Penetration testing
Preambul 86 of NIS2 highlights the essential role of penetration testing in assisting entities to prevent, detect, respond to, and recover from incidents, while also emphasizing the importance of exercising increased diligence in selecting security measures due to inherent risks. Penetration testing identifies vulnerabilities in networks and information systems, which is critical to meeting the requirements of NIS2 Article 21 for “appropriate and proportionate technical, operational and organisational measures to manage security risks”. By identifying and addressing security weaknesses, penetration testing ensures that organisations can maintain continuous operations and minimise downtime, fulfilling NIS2’s emphasis on resilience. In addition, regular penetration testing provides the documented evidence of implemented security measures needed to demonstrate compliance during audits and avoid penalties. Penetration testing is therefore a key component in achieving and maintaining NIS2 compliance.
Code review
Code Review is a fundamental step for organisations seeking to meet the requirements of the NIS2 Directive, as highlighted in Preamble 85. Essential and important organisations need to assess and ensure the overall quality and resilience of their products and services. Organisations can improve the security posture of their software by incorporating thorough code reviews to identify and mitigate vulnerabilities early in the development process. This proactive approach not only aligns with the mandates of NIS2, but also strengthens the organisation’s defences against cyber threats. Article 21 emphasises the need for continuous monitoring and updating of security measures. Through systematic code review, organizations demonstrate compliance with the NIS2 obligation to implement technical and organizational measures to reduce cyber risks and ensure the integrity, confidentiality and availability of their systems and services.
Security Consulting/Supporting
Security support and consulting is essential to meet the specific requirements of the EU’s NIS2 Directive, directly improving cyber resilience across member states. These services help organisations to identify and mitigate vulnerabilities and align their practices with the strict standards of the Directive by providing expert guidance. Specifically, as noted in Preamble 86, the directive emphasises the importance of state-of-the-art cybersecurity measures and continuous improvement. Consultants provide tailored solutions and ongoing support, facilitating compliance through regular assessments and updates. This proactive approach not only fulfils regulatory obligations, but also strengthens the overall security posture, protecting critical infrastructure from evolving threats.