecuritycompliance consulting and the math becomes very clear, very quickly.

The companies that fare best in today's threat environment aren't the ones with the most certificates on the wall. They're the ones that treat compliance as the floor, not the ceiling, of their security posture.

 

Bridging the Gap: What Your Business Should Do Right Now

If you've read this far, you're already ahead of most. Here's a practical starting point:

Audit your audit. Review your most recent compliance assessment and identify areas that were borderline passes. Those are your highest-risk zones.

Test your defences. Commission a penetration test that goes beyond what your compliance framework mandates. You want to know what an attacker could find before they do.

Get strategic leadership. If you don't have a dedicated CISO, explore virtual CISO or advisory services that bring enterprise-grade strategic thinking to your security program at a fraction of the cost.

Think multi-framework. If your business is subject to more than one regulatory standard, work with a consulting partner that has proven experience across GDPR, HIPAA, SOC 2, PCI DSS, and ISO 27001 simultaneously.

 

Final Thought: Compliance Is the Beginning, Not the End

A compliance audit is a valuable tool but it's one tool in a much larger toolbox. The organizations that truly protect themselves, their customers, and their future are the ones that go beyond the audit and build security into everything they do.

If your business is ready to move from reactive compliance to proactive security, you don't have to figure it out alone. Partnering with an experienced, globally recognized informationsecurity consulting firm is the smartest investment a business can make in 2025 and beyond

Monday, October 23, 2023

SOC 1 vs. SOC 2: Choosing the Right Audit for Your Business

 In the world of data security and compliance, SOC reports play a vital role in ensuring trust and transparency between organizations and their clients. Two commonly discussed reports in this domain are SOC 1 and SOC 2. Understanding the differences and knowing which one is right for your business is crucial. In this article, we'll explore the distinctions between SOC 1 and SOC 2 and help you make an informed decision.

What Are SOC 1 and SOC 2 Reports?

SOC 1 and SOC 2 reports are both part of the System and Organization Controls (SOC) framework, developed by the American Institute of CPAs (AICPA). These reports provide valuable information about a service organization's control environment.

SOC 1 Report

A SOC 1 report is focused on internal controls over financial reporting. It is essential for organizations that provide services that could impact their clients' financial statements, such as payroll processing, financial data hosting, or investment management.

The SOC 1 report comes in two types:

  • SOC 1 Type I Report: This report evaluates the design of controls at a specific point in time.
  • SOC 1 Type II Report: This report assesses both the design and operational effectiveness of controls over a specified period, typically at least six months.

SOC 2 Report

A SOC 2 report, on the other hand, focuses on controls relevant to security, availability, processing integrity, confidentiality, and privacy of customer data. This report is essential for any organization that provides services involving customer data, such as cloud service providers, data centers, and Software as a Service (SaaS) companies.

The SOC 2 report also comes in two types:

  • SOC 2 Type I Report: Similar to the SOC 1 Type I, it evaluates the design of controls at a specific point in time.
  • SOC 2 Type II Report: It assesses both design and operational effectiveness of controls, but in the context of security, availability, processing integrity, confidentiality, and privacy.

Key Differences Between SOC 1 and SOC 2

  1. Scope: The primary difference is the scope of the reports. SOC 1 is for controls that impact financial reporting, while SOC 2 is for controls related to the security, availability, processing integrity, confidentiality, and privacy of customer data.

  2. Audience: SOC 1 reports are generally for external auditors and clients concerned with financial reporting. SOC 2 reports are more focused on technology and data security, appealing to a broader range of industries.

  3. Applicability: Consider your business's services. If you provide payroll processing, financial statement hosting, or investment management, SOC 1 is likely more relevant. If you deal with customer data or are a technology service provider, SOC 2 is the way to go.

  4. Type I vs. Type II: The choice between Type I and Type II reports should be based on the depth of assurance your clients or stakeholders require. Type II reports offer more comprehensive assurance as they cover a period of operational effectiveness.

  5. Control Objectives: SOC 1 focuses on control objectives related to financial reporting. SOC 2 focuses on control objectives related to security, availability, processing integrity, confidentiality, and privacy.

Choosing the Right Audit for Your Business

To choose the right audit for your business, consider the following steps:

  1. Identify Your Objectives: Understand your business goals, client expectations, and regulatory requirements. This will help you determine whether financial controls or data security controls are a higher priority.

  2. Know Your Audience: Consider who will be using the report. If it's primarily clients concerned with financial reporting, SOC 1 is the choice. If you have a broader client base with data security concerns, SOC 2 may be more suitable.

  3. Assess Your Services: Examine the services you provide. Are they financial in nature or do they involve customer data? This will drive your decision.

  4. Type I or Type II: Decide if you need a Type I or Type II report based on the depth of assurance required.

  5. Consult with Experts: If you're unsure about which audit is right for your business, consider consulting with auditors or compliance experts who can provide guidance tailored to your specific situation.

In conclusion, while SOC 1 and SOC 2 reports both play vital roles in ensuring trust and transparency, the choice between them comes down to the nature of your services, your audience, and your control objectives. By making an informed decision, you can demonstrate your commitment to safeguarding the interests of your clients and stakeholders, whether it's in the realm of financial reporting or data security.

Remember that regardless of your choice, obtaining a SOC report demonstrates your dedication to maintaining effective controls, a valuable asset in today's business landscape.

Monday, August 21, 2023

Understanding SOC 2 Audit and Attestation: Enhancing Trust in Service Organizations

 


In an era where businesses heavily rely on third-party service providers to manage their critical operations, the assurance of data security, privacy, and operational integrity becomes paramount. This is where SOC 2 audits and attestations come into play. SOC 2, which stands for Service Organization Control 2, is a framework designed to evaluate and attest to the operational effectiveness of controls within service organizations. This article delves into the concept of SOC 2 audit and attestation, highlighting its significance, key components, and benefits for both service providers and their clients.

**1. Understanding SOC 2: A Brief Overview

1.1 Defining SOC 2

SOC 2 is a widely recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It specifically focuses on the security, availability, processing integrity, confidentiality, and privacy of data within service organizations. The framework provides a set of criteria against which service providers' internal controls are evaluated.

1.2 The Five Trust Services Categories

The SOC 2 framework is built upon five trust services categories, often referred to as the "Trust Services Criteria":

  1. Security: Ensuring protection against unauthorized access and data breaches.
  2. Availability: Ensuring systems and data are available for operation as agreed upon.
  3. Processing Integrity: Ensuring accurate, complete, and timely processing of data.
  4. Confidentiality: Protecting sensitive information from unauthorized access.
  5. Privacy: Collecting, using, retaining, and disclosing personal information in accordance with established privacy principles.

2. The SOC 2 Audit Process

2.1 Engagement and Scope Definition

The SOC 2 audit process begins with an engagement between the service organization and an independent audit firm. The scope of the audit is determined, focusing on the specific systems, processes, and controls that are relevant to the trust services categories.

2.2 Control Evaluation

The audit firm assesses the design and implementation of controls within the service organization. These controls are evaluated based on how effectively they meet the criteria outlined in the selected trust services categories.

2.3 Testing and Evidence Gathering

To verify the operational effectiveness of controls, the audit firm conducts testing and gathers evidence. This may involve examining documentation, conducting interviews, and performing technical assessments.

2.4 Reporting

Upon completion of the audit, the audit firm produces a SOC 2 report. There are two main types of SOC 2 reports:

  1. Type I Report: Focuses on the design of controls at a specific point in time.
  2. Type II Report: Assesses the operational effectiveness of controls over a defined period, usually six to twelve months.

3. The Significance of SOC 2 Audit and Attestation

3.1 Building Client Trust

Service organizations that undergo SOC 2 audits and attain attestation demonstrate their commitment to data security and operational integrity. This builds trust with existing and potential clients, giving them confidence that their sensitive information is handled with care.

3.2 Regulatory Compliance

For service providers handling sensitive data, SOC 2 audits can assist in meeting various regulatory compliance requirements, such as GDPR, HIPAA, and more.

3.3 Competitive Advantage

Having a SOC 2 attestation can provide a competitive edge in the market. It distinguishes a service organization as one that takes data security and privacy seriously.

4. Conclusion

In an interconnected business landscape, the assurance of secure and reliable services is paramount. SOC 2 audits and attestations offer a comprehensive framework for evaluating and assuring the controls that service organizations implement. By adhering to the Trust Services Criteria and obtaining a SOC 2 report, service providers can instill trust, enhance compliance, and gain a competitive advantage in an increasingly data-conscious world.

DORA TLPT Explained: Threat-Led Penetration Testing Deadline Is 2028, But Procurement Must Start in 2026

17 January 2028 sounds a long way off. For any EU financial entity designated for DORA TLPT (Threat-Led Penetration Testing), it isn't...