<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>zemITis blog</title><description>Expert insights on information security, regulation and data protection.</description><link>https://www.zemitis.hu/</link><language>en-GB</language><item><title>Do you need a Data Protection Officer? Seven questions</title><link>https://www.zemitis.hu/en/blog/do-you-need-a-dpo-seven-questions/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/do-you-need-a-dpo-seven-questions/</guid><description>Does your organisation need a DPO? Seven questions about GDPR appointment duties, conflicts of interest and the benefits of an outsourced specialist.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><category>Data protection</category><category>DPO</category><category>GDPR</category><category>Data Protection Officer</category><category>outsourced DPO</category></item><item><title>NIS2 in Hungary: who must appoint a security officer?</title><link>https://www.zemitis.hu/en/blog/nis2-information-security-officer-appointment/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/nis2-information-security-officer-appointment/</guid><description>Who needs an Information Security Officer under Hungarian NIS2 rules? Understand scope, duties, conflicts and the steps to an outsourced appointment.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><category>IBF</category><category>IBF</category><category>NIS2</category><category>appointment</category><category>Information Security Officer</category></item><item><title>NIS2 in 2026: audits, deadlines and your next steps</title><link>https://www.zemitis.hu/en/blog/nis2-audit-deadline-2026/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/nis2-audit-deadline-2026/</guid><description>NIS2 compliance in Hungary in 2026: the first audit deadline, scope, key controls and practical next steps for management.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>NIS2</category><category>NIS2</category><category>audit</category><category>compliance</category><category>risk management</category></item><item><title>In-house or outsourced security officer? A management guide</title><link>https://www.zemitis.hu/en/blog/in-house-or-outsourced-security-officer/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/in-house-or-outsourced-security-officer/</guid><description>When does an outsourced Information Security Officer make sense? Compare costs, expertise, availability and risk to choose the right model.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>IBF</category><category>IBF</category><category>information security</category><category>outsourcing</category><category>NIS2</category></item><item><title>ISO/IEC 27001 certification: from gap analysis to audit</title><link>https://www.zemitis.hu/en/blog/iso-27001-certification-step-by-step/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/iso-27001-certification-step-by-step/</guid><description>Understand each stage of ISMS implementation: scope, risk management, controls and internal audit, so you can approach certification with confidence.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>ISO 27001</category><category>ISO 27001</category><category>ISMS</category><category>certification</category><category>audit</category><category>risk management</category></item><item><title>DORA for financial services: the pillars of resilience</title><link>https://www.zemitis.hu/en/blog/dora-digital-operational-resilience/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/dora-digital-operational-resilience/</guid><description>Explore DORA’s five main areas, its effects on financial entities and ICT suppliers, implementation planning and the overlap with NIS2.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>DORA</category><category>DORA</category><category>financial services</category><category>resilience</category><category>ICT risk</category></item><item><title>Phishing simulations: why annual training is not enough</title><link>https://www.zemitis.hu/en/blog/phishing-simulation-programme/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/phishing-simulation-programme/</guid><description>Build a recurring phishing simulation programme that develops recognition and reporting, provides targeted learning and measures real behaviour.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>phishing</category><category>awareness</category><category>cybersecurity</category><category>security culture</category></item><item><title>Gap analysis step by step: how effective are your controls?</title><link>https://www.zemitis.hu/en/blog/gap-analysis-step-by-step/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/gap-analysis-step-by-step/</guid><description>How a gap analysis compares your current position with NIS2, ISO 27001 and DORA requirements, and turns findings into a prioritised action plan.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>Compliance</category><category>gap analysis</category><category>compliance</category><category>risk</category><category>controls</category></item><item><title>NIS2 incident reporting: deadlines and responsibilities</title><link>https://www.zemitis.hu/en/blog/nis2-incident-reporting-deadlines/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/nis2-incident-reporting-deadlines/</guid><description>When do NIS2’s 24-hour, 72-hour and one-month reporting periods start? Understand deadlines, responsibilities and the steps to prepare.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>NIS2</category><category>NIS2</category><category>incident response</category><category>reporting</category><category>deadlines</category></item><item><title>Business continuity and disaster recovery in practice</title><link>https://www.zemitis.hu/en/blog/business-continuity-and-disaster-recovery/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/business-continuity-and-disaster-recovery/</guid><description>Turn BCP and DRP documents into tested capabilities. Understand BIA, RTO and RPO, and their relationship with ISO 22301 and NIS2.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate><category>Cybersecurity</category><category>BCP</category><category>DRP</category><category>business continuity</category><category>ISO 22301</category></item><item><title>Security awareness: leadership’s role in building the culture</title><link>https://www.zemitis.hu/en/blog/security-awareness-leadership-role/</link><guid isPermaLink="true">https://www.zemitis.hu/en/blog/security-awareness-leadership-role/</guid><description>Security culture starts with leadership: consistent behaviour, targeted learning and practical oversight of NIS2 responsibilities.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>IBF</category><category>awareness</category><category>security culture</category><category>leadership</category><category>IBF</category></item></channel></rss>