Table of Contents
Outsourced GRC: How Safetech Turns NIS2 and DORA Requirements into a Real Security and Resilience Program
For a CISO, the current reality is more complicated than simply a lack of people. Security teams must simultaneously keep up with cyber threats, digital transformation, the accelerated use of artificial intelligence, and a growing volume of regulatory requirements. And the problem is not always the number of people on the team, but the unavailability of skills that the organization needs and cannot cover internally.
According to the 2026 Cybersecurity Workforce Research Report, conducted by the SANS Institute and GIAC, 60% of organizations point to skills shortages as the main cybersecurity workforce challenge, while only 40% indicate staff shortages. In addition, 95% of organizations say that industry directives and regulations influence their recruitment, and the need for specialists for new roles has increased significantly, mainly amid compliance requirements.
For organizations in Romania, the problems are exacerbating as NIS2 requirements become part of the operational reality, and for the financial sector and entities within the scope of the DORA regulation, digital operational resilience becomes a permanent responsibility. If we also consider the recent statements by key people in the management of the National Directorate of Cybersecurity, according to which “Fines for non-compliance with NIS2 are inevitable”(Ziarul Financiar, September 2026), the pressure is increasing.
In this context, building an internal team covering all the necessary governance, risk management and compliance competencies can become difficult, costly and, in some cases, impossible in a short timeframe.
This is where an important change arises: GRC should no longer be seen exclusively as an internal function, but can be built and operationalized with the help of external specialists.
GRC: from compliance documentation to organizational capacity
Governance, Risk Management & Compliance is not just about developing policies or preparing the organization for an audit. A mature GRC program creates the link between business objectives, cyber risks, management responsibilities, organizational processes and concrete security measures.
In practice, this means being able to answer some essential questions:
- Who is responsible for information security?
- What risks can affect the organization’s critical activities?
- What measures are in place to reduce these risks?
- Are the policies and procedures actually enforced?
- What happens if a critical supplier is unavailable?
- How long can the organization continue to operate in the event of an outage?
- What information should be reported to management?
- How do we demonstrate that the measures implemented are effective?
- How do we manage risks from the supply chain?
- How do we prepare the organization for a major incident?
This approach is relevant for both NIS2 and DORA, even though the two frameworks have different scopes and specific requirements.
In the case of NIS2, the focus is on, among other things, management responsibility, risk management, policies and procedures, incident management, business continuity, supply chain security and staff training.
DORA introduces a specific framework for digital operational resilience for targeted financial entities, which includes ICT risk management, incident management, resilience testing and risk monitoring associated with ICT third-party service providers.
In both situations, however, the mere existence of documents is not enough. The organization must be able to demonstrate that the processes are working and that the risks are known and managed. And this is where the GRC specialist comes in.
Regulation pressure increases just when skills are harder to find
The complexity of GRC doesn’t just come from the number of regulations. Requirements are evolving, and organizations need to constantly integrate new areas of risk. One example is artificial intelligence. According to the ICA Global GRC Survey 2025, 35,9% of respondents believe that AI governance and ethics will require the most attention in GRC in the coming years, ahead of data protection and cybersecurity, indicated by 25%.
Therefore, modern GRC no longer means just “compliance”, but means the possibility of correlating in a much more complex flow:
For an already overworked internal team, covering all these competencies can be challenging. That’s why outsourcing certain GRC functions can be a natural extension of the internal team: the organization retains control and responsibility over decisions, while benefiting from access to specialists with experience in various fields and projects.
Safetech Innovations: GRC as a service, not just as a consulting project
Safetech Innovations approaches GRC from the perspective of a function that needs to be operationalized, not just documented. The company offers consulting and outsourcing services for governance, risk management and compliance, adapted to the context of each organization. Services can be delivered as individual projects, as recurring programs or as outsourced functions, depending on the client’s maturity level and objectives.
One of the advantages of such an approach is access to complementary skills without the organization having to build a complete team of GRC specialists internally, from scratch:
• vCISO – strategic expertise when the organization needs it
A virtual CISO can take over or complete the functions specific to a CISO, in direct collaboration with management and IT and security teams.
The role may include defining and monitoring the security program, monitoring indicators, reporting to management, coordinating measures resulting from audits and evaluations, as well as aligning security policies and processes with the organization’s objectives.
For companies that do not need or cannot support a full-time CISO, the vCISO model allows access to senior expertise in a flexible model.
• Governance program – from policies to enforceable processes
A GRC program must transform security requirements into clear and enforceable rules. Safetech can support organizations in developing, reviewing, and updating security policies, standards, procedures, and instructions, as well as defining responsibilities and monitoring mechanisms. The goal is not to create a document library, but to build a governance system that the organization can apply and demonstrate in practice.
• Risk analysis – what needs to be protected and why
Risk management is one of the central components of GRC. Safetech experts can perform risk analysis for the organization, processes, systems, technologies and suppliers, identifying relevant threats and vulnerabilities and helping to define risk reduction measures. Thus, security investments can be related to the real risks of the business, not just to a generic list of controls.
• TPRM – the risk does not stop at the edge of the organization
Vendors, partners, and outsourced services can become critical components of an organization’s ecosystem. Third-Party Risk Management (TPRM) helps organizations identify and manage third-party risks, from initial assessment to ongoing monitoring.
In a context where NIS2 pays important attention to supply chain security, and DORA introduces specific requirements on risks from ICT third-party service providers, TPRM becomes an essential component of the GRC program.
• BIA – understanding the impact on the business
Business Impact Analysis answers a simple but essential question: “What happens to the organization if a critical process or system is no longer available?” BIA allows you to identify critical activities, assess the impact of outages, and prioritize getting back to normal. Without this analysis, continuity plans risk being built on assumptions.
• BCP – continuity is not improvised during the crisis
Based on the impact analysis and the identified risks, Safetech can support the development and operationalization of Business Continuity Plans, so that the organization has established in advance responsibilities, processes, scenarios and measures for maintaining or resuming critical activities. Operational continuity thus becomes part of the security program, not a document kept in a folder until the next audit.
• Security Awareness – the most effective policy is the one that is complied with
An organization may have excellent policies and advanced technical controls, but these cannot fully compensate for the lack of a security culture. Safetech includes awareness and training activities in the GRC approach, as well as periodic employee assessments. The goal is for security to become part of the organization’s daily behavior: recognizing phishing attempts, protecting information, following procedures, and understanding individual responsibility.
One GRC program, multiple compliance requirements
An important advantage of a mature GRC approach is that the organization does not have to build completely separate systems for each regulation. A coherent governance, risk, and compliance framework can simultaneously support objectives related to NIS2, DORA, ISO 27001, NIST, GDPR, or other sectoral requirements, by mapping relevant controls and processes.
Safetech recommends precisely this integrated approach: cybersecurity must be connected to the organizational GRC, so that management has a unified view of risks, controls and maturity level. Management can understand what risks exist, where the organizational vulnerabilities are, what measures have been implemented and where investments are still needed.
GRC put into practice
Safetech’s experience in GRC services is not limited to methodologies and recommendations. An example is the project carried out for Profi, one of the largest businesses in Romanian retail. To manage cyber risks, strengthen the framework of policies and procedures, Profi implemented a GRC (Governance, Risk Management, Compliance) project together with Safetech Innovations. The partnership led to the development of a security culture at the organizational level, to the adoption of NIST CSF (National Institute of Standards and Technology Cybersecurity Framework) best practices, to alignment with NIS2 requirements and to a measurable and scalable implementation of protection measures.
The case study, available on the page Profi, of Profi, the leader of the local retail market, mitigates risks and prepares alignment to NIS2 through a GRC project carried out with Safetech Innovations, demonstrates the practical nature of GRC: identifying risks, defining the necessary measures, structuring processes and preparing the organization for compliance requirements must happen within the business, not just in documentation.
For more information on how the GRC framework can support your process of alignment with NIS2 requirements, please contact us at [email protected] or 021 316 05 65.








