Bg Shape
Image

Why your NIS2 Gap Might Sit Outside IT

Aaron Smith
Information Security Lead
Published:
July 20, 2026

If your NIS2 compliance plan stops at corporate IT, you may have missed the hardest part.

The IT/OT Gap

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

Supplier Log Access Problem

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The Broader Question

The NIS2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Read Our Latest Blogs

Blog Image
8 SOC Platform Requirements for 24/7 Threat Monitoring

Evaluating a threat detection and response platform? Here are the 8 requirements for 24/7 monitoring, threat intelligence, and automated response.

Blog Image
Six Ransomware Groups That Emerged in 2026

67 new ransomware groups emerged in 2026, but only six are worth your attention. See how each operates, who they target, and what actually stops them.

Blog Image
VMware vCentre Backdoor, LiteLLM Supply Chain Attack & Azure Entra ID Targeted

China-backed APT exploits VMware vCentre, LiteLLM supply chain attack hits 2,500 pipelines, and Azure Entra ID targeted with stolen credentials.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Why your NIS2 Gap Might Sit Outside IT

Leadership and Resilience
NIS2
Data Security and Privacy
Aaron Smith
Information Security Lead
July 6, 2026

If your NIS2 compliance plan stops at corporate IT, you may have missed the hardest part.

The IT/OT Gap

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

Supplier Log Access Problem

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The Broader Question

The NIS2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Aaron Smith

Information Security Lead

Aaron is the Information Security Consulting Leader at Smarttech247, advising organisations on reducing cyber risk through practical, real-world security strategies. He works closely with customers to assess risk, strengthen controls, and improve resilience across complex environments, translating security challenges into clear, actionable outcomes aligned with business priorities.

Contents:

Get ready for NIS2

Smarttech247 supports organisations with NIS2 readiness across IT, OT, and supply chain

See how we can help

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365