adesso Blog

The NIS2 Directive is causing considerable unease in many organisations. What previously affected mainly traditional operators of critical infrastructure now applies to a significantly wider range of organisations. These include manufacturing SMEs, energy and utility companies, transport, logistics and many service providers. Many are now asking themselves: ‘Are we included too?’ And if so: ‘How are we supposed to implement this in such a short time?’

With NIS2, the EU is not merely focusing on technical information security. It is just as much about the organisational and strategic management of risks. This is particularly evident in two respects. Firstly, the scope is being significantly expanded. Many organisations that have not previously regarded themselves as ‘critical’ now fall within the scope. Secondly, senior management is explicitly held accountable. Cyber and information security are therefore no longer purely an IT or Information Security Management System (ISMS) issue. They are becoming a clear management issue – with potential personal liability risks.

In this situation, we see the same pattern time and time again. Initially, attempts are made to tackle the issue using familiar methods: Excel spreadsheets, distributed documents, individual workshops and numerous PowerPoint slides. However, it very quickly becomes clear that the core requirements of NIS2 can hardly be met in a robust manner this way. There is a lack of clarity as to which parts of the organisation fall within the scope. Systems, processes and suppliers also remain unclear. Risks are assessed using different formats and tools. Measures are documented in a scattered manner. Responsibilities are only partially defined. Consistent, audit-proof reporting is hardly feasible at a reasonable cost.

This is precisely where we come in. We do not view NIS2 as a mere compliance project that ends up in folder structures and presentations. We use NIS2 as an opportunity to embed transparency, risk management and reporting within a centralised tool setup. Our aim: to turn NIS2 into a manageable system. Not a pile of documents that has to be laboriously gathered together before the audit.

The first step is transparency. You need a clear, centralised overview of all NIS2-relevant assets. These include systems, applications, processes and service providers. These are classified, assigned protection requirements and linked to responsible parties. This sounds simple, but is often the decisive factor. Only once it is clear what needs to be protected and managed can you assess risks effectively and prioritise measures. A good tool maps these interrelationships in a comprehensible way. Platforms such as OneTrust make these dependencies visible and help to establish centralised transparency regarding assets, risks and responsibilities. They highlight where critical dependencies and gaps lie.

Building on this, we establish a structured risk management framework. Risks are assessed according to a consistent methodology. Typical criteria include probability of occurrence, impact on business operations and criticality as defined by NIS2. Importantly, the risks do not exist in isolation within the tool; they are directly linked to controls and measures. This transforms a static risk analysis into a dynamic management process. You can see which risks are being actively addressed. You can see where measures are overdue, where the status is improving, and where new action is required. Dashboards provide precisely the views that IT, security, risk management and senior management need. In platforms such as OneTrust, these perspectives can be mapped on a role-based basis and evaluated in a consolidated manner.

Another key component is audit-proof reporting. Regulatory authorities, internal audit and management expect transparent, up-to-date and consistent evidence. They want to see how risks are managed and measures implemented. A suitable tool configuration enables reports at the touch of a button. These answer questions such as: Which risks have been identified within the NIS2 scope? Which measures have been defined, implemented or planned? Who assessed, approved or decided on measures, and when? Version control and a complete audit trail result in reporting that can withstand even the most critical audit. Without the frantic scramble to gather information at the last minute.

In practice, such a NIS2 setup usually looks like this: a central register consolidates all relevant assets and assigns them unambiguously. The risk analysis uses defined criteria that are tailored to your organisation and the regulatory requirements. A pre-defined catalogue of controls and measures serves as a reference framework. It may be based, for example, on International Organisation for Standardisation (ISO) 27001, the German Federal Office for Information Security (BSI) or the National Institute of Standards and Technology (NIST). This makes it clear which requirements are already met and where gaps exist. Security incidents can be recorded and assessed directly within the tool. They are assigned to the appropriate reporting obligations. Existing systems such as ticketing tools, Security Information and Event Management (SIEM), vulnerability scanners or Governance, Risk & Compliance (GRC) solutions are integrated. This means data does not need to be collected twice, but is reused and enriched.

The added value of this approach extends far beyond NIS2. Organisations gain significantly better insight into their security posture. Investments in security can be planned and justified in a more targeted manner. Collaboration between IT, information security, risk management and the legal department improves noticeably. What you build today for NIS2 can be used tomorrow to meet further requirements. These include, for example, the Digital Operational Resilience Act (DORA), ISO certifications or BSI requirements. NIS2 thus becomes a catalyst for sustainable security governance. It does not remain an additional burden without long-term benefit.

Our approach is deliberately pragmatic. We start with a concise quick check. Together, we clarify whether and to what extent your organisation is affected by NIS2. We look at where you stand today and where the biggest gaps lie. Building on this, we develop a target vision that takes your existing toolset into account. We do not create a parallel world. We select suitable tools or integrate existing solutions. We configure the setup, integrate relevant systems and design dashboards and reports that offer real added value for your stakeholders. Finally, we define roles, processes and responsibilities. This way, you don’t just comply with NIS2 ‘on paper’, but can manage it yourself in the long term.

NIS2 catches many organisations ‘by surprise’. However, your response need not be frantic or piecemeal. If you use the requirements to consistently embed transparency, risk management and reporting within the tool, you’ll create a stable foundation. For greater security, better decisions and reliable compliance. If you’d like to know what such a NIS2 setup might look like in practice for your organisation, now is the right time to take the next step.

Conclusion

NIS2 is not just another ‘mandatory exercise’ for folder structures. The directive provides the impetus to set up information security in a structured, transparent and manageable way. Those who clearly identify their NIS2-relevant assets, assess risks consistently and link them to specific measures create a robust foundation. If you bring all of this together in a centralised tool setup, you achieve more than just audit-proof compliance. You establish a permanent control mechanism for security and risk. This transforms scattered Excel spreadsheets and presentations into end-to-end processes. IT, security, risk management, the legal department and senior management then work from a shared data foundation.

The real added value extends beyond NIS2. A properly implemented NIS2 framework can be utilised for other regulations such as DORA, ISO 27001 or BSI requirements. It can be expanded step by step. What you build today for NIS2 can become a central component of your security governance tomorrow. You gain a better basis for decision-making, clearer lines of responsibility and a higher level of maturity in information security. Supported by suitable platforms such as OneTrust, this creates a central foundation not only to meet NIS2 requirements but also to manage them on an ongoing basis.

If you’d like to know whether and to what extent your organisation is affected by NIS2, let’s start with a quick assessment. This will help us clarify what a suitable, tool-supported setup might look like for your organisation. Get in touch, and together we’ll assess where you stand today, which gaps need to be closed and how you can make the most of NIS2. This creates a robust, future-proof foundation for security and compliance.

Picture Rajeev Panesar

Author Rajeev Panesar

Rajeev works in the ITMC business unit at adesso SE. He is an experienced consultant in information security, IT incident management and IT service management.

His work focuses on the implementation and further development of management systems (ISMS) within the context of information security regulations. These include, amongst others, NIS2, DORA, the Minimum Requirements for Risk Management (MaRisk), the ISO 2700x series and the BSI IT-Grundschutz, for example BSI 200-x.

Category:

Industries

Tags:

Security

IT-Security