By Jaap van Duijvenbode
Co-Founder and VP Product Strategy & Customer Experience
Summary: NIS2 and DORA push organizations to prove they can protect and recover critical data and manage third-party risk. For long-term data, restoring the files is only part of resilience. The information must also remain accessible, trustworthy, governed and usable, including by AI, for as long as it must be kept.
A compliance stack built around resilience
European organizations now operate under an interlocking set of rules. NIS2 sets cybersecurity and incident reporting obligations for essential and important entities in sectors including energy, transport, health, digital infrastructure and manufacturing. DORA, applicable since January 2025, requires financial entities to manage ICT risk, test operational resilience and oversee critical third-party providers. The EU Data Act adds switching and portability rights for cloud services.
Most resilience programs built in response focus on recent, operational data: the systems that must be back online within hours after an incident. Long-term data receives less attention, even though it often carries the longest legal obligations.
The overlooked layer
Archives, project records, regulatory submissions and historical transactions may need to be kept for ten, twenty or more years. Over that period, several things go wrong quietly:
- Media and formats age, and restore tests are rarely run on the oldest data.
- Immutability is assumed but not verified, leaving archives exposed to ransomware that targets backups first.
- Archive platforms become concentration risks, supplied by a single vendor with no tested exit path.
- Permissions and metadata are lost during migrations, so data survives but nobody knows who may see it.
- Integrity: immutable storage and verifiable copies, so records can be proven untampered years later.
- Isolation: long-term copies separated from production identities and networks.
- Portability: open formats and contracts that allow data to move without losing content, metadata or permissions, reinforced by the Data Act's switching rules.
- Accessibility: information remains findable and understandable by people who were not there when it was created.
- Governed AI use: when AI assistants draw on long-term data, they do so with original access controls enforced and every retrieval logged.
Each of these is a resilience failure, even if the bytes are intact.
Resilient data or resilient knowledge?
A restorable archive that nobody can search, verify or use is resilient only in the narrowest sense. The more useful test is broader: can the organization continue to access, trust, govern and use this information, and make it safely available to AI, throughout its required lifetime?
That test changes what resilience planning covers:
Beyond the minimum
NIS2 and DORA do not require that archives be usable by AI. They set a floor for protection, recovery and third-party oversight. But the investment needed to meet that floor for long-term data, in integrity, isolation and portability, is the same investment that keeps information valuable. Organizations that plan for usable knowledge rather than restorable files get both compliance and a return on data they are obliged to keep anyway.
Want to review the resilience of your long-term data? Talk to our specialists.
Sources