
Many organisations take a rushed and piecemeal approach to NIS 2. Time pressure and uncertainty regarding the requirements mean that efforts focus on ‘ticking the box’ quickly, rather than on building a coherent security system. The result of this approach is solutions that appear adequate at a general level but do not stand up to scrutiny during an audit or a real-world incident. Most often, the problem stems not from a lack of action, but from measures that are incomplete or inconsistent.
One of the most common mistakes is to confine NIS2 to the IT domain. Companies focus on tools such as firewalls, monitoring systems or backups, assuming that technology alone solves the compliance problem.
However, NIS2 covers a much broader scope – from risk management, through internal procedures, to management accountability and cooperation with suppliers. Failure to link these elements means that an organisation may have extensive technical safeguards but, at the same time, lack consistent operating procedures for crisis situations. In such cases, there is often a lack of clearly defined roles, decision-making procedures and risk control mechanisms. It is precisely these areas that are most frequently scrutinised during audits.

Another problem is the belief that purchasing or installing specific systems automatically ensures compliance with requirements. Organisations invest in technologies but fail to build a coherent security management process around them.
NIS2 is based on a continuous risk management cycle: threat identification, assessment, implementation of security measures, monitoring and improvement. Tools alone do not carry out this cycle — they can only support it.
The absence of a process means that even well-chosen solutions are not utilised to their full potential. Systems generate alerts that are not analysed, backups are not tested, and procedures remain out of date or unknown to staff. As a result, an organisation may appear secure, but is not prepared for a real incident.
An important area that is often overlooked is supply chain security. NIS2 extends an organisation’s responsibility to include third parties that have an impact on its systems, data or business continuity. This applies, amongst others, to IT service providers, cloud solution providers, outsourcing firms and other business partners. Each of these may constitute a potential source of risk.
Many companies lack a formal security assessment of their suppliers. The selection of partners is often based on business criteria, without analysing their cybersecurity maturity. Furthermore, mechanisms for regularly reviewing the level of risk during the course of the partnership are rarely in place. This creates gaps that are not visible within the organisation but may have a direct impact on its security.
The final significant mistake is treating NIS2-related activities as a self-contained phase. Organisations often implement organisational and technical changes, but fail to sustain them over time. Over time, there is a lack of updates to procedures, testing of their functionality and evidence of their effectiveness. Meanwhile, from an audit perspective, it is crucial not only that solutions exist, but that they are applied and monitored on an ongoing basis.
In many cases, the problem is not a lack of security measures, but an inability to demonstrate that they are working. This significantly increases the risk of compliance being called into question during an audit. NIS2 requires a process-based approach, in which security is regularly reviewed and adapted to evolving threats.
The most common problems associated with NIS2 do not stem from a lack of action, but from a fragmented approach. Organisations often focus on selected elements – technology, procedures or documentation – rather than building a coherent risk management system. This approach leads to a situation where, formally, many elements are in place, but in reality they do not form a functional whole. An effective approach to NIS2 requires, above all, consistency, coherence and continuity of action.