Bg Shape
Image

Three Things Security Leaders Must Know About NIS 2

Aaron Smith
Information Security Lead
Published:
July 20, 2026

Here is the mistake I still see with NIS 2. Too many organisations treat it like a policy exercise for the security team. That misses the real shift.

NIS 2 puts management and leadership accountability front and centre. In practice, boards and senior leadership need to be able to answer three things:

  1. Are we in scope, and as what kind of entity?
  2. Do we have documented reporting paths for a serious incident?
  3. Have we actually rehearsed those decisions before a live event happens?

The hard part is not the controls. It is knowing who needs to act, who needs to be notified, and how fast those decisions can happen under pressure. That matters because NIS 2 incident notification runs on tight timelines: 24 hours for an early warning, 72 hours for an initial report, and 30 days for the final submission. Those windows do not move. If your leadership team has never walked through that process before an incident happens, the first time they do it will be during one.

Under NIS 2, management bodies can face personal sanctions for failures in oversight, including temporary bans from management roles. That is not a theoretical risk sitting in a legal footnote. It is a direct consequence of treating compliance as a security team problem rather than a leadership obligation.

The questions leadership should stop asking: "Are we compliant?"

The questions they should start asking: "Who owns the risk? Who signs off on the decisions? And have we tested the reporting process end to end?"

NIS 2 is governance under pressure. Not paperwork on a shelf.

Smarttech247 supports leadership teams with NIS 2 readiness, including board briefings, tabletop exercises, and incident reporting preparation. Talk to our team.

Read Our Latest Blogs

Blog Image
Three Things Security Leaders Must Know About NIS 2

Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.

Blog Image
Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

This week's Risk Radar covers the Miasma supply chain worm hitting 73 Microsoft GitHub repositories, the largest Patch Tuesday in Microsoft's history including a critical Secure Boot deadline, and a confirmed Microsoft Defender bypass that lets attackers elevate to SYSTEM privileges.

Blog Image
Why your NIS2 Gap Might Sit Outside IT

Discover why NIS2 readiness needs to move beyond policy documents and into operational response planning across IT, OT, and supplier ecosystems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Three Things Security Leaders Must Know About NIS 2

Data Security and Privacy
Leadership and Resilience
Aaron Smith
Information Security Lead
July 4, 2026

Here is the mistake I still see with NIS 2. Too many organisations treat it like a policy exercise for the security team. That misses the real shift.

NIS 2 puts management and leadership accountability front and centre. In practice, boards and senior leadership need to be able to answer three things:

  1. Are we in scope, and as what kind of entity?
  2. Do we have documented reporting paths for a serious incident?
  3. Have we actually rehearsed those decisions before a live event happens?

The hard part is not the controls. It is knowing who needs to act, who needs to be notified, and how fast those decisions can happen under pressure. That matters because NIS 2 incident notification runs on tight timelines: 24 hours for an early warning, 72 hours for an initial report, and 30 days for the final submission. Those windows do not move. If your leadership team has never walked through that process before an incident happens, the first time they do it will be during one.

Under NIS 2, management bodies can face personal sanctions for failures in oversight, including temporary bans from management roles. That is not a theoretical risk sitting in a legal footnote. It is a direct consequence of treating compliance as a security team problem rather than a leadership obligation.

The questions leadership should stop asking: "Are we compliant?"

The questions they should start asking: "Who owns the risk? Who signs off on the decisions? And have we tested the reporting process end to end?"

NIS 2 is governance under pressure. Not paperwork on a shelf.

Smarttech247 supports leadership teams with NIS 2 readiness, including board briefings, tabletop exercises, and incident reporting preparation. Talk to our team.

Aaron Smith

Information Security Lead

Aaron is the Information Security Consulting Leader at Smarttech247, advising organisations on reducing cyber risk through practical, real-world security strategies. He works closely with customers to assess risk, strengthen controls, and improve resilience across complex environments, translating security challenges into clear, actionable outcomes aligned with business priorities.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365