- What I do
- Determine whether and how the rules apply
- Structure analysis and protection needs
- Close gaps in order of urgency
- Build a pragmatic management system
- Define reporting channels
- What lands on your desk
- Applicability assessment
- Structure analysis report
- Statement of Applicability
- Information security policy
- Prioritised treatment plan
- Evidence pack for management
- How you notice it
- You see on one page where the company stands and which risks are open. You decide budget and priorities on that basis, not on demand.
02 · NIS2 · ISO/IEC 27001 · IEC 62443 · BSI IT-Grundschutz
Risk and information security management
How do we, as management, demonstrate that we meet our responsibility?
What I hear
A customer has sent us a questionnaire and we do not know what to answer.
Does NIS2 apply to our company?
How to get started
A clearly bounded starting assignment with a fixed result.
NIS2 clarity
When it is unclear whether and how your company is covered.
- Applicability assessment per legal entity
- Overview of obligations
- Registration and reporting route
So that you can prove whether and how you are covered, and name your obligations as management.
Discuss thisSecurity baseline
When customers demand evidence or an audit is coming up.
- Maturity picture against ISO/IEC 27001
- Draft Statement of Applicability
- Prioritised treatment plan
So that you can direct budget to the gaps that actually matter.
Discuss this
What is necessary in your case?
In 30 minutes you will know where you stand and what the next sensible step is.
Book an initial call