AIGovHub
Vendor Tracker
CCM PlatformSentinelProductsPricing
AIGovHub

The AI Compliance & Trust Stack Knowledge Engine. Helping companies become AI Act-ready.

Tools

  • AI Act Checker
  • Questionnaire Generator
  • Vendor Tracker

Resources

  • Blog
  • Guides
  • Best Tools

Company

  • About
  • Pricing
  • How We Evaluate
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Affiliate Disclosure

© 2026 AIGovHub. All rights reserved.

Some links on this site are affiliate links. See our disclosure.

Pegasus Spyware Hack on EU Parliament Signals Urgent NIS2 and DORA Compliance Needs
Pegasus spyware
NIS2
DORA
EU Parliament
Citizen Lab
state-sponsored spyware
cybersecurity compliance

Pegasus Spyware Hack on EU Parliament Signals Urgent NIS2 and DORA Compliance Needs

AIGovHub EditorialJuly 22, 20260 views

What Happened: Citizen Lab Exposes Pegasus Spyware Attack on MEP

A recent report from Citizen Lab reveals that former Member of the European Parliament (MEP) Stelios Kouloglou was repeatedly hacked with Pegasus spyware while serving on a committee investigating the abuse of commercial surveillance tools. Forensic analysis confirmed multiple attacks on his device, exposing critical security gaps within EU institutions and raising serious concerns about data privacy and cybersecurity compliance.

The incident highlights the vulnerabilities faced by individuals involved in sensitive investigations, particularly those probing state-sponsored cyber threats. Pegasus, developed by the Israeli firm NSO Group, is capable of remotely accessing a device's camera, microphone, and data, making it a potent tool for espionage.

Why It Matters: Implications for NIS2 and DORA Compliance

This attack underscores the pressing need for organizations—especially those in critical sectors—to comply with the EU's NIS2 Directive and Digital Operational Resilience Act (DORA). Both frameworks impose strict requirements to protect against advanced persistent threats like state-sponsored spyware.

NIS2 Requirements

The NIS2 Directive (EU) 2022/2555, with a member state transposition deadline of 17 October 2024, applies to essential and important entities across 18 sectors. Key obligations include:

  • Risk management measures: Implement technical and organizational measures to manage cybersecurity risks, including supply chain security for surveillance tools.
  • Incident reporting: Report significant incidents within 24 hours (early warning) and 72 hours (full notification) to competent authorities.
  • Supply chain security: Assess and mitigate risks from third-party vendors, including commercial spyware providers.

DORA Requirements

DORA (Regulation (EU) 2022/2554), applicable from 17 January 2025, mandates financial entities to:

  • Establish an ICT risk management framework that includes protection against advanced malware and spyware.
  • Conduct digital operational resilience testing, including threat-led penetration testing (TLPT).
  • Report major ICT-related incidents to competent authorities under strict timelines.

The Pegasus attack demonstrates that even high-level EU officials are not immune to state-sponsored cyber espionage. Organizations must adopt a zero-trust architecture and deploy advanced endpoint protection to detect and block such sophisticated threats.

What Organizations Should Do: Actionable Steps

  1. Implement zero-trust architecture: Assume breach and verify every access request, regardless of source.
  2. Strengthen endpoint detection and response (EDR): Deploy solutions capable of identifying and mitigating spyware like Pegasus.
  3. Enhance supply chain security: Vet all third-party vendors, especially those providing surveillance or monitoring tools.
  4. Establish incident response protocols: Ensure compliance with NIS2 and DORA reporting timelines (24h/72h).
  5. Conduct regular security audits: Use frameworks like NIST CSF 2.0 and ISO 27001 to assess readiness.

Related Resources

For a deeper dive into AI governance and cybersecurity compliance, explore our guides:

  • AI Security Alerts: European Parliament & Tech Giants
  • EU AI Act Compliance Roadmap

To stay ahead of evolving threats, leverage AIGovHub's regulatory intelligence platform for continuous compliance monitoring and risk assessment. Our tools help you map requirements across NIS2, DORA, and other frameworks, ensuring your organization is protected against state-sponsored spyware and other advanced threats.

This content is for informational purposes only and does not constitute legal advice.