Client Situation
Our client needed help in becoming compliant with NIS2 prior to the legislation. The client is a large international company in the transport sector, which is considered critical under NIS2. NIS2, the “Network and Information Security Directive, ” is an EU regulation set to become law in the summer of 2025 with the purpose of strengthening cybersecurity across the Europe.
By introducing clearer requirements for risk analysis, security measures, and business continuity planning, NIS2 places greater responsibility on management to actively engage
Assignment
- On behalf of the client’s CIO, we initiated a project to ensure compliance with NIS2. Given that NIS2 impacts the entire organization, particularly the digital environment, our approach was comprehensive, engaging all business entities to create organization-wide alignment. To strengthen risk management, we established measures that anchored cybersecurity as a core business priority. Actions were taken to align the Cybersecurity Management System (CSMS) with NIS2, emphasizing two critical areas: resilience and resistance.
- A Cybersecurity Awareness Program, including extensive training for all employees, was also rolled out to the whole organization. We also led business impact assessment workshops, integrating both IT and business perspectives to refine risk analysis processes and thereby initiating the foundation of business continuity and disaster recovery planning.
Client Benefits
- Through this project, the client has gained deep cybersecurity expertise and a structured approach to NIS2 compliance. The fast-paced execution enabled engagement across the organization, ensuring readiness for legislative changes and the adoption of legal requirements.
- A governance model with clear role definitions is now in place, and the risk management process has been consolidated. Vendor security assessments are handled in a structured and efficient way, supported by a risk management system. Key cybersecurity measures have been evaluated to ensure they are effective and aligned with business needs. Beyond compliance, the project has strengthened the client’s overall cybersecurity posture, making the organization more resilient to future threats.
