731 901 601
The most common mistakes made by companies regarding NIS 2, which may lead to fines or problems during an audit

The most common mistakes made by companies regarding NIS 2, which may lead to fines or problems during an audit

Many organisations take a rushed and piecemeal approach to NIS 2. Time pressure and uncertainty regarding the requirements mean that efforts focus on ‘ticking the box’ quickly, rather than on building a coherent security system. The result of this approach is solutions that appear adequate at a general level but do not stand up to scrutiny during an audit or a real-world incident. Most often, the problem stems not from a lack of action, but from measures that are incomplete or inconsistent.

Treating NIS2 as an IT project rather than a holistic organisational approach

One of the most common mistakes is to confine NIS2 to the IT domain. Companies focus on tools such as firewalls, monitoring systems or backups, assuming that technology alone solves the compliance problem.

However, NIS2 covers a much broader scope – from risk management, through internal procedures, to management accountability and cooperation with suppliers. Failure to link these elements means that an organisation may have extensive technical safeguards but, at the same time, lack consistent operating procedures for crisis situations. In such cases, there is often a lack of clearly defined roles, decision-making procedures and risk control mechanisms. It is precisely these areas that are most frequently scrutinised during audits.

Focusing on tools rather than the security process

Another problem is the belief that purchasing or installing specific systems automatically ensures compliance with requirements. Organisations invest in technologies but fail to build a coherent security management process around them.

NIS2 is based on a continuous risk management cycle: threat identification, assessment, implementation of security measures, monitoring and improvement. Tools alone do not carry out this cycle — they can only support it.

The absence of a process means that even well-chosen solutions are not utilised to their full potential. Systems generate alerts that are not analysed, backups are not tested, and procedures remain out of date or unknown to staff. As a result, an organisation may appear secure, but is not prepared for a real incident.

Underestimation of supplier-related risks

An important area that is often overlooked is supply chain security. NIS2 extends an organisation’s responsibility to include third parties that have an impact on its systems, data or business continuity. This applies, amongst others, to IT service providers, cloud solution providers, outsourcing firms and other business partners. Each of these may constitute a potential source of risk.

Many companies lack a formal security assessment of their suppliers. The selection of partners is often based on business criteria, without analysing their cybersecurity maturity. Furthermore, mechanisms for regularly reviewing the level of risk during the course of the partnership are rarely in place. This creates gaps that are not visible within the organisation but may have a direct impact on its security.

A lack of continuity in actions and a focus on one-off changes

The final significant mistake is treating NIS2-related activities as a self-contained phase. Organisations often implement organisational and technical changes, but fail to sustain them over time. Over time, there is a lack of updates to procedures, testing of their functionality and evidence of their effectiveness. Meanwhile, from an audit perspective, it is crucial not only that solutions exist, but that they are applied and monitored on an ongoing basis.

In many cases, the problem is not a lack of security measures, but an inability to demonstrate that they are working. This significantly increases the risk of compliance being called into question during an audit. NIS2 requires a process-based approach, in which security is regularly reviewed and adapted to evolving threats.

The most common problems associated with NIS2 do not stem from a lack of action, but from a fragmented approach. Organisations often focus on selected elements – technology, procedures or documentation – rather than building a coherent risk management system. This approach leads to a situation where, formally, many elements are in place, but in reality they do not form a functional whole. An effective approach to NIS2 requires, above all, consistency, coherence and continuity of action.

 

Read other posts

Do you want to break into a retail chain? Start with a certificate that the chains already recognise and accept – FSSC 22000

Do you want to break into a retail chain? Start with a certificate that the chains already recognise and accept – FSSC 22000

Gaining access to a retail chain is the dream of many food manufacturers. And a real challenge – because retail chains have their own lists of requirements that a supplier must meet before their products even appear on the shelves. read more
The cloud, remote working, AI – how does ISO 27002 address threats that didn’t exist just a few years ago?

The cloud, remote working, AI – how does ISO 27002 address threats that didn’t exist just a few years ago?

The environment in which companies store and process information has changed more in the last few years than it did over the previous two decades. read more
Food safety as part of a manufacturer’s brand – how ISO 22000 builds customer trust

Food safety as part of a manufacturer’s brand – how ISO 22000 builds customer trust

Just a dozen or so years ago, a food manufacturer’s brand was built mainly on taste, price and product recognition. read more
More posts