Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


If your NIS 2 compliance plan stops at corporate IT, you may have missed the hardest part.
Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.
That gap matters under NIS 2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.
Then a second problem appears: supplier dependency.
During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS 2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.
Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS 2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.
The NIS 2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?
NIS 2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.
Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.
We protect your on-premise/cloud/OT environments - 24x7x365