The platform
Every layer, one platform — and the proof at the end of it.
Compliance is not demonstrated with products. It is demonstrated with evidence: policies that were actually applied, incidents with a timeline, coverage you can put a number on. This platform is chosen so that evidence is a by-product of running it — not a project you start the month the auditor calls.
Before the project
Where the technical measures usually fall apart.
Fragmented visibility
Endpoint, email, mobile and firewall report into separate consoles. Nobody correlates them, so nobody sees the attack as one story.
Email is still the way in
The native filter stops bulk spam, not targeted phishing or weaponised attachments aimed at your finance team.
Mobile is a blind spot
Phones reach mail, documents and business apps, and in most assessments they are the one layer with no monitoring at all.
Patching by goodwill
No vulnerability inventory and no remediation deadline means the maintenance measure has no evidence behind it.
Response is entirely manual
Isolating a machine depends on someone being available. A 24-hour reporting deadline becomes theoretical.
Nothing to show an auditor
The measures exist in a procedure, but cannot be demonstrated with reports, timelines or logs.
Each of those reads, in an auditor's wording, as a finding against a specific NIS2 measure. They are not operational inconveniences — they are the gaps that get written down.
The architecture
Every layer feeds one platform.
Prevention
Correlation
Response & evidence
One console
The 24-hour deadline is a reporting problem before it is a security problem.
An early warning has to say something concrete: which system, what impact, which vector, what you did about it. Gathered by hand from four separate consoles, that takes days. With one correlated timeline, the first notification is an export rather than an investigation.
What the 24-hour and 72-hour deadlines actually require →
Live threat-hunting console across correlated events.
Requirement → component → evidence
What each measure actually gets you, on paper.
Letters refer to the risk-management measures in Article 21(2) of Directive (EU) 2022/2555. National transpositions number the same ten measures differently — in Romania they appear as Article 13 of OUG 155/2024.
| Measure | What covers it | What the auditor is handed |
|---|---|---|
| (a) Risk analysis and information system security policies | XDR/XPR, vulnerability and patch management, external risk monitoring | Exposure and risk report, updated periodically, with the history of how it changed |
| (b) Incident handling | XDR/XPR, automated response playbooks, endpoint forensics | Complete incident timeline and forensic report, in the shape the authority asks for |
| (d) Supply chain security | Dark-web monitoring and external attack-surface management | External exposure report, including leaked credentials and brand impersonation |
| (e) Security in acquisition, development and maintenance, including vulnerability handling | Vulnerability and patch management | Vulnerability inventory, remediation deadlines, patch-compliance report per system |
| (f) Policies to assess the effectiveness of the measures | Platform dashboards and periodic reporting | A monthly indicator set: threats blocked, mean time to respond, agent coverage |
| (g) Basic cyber hygiene practices and training | Email and collaboration security, browser controls, mobile protection | User-behaviour statistics: blocked clicks, attempted access to malicious sites |
| (i) Human resources security, access control and asset management | Endpoint and mobile protection, browser data controls, account remediation | Asset inventory with security posture, data-control reports, record of blocked accounts |
What this platform does not cover
Cryptography (h), business continuity, backup and crisis management (c), and multi-factor authentication and secured communications (j) are separate chapters of a compliance programme. This platform supports them but does not cover them in full, and we would rather say so than let you find the gap during an audit — see Governance & Compliance and Consulting.
The central argument
The same features, bought four times, behave differently on the day it matters.
Four vendors
- Four consoles, four alerting models, four support contracts
- Correlating across layers stays a human job
- Response is applied by hand, layer by layer
- Audit evidence is assembled from separate exports, in different formats
- Every new integration is a project of its own
One platform
- One console, one policy model, one vendor accountable
- Endpoint, email, mobile and your existing perimeter correlated automatically
- An indicator blocked once propagates to every layer
- A single reporting set, mapped to the NIS2 measures
- Adding a module does not require an integration project
We lead with Check Point where it fits, and operate identity, endpoint, email, backup and monitoring tooling alongside it. Already standardised on Microsoft Defender, Fortinet, CrowdStrike or another stack? We integrate with and operate the one you already run — the methodology stays the same. A Check Point partner for over three years.
How it is delivered
Technology plus operation, not licences.
A stack nobody operates produces alerts, not compliance. The question an auditor asks is whether someone looked at them, and what they did next.
- 01
Implementation
Design, installation, policy tuning and cutting the false positives out of the first weeks.
- 02
Continuous operation
Monitoring, alert triage and policy updates as the infrastructure changes.
- 03
Incident response
Escalation, isolation, investigation, and help drafting the notification to the authority.
- 04
Compliance reporting
A periodic set of reports and dashboards, prepared for the security audit.
This is delivered as Threat Prevention & Response. Our role is the managed security service; the legal responsibility stays with your organisation — we deliver the implementation, the operation and the evidence.
Start with what your environment actually needs.
The free Security Checkup measures your current posture against these measures and gives you the gap list in writing.
No obligation. No sales pressure. Just facts about your environment.