Legal expertise in cybersecurity
Bull is a leader in providing legal assistance relating to the Digital Security Act, NIS2, DORA, CRA and CER. We assist organisations at every stage; from gap analyses, regulatory mapping and the establishment of management systems, to emergency assistance in the event of cyberattacks and the handling of regulatory cases involving the Norwegian Security Authority (NSM), Nkom, the Financial Supervisory Authority of Norway and the Norwegian Data Protection Authority. We have in-depth knowledge of the personal liability of the board and management for the organisation's digital security, and provide assistance across a range of sectors, including financial institutions, telecoms operators, data centres and manufacturers of digital products.
We provide proactive advice by staying at the forefront of regulatory and technological developments, and assist with everything from contracts and supplier management to security-related due diligence in connection with business transfers. We are passionate about making the regulatory framework manageable in day-to-day operations, and hold regular courses and workshops for management teams, security officers and staff on obligations, responsibilities and practical compliance.
Our services include, among other things:
Systematic identification of discrepancies between the organisation's current security level and the requirements of the Digital Security Act, NIS2, DORA, CRA, CER and other relevant regulations.
Assessment of which security regulations apply to the organisation, either directly or through contracts with customers and suppliers who are themselves subject to these regulations.
Establishment of risk assessments and management systems for cyber and information security, including alignment with ISO 27001.
Development of procedures, templates and contingency plans to detect, classify and report security incidents to the relevant authorities (NSM, Nkom, the Financial Supervisory Authority, the Data Protection Authority, ENISA/CSIRT) within the time limits set out in the respective regulations.
Immediate legal assistance during incidents, in collaboration with technical response teams, to minimise damage, fulfil notification obligations and manage contact with authorities and affected parties.
Drafting and reviewing agreements that ensure security requirements are met throughout the supply chain, including subcontractor agreements and customer contracts.
Advice on the board's and management's duties and personal responsibilities under NIS2, the Digital Security Act and DORA, as well as training and embedding these principles at management level.
Assistance to manufacturers, importers and distributors in meeting safety requirements for products with digital elements under the Cyber Resilience Act, including certification and reporting of vulnerabilities.
Assistance with ICT risk frameworks, incident classification, digital resilience testing and requirements for ICT supplier agreements for banks, insurance companies and other financial institutions.
Advice to organisations subject to the CER, either directly or through a contract.
Assistance to providers of electronic communications and data centres regarding requirements for adequate security and contingency planning.
Assistance with regulatory matters and the handling of cases concerning administrative fines, injunctions and other sanctions imposed by the Norwegian Security Authority (NSM), Nkom, the Financial Supervisory Authority of Norway and the Norwegian Data Protection Authority.
Security-related due diligence and risk assessment as part of transaction processes, including assessment of target companies' compliance with security regulations.
Courses and workshops for management teams, security officers and staff on duties, responsibilities and practical compliance with security regulations.
