Style 4 of 6Warm, human, spacious · same words, different direction
NIS2 checkContact

NIS2 · European duty of care

Your European technology and cyber security partner

We establish where you stand against NIS2, repair what is missing, put the measures in place and run them from inside Europe, around the clock. And when someone asks for evidence, your auditor, your insurer or a customer, it is ready the same day.

  • 24/7 SOCSIEM and XDR, always on
  • 15 minSLA on critical alerts
  • All tenNIS2 measures, one platform
  • 100% EUdelivered inside the Union

We implement and manage solutions from the vendors you already use.

MicrosoftGoogleCiscoFortinetCheck PointIBM

Scope

What NIS2 asks of your organisation

Every member state has written NIS2 into national law. If your organisation falls under one of those laws, you have to register, take appropriate security measures, report significant incidents within fixed deadlines and involve the board in carrying them out. You also have to be able to show what you have put in place.

ESSENTIAL

Essential entities

Large organisations from 250 staff upwards in sectors such as energy, drinking water, transport, banking, health and digital infrastructure can be classified as essential entities. The regulator may also examine these organisations without an incident having occurred first.

Each national law draws the exact sector and size lines.
IMPORTANT

Important entities

Organisations with 50 to 249 staff, and large organisations in sectors such as manufacturing, food, chemicals, waste management, postal services and digital providers, can be classified as important entities. Their duties are largely the same. Supervision usually starts after an incident, a signal or a concrete indication.

Each national law draws the exact sector and size lines.
SUPPLY CHAIN

Suppliers in the chain

Organisations that do not fall under NIS2 directly can still be affected by it. Customers who are in scope have to manage their supplier risk, so they can put security requirements into contracts, tenders, audits and supplier questionnaires.

SmartCyber

SmartCyber in five levels

SmartCyber combines security measures, management and monitoring in five service levels. Headcount gives a first indication. We also look at the technical environment, the impact of downtime, and what customers, insurers and regulators require. Each level builds on the one below it. Moving up to a higher level keeps the existing components in use.

Where to begin

Start with the classification scan

Before you have measures changed, it has to be clear which legislation applies to your organisation. A classification scan establishes that per country and per legal entity.

The opening move

The classification scan, one member state at a time

You receive a written assessment stating whether your organisation falls under the law, how it is classified, and which of the ten measures are already covered.

The scan has a fixed price per country. Price, lead time and any offset against follow-up work are agreed in the intake call.
Plan an intake callA call with our CISO, free of charge.
Cyber Incident