Wissen Sie, was in Ihrer Software steckt?

From Consultant to Consultant: How Companies Can Become NIS2-Ready Now

feature-image

From Consultant to Consultant: How Companies Can Become NIS2-Ready Now

We love our job for many reasons. One of them is the openness of the identity community. People exchange ideas, discuss best practices and work together to shake companies awake. Right now, this is urgently needed, especially with regard to NIS2. Many organizations do not consider themselves affected by the EU directive — even though they are. Our Managing Director Sebastian spoke about this with Can Yildiz from CYI Consulting, developed key hypotheses and outlined a mini-roadmap:

ℹ️ Prefer to listen instead?

If you would rather see our two experts in color and listen to them directly, you can start the podcast here:

Watch the podcast on YouTube

NIS2 Is a Management Issue

Regulations such as NIS2, the CRA and, a few years ago, the GDPR show that cybersecurity and data protection are no longer voluntary add-ons. However, they are also more than just obligations. After all, these requirements help companies position themselves more securely against current threats. Yet even when this understanding exists, decision-makers often make one mistake: they label NIS2 as a purely IT-related topic. In reality, it goes far beyond that. Risk management, responsibilities, technical measures, processes and evidence all play a central role.

This makes it clear why NIS2 is a management issue. As a first step, executive management must understand risks, prioritize measures, approve budgets, clarify responsibilities and request evidence. Anyone who fails to anchor NIS2 in corporate governance risks management liability. The guiding principle is simple: responsibility can be distributed. Accountability lies solely with the executive level.

NIS2 Does Not Only Affect Large Corporations

One misconception persists: NIS2 requirements only affect large corporations, while medium-sized companies have no obligations. In fact, every company is required to check whether it is affected. Companies must take action if they have at least 50 employees or generate annual revenue and an annual balance sheet total of more than EUR 10 million each, and can be assigned to one of the regulated entity types or sectors under the BSIG.

A gut decision along the lines of “No, this does not affect us” would be premature and grossly negligent. The first step must therefore be an assessment of whether the company is affected. In most cases, it makes sense to involve experts or specialist lawyers to ensure nothing is overlooked. At the very least, the self-assessment should be reviewed by an external party to avoid slipping into negligence from the outset.

Inaction Will Be Expensive

NIS2 should not be understood merely as a set of obligations designed to avoid sanctions. In fact, it contains important measures that help organizations protect themselves adequately against current cyber threats and strengthen their cyber resilience.

However, this also means that organizations that fail to act or do not document their measures in a verifiable way are acting negligently and risking economic consequences. And they are doing so immediately. The NIS2 Implementation Act does not contain defined transition periods. Anyone who fails to meet their obligations and is discovered must expect supervisory measures and significant sanctions — often amounting to millions.

Supply Chain Security Must Not Be Forgotten

NIS2 does not stop at a company’s own boundaries. Suppliers, service providers and external access must also be included more closely in the security assessment. After all, risks do not arise solely from a company’s own IT, but also from maintenance access, remote access, software providers or service providers that access critical systems.

This is precisely where many companies have a blind spot: access by external partners is often not properly documented, time-limited or sufficiently secured from a technical perspective. Anyone who takes supply chain risks seriously must therefore also check which third-party providers have access to systems, data or administrative interfaces — and whether this access corresponds to the required level of protection.

The topic of the software supply chain is also important here. Software supply chains have long since become a new attack surface. You can read why protecting them not only creates more security, but also more trust, in our blog post “Software Supply Chain Security as a Competitive Factor.”

NIS2-Ready: The First Steps

NIS2 requires more than good intentions. Companies must be able to demonstrate which risks they have identified, which protective measures have been derived from them and how the effectiveness of these measures is reviewed. The starting point should therefore be structured — not driven by panic, but guided by clear prioritization.

Step 1: Check whether you are affected Before rushing into action or sitting back and doing nothing, one question must be answered clearly: Does the company fall under NIS2? Organizations should urgently start this assessment now. The BSI provides an online form for this purpose: https://betroffenheitspruefung-nis-2.bsi.de/ .

Step 2: Conduct a gap analysis Once it is clear whether the company is affected, the next step is to examine the current state. Which requirements are already being met? Where are technical, organizational or documentation-related measures still missing? A gap analysis helps make the gap between the current security level and the NIS2 requirements visible.

Step 3: Establish or refine risk management Risk management is a central building block. Companies should document which risks exist for systems, processes, data, supply chains and access. They must then derive concrete measures from this — including responsibilities, priorities and evidence.

ℹ️ Classify existing standards

An ISMS or ISO 27001 certification can be a good foundation. However, companies should not rely on it blindly. Certification does not automatically mean that all NIS2 requirements are fully met. What matters is whether the specific risks, reporting channels, evidence and responsibilities match the company’s NIS2 exposure.

Step 4: Prepare reporting chains Incidents need preparation. Companies should clarify who assesses security incidents, who escalates them internally, who documents them and who submits a report to the BSI. It is important not only to define these processes on paper, but also to test them.

Step 5: Prioritize IAM measures Many NIS2 requirements can be supported specifically through Identity and Access Management, or IAM. These include strong authentication, phishing-resistant multi-factor authentication, the cleanup of orphaned accounts, clean role and permission processes, Privileged Access Management and controlled remote access for employees and service providers.

Step 6: Continuously document evidence Being NIS2-ready does not mean implementing a measure once and then ticking it off. Companies must document in a traceable way what they have done, why they have done it and how they review its effectiveness. Evidence therefore becomes a permanent part of the security organization.

Better Now Than Expensive Later

NIS2 is already mandatory for many companies today. Those who have not yet taken a closer look at it should now initiate the first steps: assess whether they are affected, analyze the current state, identify and evaluate risks, implement measures, define and test reporting channels, and maintain evidence.

However, those responsible do not have to take this path alone. Identity experts are the ideal point of contact for quickly achieving NIS2 readiness and minimizing costly liability risks.

Would you like to check whether your company is affected and, if necessary, initiate the next steps? Let’s start with a non-binding initial consultation.

Jetzt Termin vereinbaren