NIS2 requires companies to establish structured governance, implement technical security measures, and maintain demonstrable incident-response processes, for which CISOs must assume full responsibility at board level.
NIS2 requires organisations to ensure security awareness functions in real work situations and does not remain merely theoretical knowledge — a focus on behavioural change rather than compliance documentation.
A security vulnerability in Exchange Online allows email sender spoofing under certain conditions, facilitating phishing and social engineering attacks.
Validato enables organizations in critical infrastructure to document human security risks in an audit-ready manner, thereby meeting NIS2, CER, and ISO-27001 requirements.
Operational Technology in factories presents attackers with significantly lower barriers than modern IT infrastructure, while cyber outages in production have existential consequences.
Official NIS2 compliance audits begin on June 30, 2024, and will verify the actual implementation of cybersecurity measures at critical infrastructures and important digital services.
Deutsche Telekom and Palo Alto Networks jointly operate a security platform on European infrastructure with local key management to combine cyber defense and data sovereignty.