With NIS2, the topic of IT security is becoming mandatory for many companies for the first time. Many already know that changes are imminent — but often not what specific measures are necessary.

What is behind NIS2

The NIS2 Directive significantly expands the previous IT security requirements.

Objectives of the Directive:

  • Higher safety standards
  • Clear Responsibilities
  • Mandatory reporting requirements

Who is affected

In addition to critical infrastructures, many medium-sized companies are now also affected.

Typical areas:

  • healthcare
  • IT service provider
  • Industry
  • Public institutions

What is specifically required

Among other things, companies must:

  • Evaluate risks
  • Implement safety measures
  • Report incidents
  • Documenting processes

Where many are currently

In practice, there is often no such thing as:

  • Clear documentation
  • Structured security strategy
  • Defined responsibilities
  • Up to date technical protection

How companies should start now

A useful start consists of:

  • Current IT analysis
  • Assessment of Existing Risks
  • Prioritize key measures
  • Step-by-Step Implementation

Conclusion

NIS2 is not a one-time project, but an ongoing process.

CTA

Would you like to know whether your company is affected and what specific measures are required?

We support you with analysis, planning and implementation.

With NIS2, IT security is no longer just a technical issue — it is becoming more of a task for company management.

What is specifically required

Companies must evaluate their existing security measures in a structured manner and establish appropriate technical and organizational measures.

  • Analyze and evaluate risks regularly
  • Implement technical protective measures
  • Control access rights and identities
  • Detect and report security incidents
  • Define emergency and restart processes
  • Sensitize employees regularly
  • Consider suppliers and external service providers

Where many companies are currently

Many companies already have individual security measures in place. However, there is often a lack of a consistent concept that combines technical measures, responsibilities, documentation and regular review.

This is exactly where preparation should start: identify existing measures, identify gaps and derive a realistic action plan from them.