NIS2 GAP analysis and action plan
What tasks need to be performed to build an NIS2 information security management system? What impact will these have on the company’s existing procedures and policies? How long will it take and how much will it cost to prepare for NIS2?
These are among the most frequently asked questions about the new rules concerning cybersecurity supervision and certification.
To whom do we recommend our NIS2 GAP analysis service?
We recommend our NIS2 preparatory analysis service to CEOs and managers who want to get a comprehensive analysis and action plan to prepare themselves to comply with the requirements of Act XXIII of 2023 on Cybersecurity Certification and Cybersecurity Supervision.
Our approach involves a comprehensive and practical process that is tailored to your company’s specific needs.
Want to know more about our NIS2 GAP analysis service? Click to make an appointment with one of our experts!Why choose our NIS2 GAP analysis service?
- Classification: We identify your information systems and processes and classify them into security classes.
- Analysis of local policies and practices: We assess your current security measures and review related policies.
- Analysis of company group relations:We consider the impact of the parent company or subsidiaries on NIS2 compliance
- Analysis of third-party relations: In the case of external support, we conduct an analysis and discussion of the outsourced tasks.
- GAP analysis and reporting: We perform a risk analysis and prepare an action plan to mitigate the risks.
How do we prepare your company for NIS2 compliance?
- We help you accurately assess, analyse and prioritise the tasks required to build an NIS2 information security management system.
- We perform the security classification of your Electronic Information Systems (EIS) based on the criteria and damage impacts defined in the legislation. We review existing policies and practices through questionnaires and online interviews. If necessary, we also conduct a face-to-face meeting or a site visit.
- For company groups, we also consider the impact of affiliates on the company’s NIS2 compliance. In the case of contributors and IT suppliers, we carry out an assessment of outsourced services.
- We participate in the preparation of the compulsory official notification (to be given to SZTFH, the Supervisory Authority for Regulated Activities), and provide support during the registration process.
- Through the GAP analysis, we prepare a detailed action plan, which provides a clear picture of the tasks required to comply with the legal points of control specified in the relevant provision of law.
Implementation
The implementation of NIS2 protection measures can take 3-9 months depending on the content of the action plan and the objectives set, which we can support with additional expert services if required.