NIS2, DORA and ISO 27001 never use the words "risk register" for your internal risks, yet none of their obligations can be met without one. A walk through the actual articles.
Almost every risk programme starts in a spreadsheet. The problems appear later: no single view, no history, no supplier oversight, no alerts. Here is why they are structural, not user errors.
Every new project restarts the same analysis: the same requirements rewritten, scoring drifting between analysts, a backlog growing faster than the team. Automation changes what the job is.
Most third-party programmes stop at onboarding: one questionnaire, filed and forgotten. Regulators now expect a lifecycle. Here is what continuous supplier oversight looks like in practice.
Risk in one tool, assets in another, findings in a tracker, exceptions in a document. Each is fine alone; together they produce reconciliation work. What changes when everything references one record.
A flat third-party programme over-assesses the trivial and under-assesses the critical. Tiering is how proportionality becomes operational.
A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.