Skip to content
GD IT Consultancy
All articles

Security

NIS2: where to start when you have not started at all

The directive is broad and the texts are heavy going. Five steps that deliver the most in practice, in the order we tackle them.

Published on
18 June 2026
Insights
2 min read

NIS2 affects considerably more organisations than its predecessor, and many directors discover late that they fall under it. The temptation is to have a consultancy write a compliance report. That report does nothing for your actual resilience.

We do it the other way around: start with the measures that reduce risk fastest, and document as you go. Compliance then becomes a by-product rather than a goal in itself.

1. Establish whether you are in scope

NIS2 distinguishes essential and important entities, determined by sector and size. Even if you fall outside the directive yourself, you may encounter it through your customers: they must assess their supply chain and will start asking questions. Put this on paper before doing anything else.

2. Know what you have

You cannot protect what you do not know about. An up-to-date overview of systems, data and suppliers is the dullest and most underrated step. In most organisations this overview alone produces three surprises.

3. Clean up access rights

In almost every organisation we enter there are more admin accounts than administrators. Rights get handed out and are rarely revoked. Cleaning this up costs little and reduces risk immediately.

  • Map who holds which elevated rights, and why
  • Revoke everything not actively needed, with a fallback procedure
  • Introduce multi-factor authentication, starting with admins and remote access
  • Make sure rights expire automatically when someone leaves

4. Test your recovery

A backup that has never been restored is not a backup but an assumption. Schedule one day on which you actually restore a critical system in a test environment and time how long it takes. That number is worth more than any policy document.

5. Rehearse the incident

NIS2 imposes reporting duties with short deadlines. Who calls whom, on which number, when the network is down and email is unreachable? A two-hour exercise with the management team exposes more than six months of meetings.

Compliance is the evidence that you are doing something. So start with the doing, not with the evidence.

Keep reading

Questions about this article?

We are happy to think along about your specific situation.