NIS2
Risk management, incident handling and supply-chain security for essential and important entities, with management accountable.
Where you are
NIS2 is applied through national law in each EU country. It asks for risk-management measures, including secure development and supply-chain security, and for incident reports on a tight clock.
Sounds familiar?
- Management has never signed off on cyber risk
- Supplier security is a questionnaire, once
- No 24-hour path to report an incident
What you need
Each need, why it matters, and what covers it: the services that set it up, and the tower modules that will keep watching it.
- Risk management with owners
Measures approved by management and reviewed.
Services
Atalaia tower · Soon
- Secure development
Vulnerability handling in how you build and maintain systems.
Services
Atalaia tower · Soon
- Supply-chain security
Your suppliers and the software they ship you.
Services
Atalaia tower · Soon
- Incident handling
Detection and reporting within 24 and 72 hours.
Services
Atalaia tower · Soon
Services only, for now.
What it asks, and where the evidence comes from
A simplified reading. Check your national transposition with your legal team.
| NIS2 asks for | Evidence from the line | Who helps |
|---|---|---|
| Risk-management measures | Policies, risk register, management sign-off | Policies, Compliance & Risk |
| Security in development and maintenance | Scans, threat models, fix times | Security Scans, Threat Modeling |
| Supply-chain security | Package and supplier register, policy at install | Supply Chain Security, Package firewall |
| Incident handling and reporting | Detections, 24h and 72h runbooks | Detection Engineering |
We help you produce the evidence. We are not your auditor or your lawyer.
Services
Policies, audits, risk assessment
See the station →Station 08 · BuildSecurity ScansSAST · SCA · Secrets · IaC · Container
See the station →Station 03 · DesignThreat ModelingBusiness, devs and cyber, one table
See the station →Station 07 · BuildSupply Chain SecurityPackages, extensions, registries
See the station →Station 17 · RunDetection EngineeringPentest findings become SOC use cases
See the station →Atalaia tower modules
In development. Early-access teams get them first.
What you end up with
- Measures management signed
- Supply-chain security you can show
- An incident clock you can meet
Talk it through
A 30-minute call. No slides, no price list, and a next step either way.