NIS-2 Compliance

We are your partner for cybersecurity and provide you with targeted support in implementing the legal requirements of the new EU Directive.

Efficient, uncomplicated and safe.

We make you fit for the NIS-2 requirements.

Legally compliant
NIS-2 Solutions

The NIS 2 Directive is an EU-wide legislation that obliges companies in critical and selected sectors to secure their IT systems and networks against cyber risks. A key step in meeting the requirements is the establishment of an information security management system (ISMS) in accordance with the proven ISO 27001 standard. This ensures that risks are systematically identified and minimized. At the same time, you meet legal requirements, protect yourself from sanctions and fines and strengthen the trust of your customers and partners. We accompany you step by step in the implementation of an ISMS – from analysis to implementation to incident reporting – and thus strengthen your cybersecurity in the long term.

Our services

Inventory analysis in accordance with
NIS-2 Requirements

We analyze your processes and hazards and identify potential gaps compared to the NIS-2 requirements.

ISMS development and
Implementation

We support the creation and introduction of an information security management system (ISMS) in accordance with ISO 27001.

Training and awareness raising

We train every level of the organization on cybersecurity risks and provide practical solutions to promote security awareness

We specialise in advising small and medium-sized enterprises (SMEs) and also offer attractive conditions for micro-enterprises.

Why e.lective for your cybersecurity?

All services in one package

Time- and resource-saving.

Take advantage of our expertise to build up your ISMS efficiently and purposefully. We take care of the analysis, identify weak points and provide comprehensive support during implementation so that you can continue to focus on your core business.

Objective safety assessment.

Benefit from our specialized expertise and objective analysis to accurately identify your IT security vulnerabilities and assess risks independently and impartially. In this way, you can secure your systems effectively and sustainably.

By experts for experts.

As a certified company according to TISAX®, we know the high requirements of information security from our own experience. We know what is important when introducing an ISMS and offer you pragmatic solutions that have proven themselves in practice.

NIS-2 Quick Check

Find out exactly where you stand in terms of the NIS-2 Directive in just a few minutes. Our interactive quiz will immediately show you which steps you should take next.

NIS-2 - FAQ

Information about the NIS-2 EU Directive to strengthen cybersecurity.

The NIS 2 Directive is an EU piece of legislation aimed at improving cybersecurity in critical sectors. NIS stands for network and information security. It obliges companies to secure their networks and information systems against cyber risks and to report incidents. The first NIS Directive was adopted by the EU Parliament in 2016. Building on this, the second version of the Directive (NIS2) was introduced in 2022, which has already entered into force and must be transposed into national law by October 2024. In Germany, however, implementation will be delayed until the first quarter of 2025, and companies should familiarize themselves with the requirements now and start implementing them.

The NIS-2 applies to companies in sectors such as energy, health, transport, food supply, finance, digital infrastructure and public administration, both in the private and public sectors. There are no fixed thresholds in NIS-2 that clearly apply to all companies concerned. However, for some sectors, small and medium-sized enterprises (SMEs) are taken into account, which means that companies with fewer than 50 employees and an annual turnover of less than €10 million are usually not directly affected by NIS-2. However, despite their size, small companies operating in critical sectors such as healthcare or energy supply must meet certain minimum requirements, even if they are not fully covered by NIS-2. If you are unsure, please feel free to contact us – we will help you to correctly classify your impact on the NIS 2 requirements.

Companies must take a variety of measures to meet the requirements of NIS-2. The starting point for this is an ISMS. In addition, the following points in particular must be implemented:

Risk management and safety precautions: Companies must establish an effective risk management system based on the identification and minimization of cyber risks. Security precautions must be taken to protect sensitive data and systems from attacks.

Report cybersecurity incidents: In the event of an incident, companies are obliged to report it to the competent national authorities within 24 hours. A detailed report of the incident must be submitted within 72 hours of the initial report.

Monitoring and regular audits: Companies need to regularly review their security measures and ensure that they are up-to-date and effective. This includes conducting security audits and implementing improvement measures.

Companies that do not comply with the requirements of the NIS 2 Directive can be subject to significant penalties. These penalties can be as high as €10 million or 2% of the company’s annual global turnover, whichever is higher. In addition to the financial penalties, there may also be legal consequences and a loss of trust on the part of customers and partners, which can lead to long-term business damage. Therefore, it is crucial to meet the requirements in a timely manner to avoid these risks.

An ISMS (Information Security Management System) is a structured system for managing and improving information security in an organization. It includes processes, policies, tools, and procedures for identifying, assessing, and addressing security risks. An ISMS according to the ISO 27001 standard forms the basis for the implementation of the NIS-2 requirements. It helps businesses implement the necessary security measures, report incidents, and continuously improve their cybersecurity. The introduction of an ISMS ensures that all requirements of NIS-2 are taken into account in a systematic framework.

Now free
Arrange an initial consultation

Contact
Screenshot 2024-09-18 154450