CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

ARTICLES

NIS2: what has to be true on the day

Not what the directive says — what an inspector can ask you to show, and what most organisations will not have.

The obligation is evidence, not intent

Most NIS2 preparation stops at a policy document, because a policy is the thing that is easy to write. The directive asks for risk management measures that are appropriate and proportionate, which in practice means somebody has to be able to show the reasoning: what you decided, on what basis, and what you did about it.

A register nobody has updated since it was written does not survive that question. Neither does a supplier list without contracts behind it.

Twenty-four hours is shorter than it sounds

The early warning clock starts when you become aware of a significant incident, not when you have understood it. That means the decision "is this reportable" has to be makeable by whoever is on shift at two in the morning, against a written threshold, without waiting for a management meeting.

If that threshold does not exist on paper today, it will be invented under pressure on the worst night of the year.

Management is personally in scope

The part that changes behaviour is not the fine. It is that management bodies have to approve the risk measures and can be held liable for failing to. That moves security from a line in the IT budget to something a board has to be able to discuss without the CIO in the room.