Bg Shape
Image

Three Things Security Leaders Must Know About NIS 2

Aaron Smith
Information Security Lead
Published:
July 20, 2026

Here is the mistake I still see with NIS 2. Too many organisations treat it like a policy exercise for the security team. That misses the real shift.

NIS 2 puts management and leadership accountability front and centre. In practice, boards and senior leadership need to be able to answer three things:

  1. Are we in scope, and as what kind of entity?
  2. Do we have documented reporting paths for a serious incident?
  3. Have we actually rehearsed those decisions before a live event happens?

The hard part is not the controls. It is knowing who needs to act, who needs to be notified, and how fast those decisions can happen under pressure. That matters because NIS 2 incident notification runs on tight timelines: 24 hours for an early warning, 72 hours for an initial report, and 30 days for the final submission. Those windows do not move. If your leadership team has never walked through that process before an incident happens, the first time they do it will be during one.

Under NIS 2, management bodies can face personal sanctions for failures in oversight, including temporary bans from management roles. That is not a theoretical risk sitting in a legal footnote. It is a direct consequence of treating compliance as a security team problem rather than a leadership obligation.

The questions leadership should stop asking: "Are we compliant?"

The questions they should start asking: "Who owns the risk? Who signs off on the decisions? And have we tested the reporting process end to end?"

NIS 2 is governance under pressure. Not paperwork on a shelf.

Smarttech247 supports leadership teams with NIS 2 readiness, including board briefings, tabletop exercises, and incident reporting preparation. Talk to our team.

Read Our Latest Blogs

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Blog Image
Ghost Executive: The Fast-Growing Fraud Impersonating Your Leadership

A Ghost Executive attack is a form of business email compromise (BEC) in which a fraudster impersonates a senior figure to authorise a fraudulent payment or reroute a legitimate one. Read more at Smarttech247

Blog Image
Autonomous AI Attacks, Ransomware Disruption, and a Critical WordPress Threat

Explore this week's Risk Radar covering autonomous AI cyberattacks, the Anubis ransomware attack, and a critical WordPress vulnerability, with key guidance for CISOs.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Three Things Security Leaders Must Know About NIS 2

Data Security and Privacy
Leadership and Resilience
Aaron Smith
Information Security Lead
July 4, 2026

Here is the mistake I still see with NIS 2. Too many organisations treat it like a policy exercise for the security team. That misses the real shift.

NIS 2 puts management and leadership accountability front and centre. In practice, boards and senior leadership need to be able to answer three things:

  1. Are we in scope, and as what kind of entity?
  2. Do we have documented reporting paths for a serious incident?
  3. Have we actually rehearsed those decisions before a live event happens?

The hard part is not the controls. It is knowing who needs to act, who needs to be notified, and how fast those decisions can happen under pressure. That matters because NIS 2 incident notification runs on tight timelines: 24 hours for an early warning, 72 hours for an initial report, and 30 days for the final submission. Those windows do not move. If your leadership team has never walked through that process before an incident happens, the first time they do it will be during one.

Under NIS 2, management bodies can face personal sanctions for failures in oversight, including temporary bans from management roles. That is not a theoretical risk sitting in a legal footnote. It is a direct consequence of treating compliance as a security team problem rather than a leadership obligation.

The questions leadership should stop asking: "Are we compliant?"

The questions they should start asking: "Who owns the risk? Who signs off on the decisions? And have we tested the reporting process end to end?"

NIS 2 is governance under pressure. Not paperwork on a shelf.

Smarttech247 supports leadership teams with NIS 2 readiness, including board briefings, tabletop exercises, and incident reporting preparation. Talk to our team.

Aaron Smith

Information Security Lead

Aaron is the Information Security Consulting Leader at Smarttech247, advising organisations on reducing cyber risk through practical, real-world security strategies. He works closely with customers to assess risk, strengthen controls, and improve resilience across complex environments, translating security challenges into clear, actionable outcomes aligned with business priorities.

Contents:

NIS 2 Compliance Services

The hard part is not the controls. It is knowing who needs to act

Learn about how we can help

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365