All articles

Tag

Articles on NIS2.

9 posts tagged#NIS2.

Three professionals in an office comparing documents held in separate folders — the three-way choice this guide is about.

Virtual CISO·

The Brain, the Hands, and the Specialist: A Buyer's Guide to vCISO vs. MSSP vs. Consultant

SMBs under €50M are really choosing between three things: a leader, an operator, and a specialist. How to tell a vCISO, an MSSP and a consultant apart.

6 min read · Sylvio Sorel

Two technicians in blue coveralls at an industrial control-room console, one facing banks of process monitors and the other standing at a panel of illuminated switches.

NIS2·

NIS2 and the CRA: two clocks on one factory

NIS2 regulates the plant you run. The CRA regulates what leaves it. Two 24-hour clocks, two different triggers — and in most factories, no owner.

8 min read · Sylvio Sorel

Four white ring binders standing upright in a wooden crate, their spines hand-labelled — the physical evidence pack an auditor actually reads.

ISO 27001·

One ISMS, three regulators: the same nine documents

NIS2, DORA and your ISO auditor ask for the same nine documents — and reject them for three different reasons. Here is the pack, mapped.

7 min read · Sylvio Sorel

Three colleagues at a dark meeting table reviewing a document in a folder; one holds a pen over the page while another points to a line on it.

Vendor Risk Management·

You've Spent Years Answering Security Questionnaires. Here's the One You Should Be Sending.

A 12-question vendor security questionnaire for SMBs — the red-flag answers and a one-page scoring rule, mapped to NIS2 Article 21(2)(d).

8 min read · Sylvio Sorel

An open pocket watch resting in an open hand — the reporting clocks that start before a company knows the scope of an incident.

Incident Response·

One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72

Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

7 min read · Sylvio Sorel

A small team calmly working an incident response plan at night.

Incident Response·

Incident Response Without a SOC: The 5-Step Playbook a 50-Person Company Can Actually Run

A practical 5-step incident response playbook for SMEs without a SOC — prepare, detect, contain, recover, report. Mapped to NIST 800-61r3, NIS2 and CRA clocks.

7 min read · Sylvio Sorel

An aerial view of two paths crossing in a green field, a cyclist pausing at the intersection — which regulatory route applies to you.

NIS2·

NIS2 vs DORA vs ISO 27001: which ones apply to you

NIS2, DORA and ISO 27001 are not rival options: two are law, one is a standard. Who each one binds, where they overlap, and which one wins.

7 min read · Sylvio Sorel

A chess board mid-game — boards now have to make calculated, defensible moves on NIS2.

NIS2·

NIS2 Enforcement Has Started: 8 Questions Your Board Must Answer in the First 30 Days

NIS2 is now enforced across most of the EU. Article 20 puts directors personally on the hook. Eight questions every board must answer in 30 days.

7 min read · Sylvio Sorel

Compliance binders next to a padlock — paperwork is not protection.

Compliance·

Compliance Is Not Security: What GDPR, PCI DSS, and NIS2 Won't Protect You From

Passing audits is not the same as being defensible. Where the major frameworks stop, what attackers exploit anyway, and how to bridge the gap.

7 min read · Sylvio Sorel