jump to main content

The ongoing digital transformation and the growing threat of cyberattacks are leading to a fundamental tightening of regulatory requirements for companies. The NIS 2 Directive significantly expands the scope of companies subject to these requirements and substantially strengthens the responsibilities of company management.

In addition to traditional KRITIS companies, many medium-sized organizations are also affected and must meet comprehensive requirements for risk management, IT security, and reporting processes. At the same time, violations can result in severe penalties as well as personal liability risks for management.

Against this backdrop, it is crucial to establish transparency regarding your organization’s specific impact at an early stage, assess existing IT security measures, and establish sustainable governance structures.

Our support for NIS 2

We provide comprehensive support in implementing NIS-2 requirements — from the initial impact analysis to the auditable implementation of an effective IT security management system.

Our interdisciplinary team of IT experts and certified Public Auditors combines regulatory expertise with a deep understanding of business processes and IT architectures.

Our services

  • Identification of your regulatory classification and determination of specific actions required
  • Assessment of your current IT security level compared to the NIS 2 requirements
  • Support in establishing an information security management system (e.g. in accordance with ISO 27001)
  • Development of appropriate policies, controls, and reporting structures for management
  • Designing efficient processes to comply with regulatory reporting deadlines
  • Ensuring the security of service providers and relevant partners in accordance with NIS 2 requirements
  • Conducting audits during or after the completion of a project to ensure compliance