Skip to content

NIS2 in Small and Mid-sized Industry — What You Actually Need to Do

The EU’s NIS2 directive brought cyber security obligations to a large group of companies that never thought of themselves as “critical infrastructure”. Consultant slide decks paint threat scenarios and fine ceilings. Let’s take a breath: NIS2 does not demand magic. It demands systematic work — the same kind quality management systems have demanded for decades.

I work daily with both quality and information security in industry, and I’ll make a claim: a company that knows its way around the ISO world already has the basic grip NIS2 requires. It is about identifying risks, choosing controls, documenting, and management responsibility. What’s new is mainly that you can no longer decline.

Cyber security doesn’t start with a purchase. It starts with an inventory.

Where to start — a practical order

First: find out whether NIS2 applies to you — sector and size decide, and many industrial SMEs are in scope either directly or through their customers’ supply chains. Second: inventory. You cannot protect what you don’t know you own. List the systems, accounts, devices and data flows — dull work that always turns up surprises.

Third, the basics, in this order: multi-factor authentication everywhere, backups whose restore has actually been tested, a clean-up of access rights, a patching practice, and staff training. These five stop the majority of real attacks — and every one of them costs less than any piece of hardware.

Fourth: rehearse an incident. NIS2’s reporting obligation is strict, and the notification chain is not something to learn during your first real case. One tabletop exercise a year — “our email is encrypted by ransomware; what do we do in the next hour?” — teaches more than a hundred pages of policy documents.

Management responsibility is a feature, not a threat

NIS2 puts cyber risk on the management table with personal accountability attached. See it as a gift: at last there is a reason for information security to carry the same weight as finance and occupational safety. Well-managed security is also a sales argument — large customers already ask their suppliers about these things, and the questionnaires get denser every year.

Next Wednesday I continue on the supply chain theme: security of supply begins with procurement — and the cheapest supplier is expensive if it is the only one.

As a service: business continuity and preparedness.