← Expertise

NIS2

NIS2 raises the bar for cybersecurity across the EU, expanding the sectors in scope and placing direct accountability on management for getting it right.

The essentials

What NIS2 requires

In-scope organisations must take risk-based security measures, report significant incidents quickly, and have management actively oversee cyber risk — with personal accountability for leadership.

Security measures

Risk management, supply-chain security and continuity appropriate to your risk.

Incident reporting

Early warning and follow-up reports to authorities within tight deadlines.

Management duties

Leadership must approve, oversee and be trained on cybersecurity measures.

How we help

Cybersecurity that meets the law

We connect your security work to the legal requirements of NIS2 — so you can show compliance, not just claim it.

01

Scope & assess

We confirm whether you are in scope and benchmark your measures.

02

Implement

Policies, supply-chain controls and incident processes aligned with NIS2.

03

Govern

Board reporting and training so management duties are met.

Questions & answers

Are we in scope?

NIS2 covers many medium and large organisations across essential and important sectors. We help you check.

Who is liable?

Management can be held directly accountable for failing to oversee cybersecurity.

How fast must we report incidents?

An early warning is due within 24 hours, with follow-up reports after that.