Bg Shape
Image

Why your NIS2 Gap Might Sit Outside IT

Aaron Smith
Information Security Lead
Published:
July 20, 2026

If your NIS 2 compliance plan stops at corporate IT, you may have missed the hardest part.

The IT/OT Gap

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS 2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

Supplier Log Access Problem

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS 2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS 2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The Broader Question

The NIS 2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS 2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Read Our Latest Blogs

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Blog Image
Ghost Executive: The Fast-Growing Fraud Impersonating Your Leadership

A Ghost Executive attack is a form of business email compromise (BEC) in which a fraudster impersonates a senior figure to authorise a fraudulent payment or reroute a legitimate one. Read more at Smarttech247

Blog Image
Autonomous AI Attacks, Ransomware Disruption, and a Critical WordPress Threat

Explore this week's Risk Radar covering autonomous AI cyberattacks, the Anubis ransomware attack, and a critical WordPress vulnerability, with key guidance for CISOs.

Bg ShapeBg Shape
BLOGS & INSIGHTS

Why your NIS2 Gap Might Sit Outside IT

Leadership and Resilience
NIS2
Data Security and Privacy
Aaron Smith
Information Security Lead
July 6, 2026

If your NIS 2 compliance plan stops at corporate IT, you may have missed the hardest part.

The IT/OT Gap

Most organisations understand their IT risk considerably better than their OT risk. That is not surprising. OT environments grew up separately, under different teams, with different ownership, different tooling, and different operational priorities. The two worlds were never designed to converge, and in many organisations they still have not.

That gap matters under NIS 2. Sectors with significant OT exposure, manufacturing, energy, aviation, healthcare, are among those facing the highest scrutiny. Understanding where IT and OT connect, and who actually governs those touch points, is now a compliance requirement, not a best practice.

Then a second problem appears: supplier dependency.

Supplier Log Access Problem

During live incidents, one of the most critical bottlenecks is log access. Logs are needed from a supplier to support containment and remediation, but those logs do not arrive until months later because of access restrictions, segregation, and contract obligations that were never aligned in advance. That is not a technical footnote. That is an incident response delay at the exact moment when speed matters most. NIS 2 mandates early warning within 24 hours and a full incident report within 72. Supplier contracts that were not written with those timelines in mind will break your response.

Only 37% of organisations have full visibility into supplier cybersecurity practices. Existing contracts typically do not contain NIS 2 clauses, and re-papering takes years. This is one of the areas where programmes most commonly stall.

The Broader Question

The NIS 2 question for IT and security leaders is broader than "are we monitoring our OT?" A better question is: where do IT, OT, and supplier environments connect? Who owns those touch points? And what happens contractually during a live incident?

NIS 2 pushes supply chain security and business continuity into the same conversation. For organisations with operational technology, that conversation needs to happen now, not after an outage.

Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain environments, including gap assessments, third-party risk management, and 24/7 MDR. Talk to our team.

Aaron Smith

Information Security Lead

Aaron is the Information Security Consulting Leader at Smarttech247, advising organisations on reducing cyber risk through practical, real-world security strategies. He works closely with customers to assess risk, strengthen controls, and improve resilience across complex environments, translating security challenges into clear, actionable outcomes aligned with business priorities.

Contents:

Get ready for NIS 2

Smarttech247 supports organisations with NIS 2 readiness across IT, OT, and supply chain

See how we can help

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365