Skip to content

NIS2 stress test: What happens when email and identity services go down?

In brief: According to a Wire study, 62 percent of security leaders consider themselves well prepared for NIS2 compliance, while 48 percent simultaneously share sensitive data via unsuitable channels – the real test is the ability to act without email and central identity services.

Many companies have completed the formal implementation of NIS2, but according to a Wire study, what matters is operational capability in an actual emergency: 62 percent of the IT, security and compliance leaders surveyed consider themselves well prepared, while at the same time 48 percent occasionally share sensitive information via unsuitable channels.

NIS2 requires an initial early warning within 24 hours for significant security incidents, followed by a more detailed notification within 72 hours. These deadlines can only be met if responsibilities, reporting paths and communication channels have been clarified in advance and tested in everyday practice – not merely documented on paper. A survey commissioned by Wire reveals a discrepancy between perceived and actual preparedness: 62 percent of the IT, security and compliance leaders surveyed rate their organization as well or very well prepared for regulatory requirements. At the same time, 48 percent state that they at least occasionally share sensitive information via unsuitable channels, and for 61 percent, access rights to shared files remain active longer than intended.

For CISOs, this means that an attack rarely follows the course of an audit. If the email system is affected, teams switch to private messengers; if an external consultant cannot access the internal platform, files are shared via hastily set-up links; if management needs to make a quick decision, spontaneous chat groups form on private devices. From a NIS2 perspective, these workarounds are relevant because they undermine the controlled, traceable communication needed for timely reporting and robust incident documentation. A crisis team needs a trustworthy space for decisions, assessments and task allocation that functions independently of potentially compromised infrastructure – including reachability of management and collaboration between IT, legal, communications and external specialists.

In this context, the article does not primarily classify shadow IT as a discipline problem, but as a symptom of official systems lacking practical usability. Employees frequently resort to private messengers, personal email accounts or freely available file services when official solutions make collaboration with external parties, mobile teams, or work under time pressure more difficult. A system considered too complicated during normal operations will not be adopted in a crisis either – this also applies to emergency channels that are documented but never tested. The practical consequence for CISOs is that they should not measure their organization’s NIS2 maturity by the completeness of its documentation, but instead specifically test how the organization reacts when email, central identity services and familiar collaboration tools are unavailable or untrustworthy.


Source: www.it-daily.net · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: