NIS2 Advice for the SMEs – technically implemented, demonstrable
The registration portal of the BSI is open, around 29,500 institutions in Germany are affected. We bring your IT up to the required level and ensure that you can prove what you have implemented.
Who NIS2 concerns
Three questions decide: In which sector are you active, how big are you – and for whom do you deliver?
What to do concretely
Six areas where NIS2 requires action. The most complex is rarely the technique, but the proof that it works.
What we do – and what we do not
- IT inventory of the required measures
- Technical implementation: access, logging, backup, recovery
- Monitoring and alerting so that incidents are even noticeable
- Set up reporting channels and templates for the 24-hour case
- Demonstration: protocols, tests, traceable changes
- Make requirements for your service providers technically testable
- Legal determination whether you are affected
- Contract drafting and legal audit
- Representation of authorities
We are engineers, not lawyers. The classification of whether and in which category your company falls is part of the legal advice – we provide the technical facts and then work together with your law firm or your data protection officer.
Why this is different for SMEs
NIS2 was not written for the middle class, but hits him with full force. A company with 80 employees does not have a security department, but two people who keep everything going. For them, a catalogue of requirements according to the prior art is first a wall.
That is why we are breaking down the subject. Not everything has to happen at the same time, and not every measure is worth the same. At the beginning there is an inventory that says where you stand – then an order that follows the risk and not the order in the legal text.
The pressure is real: According to the situational picture of the BSI, almost 80 percent of all ransomware attacks are now aimed at SMEs. Attackers know that tangible values meet slim security budgets here. The duties from NIS2 force to what was already overdue.
- Inventory rather than catalogue processingFirst see what is available – amazingly much it is usually already.
- Sequence of riskWhat is most likely to be exploited comes first. Not what the law says above.
- A contact person instead of a bodyThey talk to the same people who then implement the measures.
- Initial consultation free of charge and without obligation
- Also suitable if the affected is still unexplained
- On request with initial assessment of the need for action