




NIS2 · The reporting duty
24 hours. 72 hours. One month.
A significant incident starts three deadlines that are law, and being ready for them is the sharpest test of the whole duty of care. We build the measures, run them from our European SOC, and draft each notification with you.
We implement and manage solutions from the vendors you already use.
Scope
What NIS2 asks of your organisation
Every member state has written NIS2 into national law. If your organisation falls under one of those laws, you have to register, take appropriate security measures, report significant incidents within fixed deadlines and involve the board in carrying them out. You also have to be able to show what you have put in place.
Essential entities
Large organisations from 250 staff upwards in sectors such as energy, drinking water, transport, banking, health and digital infrastructure can be classified as essential entities. The regulator may also examine these organisations without an incident having occurred first.
Each national law draws the exact sector and size lines.Important entities
Organisations with 50 to 249 staff, and large organisations in sectors such as manufacturing, food, chemicals, waste management, postal services and digital providers, can be classified as important entities. Their duties are largely the same. Supervision usually starts after an incident, a signal or a concrete indication.
Each national law draws the exact sector and size lines.Suppliers in the chain
Organisations that do not fall under NIS2 directly can still be affected by it. Customers who are in scope have to manage their supplier risk, so they can put security requirements into contracts, tenders, audits and supplier questionnaires.
SmartCyber
SmartCyber in five levels
SmartCyber combines security measures, management and monitoring in five service levels. Headcount gives a first indication. We also look at the technical environment, the impact of downtime, and what customers, insurers and regulators require. Each level builds on the one below it. Moving up to a higher level keeps the existing components in use.
Essential
Baseline protection for small organisations: endpoints, mail and backups in managed hands.
20 to 49 employees The usual choiceAdvanced
Full round-the-clock SOC, SIEM plus XDR underneath. Where most organisations under NIS2 land.
100 to 499 employees Level 5Enterprise
Governance for group structures across several countries, with reporting a board can sign.
1000 employees and aboveWhere to begin
Start with the classification scan
Before you have measures changed, it has to be clear which legislation applies to your organisation. A classification scan establishes that per country and per legal entity.