Art. 21(2)(b) Supports
Incident handling
Detect, analyse, contain, and respond to cybersecurity incidents.
Early external signal when credentials or documents appear on the dark web; sourced findings for analysis. Not containment or SOC tooling.
Art. 21(2)(a) Supports
Risk analysis
Policies on risk analysis and information system security.
Objective exposure evidence of what actually circulates about you and your chain — input to risk analysis beyond self-attestation.
Art. 21(2)(f) Supports
Effectiveness of measures
Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
Audit-ready monitoring reports document that supply-chain and self exposure watch is operational over time.
Art. 23 Supports
Incident reporting
Report significant incidents to competent authorities within mandated timelines.
Timestamped artefacts for the narrative and timeline. Does not file notifications.
Art. 21(2)(c) Supports
Business continuity / crisis
Business continuity, backup, disaster recovery, and crisis management.
Faster awareness of exfiltration can reduce time-to-decision. Not a BCP or backup product.