Bg Shape
Image

Why your NIS2 Gap Might Sit Outside IT

Aaron Smith
Information Security Lead
Published:
July 20, 2026

If your NIS 2 compliance plan stops at corporate IT, you may have missed the hardest part.

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS 2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS 2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS 2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The NIS 2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS 2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Read Our Latest Blogs

Blog Image
Three Things Security Leaders Must Know About NIS 2

Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.

Blog Image
Miasma Worm, Microsoft Mega Patch Tuesday & Defender Bypass

This week's Risk Radar covers the Miasma supply chain worm hitting 73 Microsoft GitHub repositories, the largest Patch Tuesday in Microsoft's history including a critical Secure Boot deadline, and a confirmed Microsoft Defender bypass that lets attackers elevate to SYSTEM privileges.

Blog Image
Why your NIS2 Gap Might Sit Outside IT

Discover why NIS2 readiness needs to move beyond policy documents and into operational response planning across IT, OT, and supplier ecosystems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Why your NIS2 Gap Might Sit Outside IT

Leadership and Resilience
NIS2
Data Security and Privacy
Aaron Smith
Information Security Lead
July 6, 2026

If your NIS 2 compliance plan stops at corporate IT, you may have missed the hardest part.

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS 2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS 2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS 2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The NIS 2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS 2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Aaron Smith

Information Security Lead

Aaron is the Information Security Consulting Leader at Smarttech247, advising organisations on reducing cyber risk through practical, real-world security strategies. He works closely with customers to assess risk, strengthen controls, and improve resilience across complex environments, translating security challenges into clear, actionable outcomes aligned with business priorities.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365