How prepared is your organisation when the regulator comes knocking?
This question stood at the centre of the IQ Defence workshop “Response to Regulatory Audit”, held during the TOP Imotski Security Conference, where cybersecurity and compliance professionals gathered for a hands-on tabletop exercise focused on Croatia’s implementation of the NIS2 Directive.
Designed as a realistic regulatory audit simulation, the workshop challenged participants to analyse audit findings, identify cybersecurity gaps and prepare structured responses to supervisory authorities. Through collaborative exercises and practical scenarios, participants explored how organisations can improve regulatory readiness, strengthen internal coordination and respond effectively under increasing cybersecurity compliance requirements.
The workshop highlighted the growing importance of regulatory literacy and evidence-based decision-making in today’s cybersecurity landscape. As the NIS2 Directive continues to reshape cybersecurity obligations across Europe, organisations are expected not only to implement technical security measures, but also to demonstrate accountability, preparedness and clear communication with regulators.
Participants worked through complex compliance situations that reflected real-world challenges faced by organisations operating in critical and important sectors. The exercise encouraged discussion around risk management, incident preparedness, audit documentation and organisational response strategies, while also emphasising the importance of cooperation between cybersecurity, legal and management teams.
By combining policy awareness, technical understanding and practical exercises, workshops such as “Response to Regulatory Audit” help organisations build the confidence and capabilities needed to navigate the evolving European cybersecurity regulatory framework.

For those who would like to learn more, the “Response to a Regulatory Audit” exercise, designed to develop regulatory literacy, critical assessment of audit findings, and communication with supervisory authorities in the context of Croatia’s implementation of the NIS2 Directive, can be downloaded by completing the form below.