Skip to content
Cybersecurity Act · NIS2

NIS2 asks for evidence,
not a policy document.

NIS2 asks you to show what happened, not just that you have written a policy. A policy document takes a week; a timeline across four systems cannot be reconstructed afterwards. We make sure the evidence is recorded as things happen, so an audit question becomes an export instead of three weeks of work.

Where it stalls

The deadline is not the problem, the burden of proof is.

Most organisations get a long way with policy and agreements. It stalls at the moment somebody asks: now show me that it went that way.

24 hours

A reporting deadline you cannot meet.

Twenty-four hours sounds generous until you find the timeline is spread across four systems and the person who knows is on holiday.

Paper

Policy you cannot demonstrate.

A document proves nothing. The regulator asks about the event: who, when, which system, which measure.

OT

Production that stays out of view.

On the plant floor you are not allowed to intervene, so nothing gets measured either. That is exactly the part of the chain a regulator asks about.

Every year

Work that starts from scratch.

The same questions, the same people, every audit from zero, because the evidence was never kept anywhere.

Our starting point

We do not make you compliant,
we make you demonstrable.

Compliance is policy, people and working practice. Technology has nothing to say about that, and we do not claim otherwise.

What technology can do: make sure you can show at any moment what happened, who was involved and which measure worked. That is the part organisations get stuck on, and the only part where we add something.

The question that counts

Can you show what happened ?

Not: do you have a policy about it. But: can you retrieve the event, with timestamp, source and the person involved. That is a technical question.

What we deliver

Four things, and nothing before or after.

No compliance programme and no advisory report. Four concrete pieces of engineering a regulator asks about.

01

The incident timeline.

One timeline across IT and OT, so a report within twenty-four hours is a search rather than a reconstruction of four systems.

02

Access and changes.

Who came in, who changed what, and with what right. The two questions that come back in every assessment.

03

The OT boundary, read-only.

Traffic across the boundary between office and production, removable media and access outside working hours. Listening in, without intervening.

04

Reporting you can hand over.

The questions that return every year as a standard report. Run, check, send.

Zero interventions in the production process. That is not a promise but a design choice: everything we do in OT is read-only.

The topics

What comes up in a conversation like that.

Incident timelineReporting dutyAccess logging ChangesOT boundaryChain partners Retention periodsAccountabilityData provenance Evidence at the moment itself
10 mln
Maximum fine, or 2% of worldwide annual turnover
24 hours
Reporting window for a serious incident
69%
Say an IT inventory takes too much time
0
Interventions in the production process

Fines and reporting deadlines come from the NIS2 directive itself, as summarised by Splunk (October 2024). Whether and how they apply to your organisation is a legal question, we are not lawyers. The 69% comes from State of Security in Manufacturing (Splunk, 2024). The last figure is our way of working, not a measurement.

Do you fall under it?

The honest version.

We cannot answer that definitively, and anyone who does is selling you something. What we can do is ask the questions that sharpen the conversation.

We do not think we fall under it.

Possibly true. Still, look at your customers: if one of them does, the question reaches you through the contract anyway. Chain responsibility is the part that surprises most organisations.

We already have ISO 27001.

A good starting point, and it genuinely saves work. It does not answer the same question though: a certification shows you have a system, an assessment asks what happened on that one day.

Our OT environment must not be touched.

Correct, and we do not. We read along at the boundary: traffic between office and production, removable media, access outside working hours. No agents on a PLC, no interventions in the process.

What does it cost?

That depends on your size and on what is already in place. We quote after a health check, so the price rests on facts. The health check itself has a fixed price and takes five days.

Compliance Control Center
Controls covered
94%
Open findings
7
Evidence within
1 day
Access to critical systems, per week
What it looks like

Evidence that appears while it happens.

Not a folder of screenshots, but a screen where you can show at any moment which controls are covered, which findings are open and how quickly evidence is available.

  • Every event with its time, source and the person involved
  • Clickable from the figure down to the underlying entries
  • Retention per type of event, recorded alongside the evidence itself
  • A standard report for the questions that return every year
More on audit & compliance

Can you show today what happened last month?.

Bring one incident or one audit question to a one-hour conversation. By the end you know whether you can demonstrate it, and if not: what is missing.

Test your situation