- Financial Services / Banking / FinTech
| What to learn | Why it matters |
|---|---|
| DORA | ICT risk and operational resilience |
| NIS2 | Cybersecurity requirements where applicable |
| GDPR | Customer/employee data |
| UK GDPR | UK privacy |
| ISO 27001 | Information security |
| ISO 27002 | Security controls |
| NIST CSF | Cybersecurity risk |
| NIST SP 800-53 | Detailed security controls |
| PCI DSS | Extremely important for payment/FinTech companies |
| SOC 2 | Common for technology/FinTech suppliers |
| Key skills | ICT risk, third-party risk, operational resilience, control testing, evidence, regulatory compliance, risk registers |
Best combination for you:
DORA + ISO 27001/27002 + NIST + PCI DSS + GDPR + SOC 2
2. Technology / SaaS / Cloud
| What to learn | Why it matters |
|---|---|
| SOC 2 | Very important for SaaS companies |
| ISO 27001 | Enterprise security certification |
| ISO 27002 | Control implementation |
| NIST CSF | Cybersecurity governance |
| NIST SP 800-53 | Detailed controls |
| GDPR | Customer data |
| NIS2 | Applies to certain entities/sectors |
| EU AI Act | Increasingly important for AI companies |
| Key skills | Cloud risk, vendor risk, security controls, access control, vulnerability management, incident response |
High-value combination:
ISO 27001 + SOC 2 + NIST + Cloud Security + GDPR
3. Payments / Card / FinTech
| What to learn | Why it matters |
|---|---|
| PCI DSS 4.0.1 | Core payment-card security standard |
| DORA | Financial-sector ICT resilience |
| ISO 27001/27002 | Information security |
| NIST CSF | Cybersecurity |
| NIST 800-53 | Security controls |
| GDPR | Personal/customer data |
| SOC 2 | Technology assurance |
| Key skills | Cardholder data environment, access control, logging, vulnerability management, encryption, incident response, third-party risk |
This is particularly interesting for you because you are already studying PCI DSS and DORA.
4. Insurance
| What to learn | Why it matters |
|---|---|
| DORA | Major requirement for EU financial entities |
| UK operational resilience | Important for UK financial firms |
| GDPR / UK GDPR | Large amounts of personal data |
| ISO 27001/27002 | Information security |
| NIST | Cyber risk |
| SOC 2 | Third-party technology assurance |
| Key skills | ICT risk, resilience, third-party risk, data protection, business continuity |
5. Consulting / Big 4 / GRC Consultancy
| What to learn | Why it matters |
|---|---|
| ISO 27001/27002 | Used across many clients |
| NIST CSF | Cybersecurity assessments |
| NIST 800-53 | Control assessments |
| SOC 2 | Client assurance |
| PCI DSS | Payment clients |
| GDPR | Privacy assessments |
| DORA | Financial-services clients |
| NIS2 | EU cybersecurity clients |
| EU AI Act | AI governance clients |
| Key skills | Gap assessments, control testing, evidence, crosswalks, remediation, reporting |
Big advantage: you can work across multiple industries rather than being locked into one.
6. Healthcare / Pharmaceuticals
| What to learn | Why it matters |
|---|---|
| GDPR / UK GDPR | Patient/personal data |
| ISO 27001/27002 | Information security |
| NIST CSF | Cybersecurity |
| NIST 800-53 | Security/privacy controls |
| NIS2 | Certain healthcare entities |
| SOC 2 | Technology providers |
| Key skills | Privacy, access control, data security, incident response, third-party risk |