Swisscom Trust Services - Trust Blog

Cybersecurity 2025: Unlock growth with DORA, NIS2, and Digital Trust

Written by Peter Amrhyn | 10/3/24 7:44 AM

Cybersecurity in 2025 will be heavily impacted by the DORA (Digital Operational Resilience Act) and the NIS2 Directive, reflecting a growing need for robust digital infrastructures and resilient cybersecurity strategies. As these regulations reshape the security landscape, they have far-reaching implications for digital trust — a crucial component for businesses operating in an increasingly digital economy. So, it’s worth looking at the most significant trends I anticipate for the upcoming year. 

1. Strengthening Operational Resilience Management


Companies must enhance their capabilities to detect, defend, and recover from cyberattacks. DORA mandates robust ICT risk management systems that cover the entire lifecycle of IT systems and include regular stress tests to assess cyber resilience. 

Financial institutions and other critical infrastructure organizations will increasingly conduct simulations of real-world cyber threats to test their ability to respond to emergencies and disruptions.

2. Enhanced Incident Reporting

DORA and NIS2 require companies to implement stricter and faster incident reporting mechanisms. Organizations must implement more efficient systems for capturing and quickly communicating cyber incidents to regulators. 

Companies must analyze and report on their cyberattack surfaces, enabling a more comprehensive understanding of potential threats. 

3. Expanded Third-Party Risk Management

NIS2 and DORA emphasize the importance of comprehensive supply chain risk management, mainly when working with IT service providers and cloud services. Mitigating risks posed by third-party vendors will become a top priority. 

Financial institutions and critical infrastructures must ensure that cloud providers are subject to rigorous security audits to meet the compliance requirements of DORA and NIS2. 

4. Automation and Artificial Intelligence (AI) in Cyber Defence

Businesses will increasingly adopt AI-based security solutions to detect and prevent real-time attacks. Automated threat response systems may become the standard to meet the rapid response requirements of modern cyber incidents. 

The growing demands of DORA and NIS2 compliance will drive the need for automated tools that continuously monitor compliance status, identify vulnerabilities, and generate reports for regulators. 

5. Increased Governance and Regulatory Pressure

NIS2 introduces higher penalties for companies that fail to implement the necessary security measures, requiring a more active role in overseeing boards and executives. With fines of up to 2% of global revenue, organizations must strengthen their efforts to adapt their security strategies, necessitating regular security reviews and adapting security protocols to meet new regulatory requirements. 

6. Greater Focus on Data Protection and Privacy

The close alignment between privacy regulations such as the GDPR and the security requirements of DORA and NIS2 will make protecting sensitive data a central component of cybersecurity. Companies will invest heavily in data protection solutions to ensure compliance with reporting obligations and security standards. 

Digital Trust through the looking glass 

The rise of cyber threats, coupled with the stricter regulatory frameworks imposed by DORA and NIS2, makes digital trust a non-negotiable element for any organization, ensuring secure digital interactions, data integrity, and robust privacy protections — all essential in today’s digital ecosystem. 

For customers and partners, digital trust translates into confidence that their sensitive information is protected and that business interactions are safe from breaches and fraud. Establishing digital trust will enable businesses to strengthen their reputation, attract more clients, and foster long-term relationships in a competitive global marketplace. 

Partnering with a Trust Service Provider 

Organizations looking to navigate the complexity of DORA and NIS2 compliance while maintaining high standards of digital trust can significantly benefit from partnering with a reliable trust service provider like Swisscom Trust Services. 

A trusted provider can offer: 

  • Seamless integration of trust services: From qualified electronic signatures to secure authentication and data encryption, trust service providers ensure that your digital processes meet the highest compliance standards. 
  • Expert guidance on compliance: Navigating regulatory frameworks like DORA and NIS2 can be daunting. A partner with deep expertise can help streamline compliance, reduce costs, and improve operational resilience.
  • Business growth through trust: A strong reputation for security and regulatory compliance can give businesses a competitive advantage, opening doors for international expansion and new opportunities. 

By aligning with a trusted partner, businesses strengthen their operational resilience and gain the tools and confidence to grow securely across borders while building and maintaining digital trust with clients, customers, and partners.