
The NIS2 directive sets new European cybersecurity rules that, in practice, place concrete obligations on company boards and owners. It’s no longer just about “having antivirus” — it’s about real processes: risk analysis, incident response procedures, training, documentation, and reporting.
If you run a company in a sector covered by NIS2 (e.g., digital services, IT infrastructure, finance, healthcare, energy, transport, or a supplier to these industries), failing to comply can end in serious financial penalties — and in extreme cases, even personal liability for management.
In practice, NIS2 fits naturally with the specialized IT security and hosting services you already use at Remote Admin — from server administration, through security, to cloud and GPU Cloud.
This article is a practical checklist for the board: exactly what you need to have under control so you can face NIS2 with confidence, instead of waking up to an unexpected audit.
In brief
-
NIS2 isn’t just an IT department problem — it’s an obligation at the board/management level.
-
Companies covered by the directive must adopt a systematic approach to cybersecurity: risk analysis, policies, procedures, training, monitoring.
-
Failing to comply can mean steep financial penalties and personal liability for management.
-
The most sensible practical step is a security audit plus vCISO and SOC-type services, delivered by a specialized partner — for example, vCISO and SOC as a service.
-
NIS2 isn’t just “paperwork” — properly implemented, it genuinely reduces the risk of downtime, ransomware attacks, and data leaks, especially when backed by continuous vulnerability monitoring (ReconMore) and penetration testing.
What is the NIS2 directive, and who does it apply to in Poland?
The NIS2 directive is an update to the earlier NIS directive, adopted at the EU level to raise the level of cybersecurity across key sectors of the economy.
In practice, it covers two categories of entities:
-
essential entities — e.g., energy, transport, banking, digital infrastructure, healthcare,
-
important entities — e.g., certain types of digital services, IT service providers, data processing, some e-commerce.
You don’t need to be a “big corporation” to fall under NIS2. Often, it’s enough that:
-
you provide critical IT services to entities in essential/important sectors,
-
you operate infrastructure that others depend on (e.g., hosting, VPS servers, systems maintenance).
So the first question for the board is:
Does my company fall under NIS2 — directly, or indirectly as an IT service provider?
If you’re not sure, the natural move is to consult an experienced partner — for example, through a vCISO service — who can help you sort out regulatory compliance (NIS2, DORA, MiCA).
What are the key NIS2 obligations from the board’s perspective?
NIS2 doesn’t get into details like “use this specific firewall” — instead, it defines the areas where an organization must have risk management measures in place. In simplified terms:
1. Risk management and security policy
-
identifying critical assets (systems, data, services),
-
regular risk analysis (what could go wrong, and with what impact),
-
adopting a formal information security policy.
This is where strategic vCISO support works well — a virtual Chief Information Security Officer who helps design and implement policies tailored to your company’s reality.
2. Incident management
-
procedures for detecting, reporting, and handling incidents,
-
a clear decision-making chain: who does what when something happens,
-
a communication plan (internal and external, including with the relevant authorities).
In practice, this requires continuous monitoring and response — which is exactly what a Security Operations Center (SOC) as a service handles.
3. Supply chain security
-
vendor assessment (especially IT, cloud, hosting, and software houses),
-
security requirements built into contracts,
-
verifying that a vendor actually meets minimum standards.
If you use hosting or infrastructure services, it’s essential that the operator — like Remote Admin — provides a high level of security, backups, anti-DDoS protection, and so on.
4. Network and systems security
-
access control, network segmentation, updates, backups,
-
protection against malware, phishing, and ransomware,
-
monitoring and logging (recording events).
This is where both penetration testing and a vulnerability scanner come into play:
-
continuous infrastructure testing with the ReconMore Vulnerability Scanner.
5. Business continuity and disaster recovery
-
business continuity plans (BCP) and disaster recovery plans (DRP),
-
testing backups and failure scenarios,
-
procedures for keeping key services running.
This ties directly into how your servers, clusters, backups, and cloud are designed — an area where Remote Admin’s administrators and DevOps engineers specialize.
6. Employee training and awareness
-
regular cybersecurity training,
-
scenarios such as phishing, misdirected data, and remote work,
-
education not just for IT, but also for accounting, sales, and the board.
A program like this is easier to roll out with an experienced security team (vCISO + SOC) behind you, one that knows where people tend to make mistakes.
The NIS2 checklist for the board: what should you have checked off?
Below is a simple checklist you can walk through at a board or management meeting.
If your answer to most of these is “no” or “not sure”, that means NIS2 is a real risk for you — not just an “EU curiosity.”
1. Diagnosis and accountability
-
Do we know for certain whether our company falls under NIS2 (directly or as a supplier)?
-
Does the board have a clear owner for the NIS2 topic (e.g., a board member responsible for IT/security)?
-
Do we have a formally designated person or function responsible for information security (e.g., a CISO/vCISO)?
2. Policy and risk analysis
-
Do we have an up-to-date information security policy?
-
Has a formal risk analysis been carried out in the IT/OT area in the last 12 months?
-
Do we have a list of critical systems and services whose failure would stop the business?
3. Incidents and procedures
-
Are there written procedures for responding to security incidents?
-
Do we know when and to whom an incident must be reported (timing, method, scope of information)?
-
Have we ever run a “dry run” exercise (incident simulation)?
4. Vendors and the supply chain
-
Do we have a list of key IT/cloud/hosting vendors?
-
Do our contracts include security requirements (SLAs, backups, incident response)?
-
Do we carry out regular vendor risk assessments?
5. Technical safeguards
-
Do we use multi-factor authentication (MFA) wherever possible?
-
Do we have a backup system in place with restore testing?
-
Is event monitoring and logging centralized and actually reviewed (not just “logged because it’s logged”)?
6. Business continuity
-
Is there a business continuity plan (BCP) and a disaster recovery plan (DRP)?
-
Have failure scenarios been tested, e.g., a key system outage or a ransomware attack?
-
Does the business know how long it can stay “offline” without critical losses?
7. People and awareness
-
Do employees get regular cybersecurity training?
-
Do the board and management understand the consequences of an incident (financial, legal, reputational)?
-
Do we have a simple procedure for what an employee should do if they notice something suspicious?
What does the NIS2 implementation process look like, step by step?
In simplified terms, NIS2 implementation looks like this at many companies:
1. Initial audit
-
assessing whether and how NIS2 applies to the company,
-
mapping systems, services, data, and processes,
-
identifying gaps — technical, organizational, legal.
This part is handled well by combining vCISO with penetration testing and vulnerability scanning services.
2. Action plan (“roadmap”)
-
priorities: what needs to happen immediately (e.g., backups, MFA),
-
what can be implemented in phase two (e.g., more advanced monitoring, SOC),
-
a timeline and ownership.
3. Implementing technical and organizational measures
-
policies, procedures, documentation,
-
system configuration, network segmentation, backups, monitoring,
-
employee training.
This is where server administration, DevOps, and hosting services come into play, alongside operational SOC support.
4. Tests and exercises
-
checking that everything works in practice, not just “on paper,”
-
incident simulations, data restore tests, team response drills.
5. Continuous monitoring and improvement
-
periodic risk reviews,
-
updates to policies, procedures, and safeguards,
-
reporting to the board (not just “everything’s fine,” but concrete metrics).
At this stage, a 24/7 SOC and continuous ReconMore vulnerability monitoring take a huge burden off the company.
What are the consequences of NIS2 non-compliance?
Financial penalties get the most attention, but that’s not the whole story.
The risks include:
-
steep administrative fines,
-
personal liability for management — including individual liability for failing to exercise due diligence,
-
orders to implement specific measures, which in practice means costly, urgent changes,
-
reputational risk — tied to publicity around incidents and penalties imposed.
In practice: if a company falls victim to a serious incident and the supervisory authority finds that basic steps weren’t taken, the board has a serious problem on its hands. All the more reason to have a partner on your side who genuinely lives and breathes cybersecurity — like Remote Admin.
How can an external IT/security partner (like Remote Admin) help?
For most companies, building a full in-house cybersecurity team simply isn’t cost-effective. The sensible approach is to combine:
-
internal knowledge of your business processes,
-
an external partner who handles auditing, implementation, monitoring, and SOC.
Typical areas where a partner like this genuinely takes the load off the board:
-
conducting a compliance and risk audit (vCISO + security testing),
-
preparing an action roadmap broken into sensible phases,
-
implementing and configuring tools (backups, monitoring, logging, MFA, vulnerability scanning),
-
continuous vulnerability and incident monitoring (ReconMore, SOC),
-
support when dealing with supervisory authorities and auditors.
If you’d like to talk about this directly, feel free to reach out through the Remote Admin contact form.
FAQ: the questions boards ask most about NIS2
Does NIS2 only apply to large corporations?
No. The directive covers entities in specific sectors, often regardless of legal form, as well as suppliers of services to those sectors. A smaller IT company or software house serving an essential entity can also fall within NIS2’s scope.
Is having “good IT practices” enough to comply with NIS2?
Not always. NIS2 requires a documented approach to risk and security management — policies, procedures, plans, risk analyses, training. Good intentions from the IT department alone won’t replace a systematic approach.
Is NIS2 mostly paperwork, or do you actually need to change something?
If implementation comes down to documents alone, it will be ineffective and risky. The directive covers both organizational measures (policies, procedures) and technical ones (safeguards, monitoring, backups). One without the other doesn’t work.
How long does NIS2 implementation take at a typical company?
It depends on the size of the organization, the complexity of its systems, and its current level of security. At smaller companies, basic alignment (audit + priority actions) can take a few weeks to a few months. At larger ones, it’s usually a project spread over many months, broken into phases and priorities.
Do I have to report every security incident?
Not every minor incident requires a formal report, but NIS2 requires you to have clear procedures for classifying incidents and reporting the significant ones according to the guidelines. This has to be defined and documented — it can’t be an ad hoc decision.
What’s next? A practical next step for the board
The smartest move is to turn this checklist into concrete action:
-
Do an internal review — how many items on this list can you answer “yes, we have that” to?
-
Schedule a conversation with a security expert, for example through a vCISO service or SOC.
-
Build a phased implementation plan — from critical items to “nice to haves.”
