NIS2 · Cyber Resilience
NIS2 Consulting for Critical Infrastructure and Regulated Organizations
Insight42 checks whether you are in scope, analyzes gaps against the risk management measures of Section 30 BSIG and implements the technical and organizational measures – from identity and logging to incident response and cloud security. With evidence you can show to auditors and customers.
NIS2 is an implementation project, not a paperwork project
With Germany’s NIS2 implementation act (NIS2UmsuCG), binding obligations on risk management, incident reporting and supply chain security apply to far more organizations. What matters is that measures actually work and can be evidenced.
We connect technical implementation and compliance: every measure gets an owner, evidence and a mapping to the frameworks you already serve.
Note: We advise on technical and organizational implementation. We do not replace legal advice.
Our NIS2 services
1. Scope check: are you affected?
Based on sector, size and activity, we check whether your organization is likely to qualify as an essential or important entity, which units and services are in scope, and which obligations follow – such as registration with the BSI. Please confirm the legal assessment with your legal counsel.
2. Gap analysis
We compare your current state with the risk management measures of Section 30 BSIG, assess existing controls, document gaps and prioritize them by risk and effort. The result is an actionable roadmap with clear ownership.
3. Risk management
Building or sharpening your risk register, crown-jewel analysis and security policies – so risks are assessed regularly and measures are managed in a traceable way.
4. Identity, MFA & PAM
Strong identity as the foundation: MFA for all access, privileged access management with just-in-time rights, conditional access and regular access reviews in a zero-trust model.
5. Supply chain security
Assessment of service providers and cloud vendors, security requirements in contracts and evidence such as C5 attestations. For software supply chains we implement code signing and provenance.
6. Incident response
Incident response plan, playbooks and exercises, plus defined reporting paths so significant security incidents can be reported to the BSI on time.
Detect, keep operating, prove it
7. Logging & monitoring
Central logging, SIEM/SOAR use cases and alerting, so attacks are detected early and incidents can be traced end to end.
8. Business continuity
A backup strategy with immutable backups, restore tests against defined RTO/RPO, and emergency and crisis management.
9. Cloud security
Secure landing zones, cloud security posture management across multi-cloud environments, network segmentation, and encryption with key custody – see our key management consulting.
10. Evidence & audit readiness
Every measure gets an owner and evidence – automated wherever possible: exported access reviews, logged restore tests, attested configurations. That prepares you for audits, BSI evidence requests and your customers’ security questionnaires.
11. Mapping to BSI C5 and ISO 27001
Hardly any organization has only NIS2 on its plate. We map measures to existing frameworks so one piece of evidence serves several requirements: an existing ISO 27001 ISMS is a good starting point, and the risk management measures of Section 30 BSIG as well as the supply chain obligations can largely be evidenced with C5 controls. More in our BSI C5 consulting.
How NIS2-ready is your organization?
In a 30-minute initial call we clarify whether you are likely to be in scope, where your implementation stands and whether a NIS2 readiness assessment makes sense for you.
Why Insight42
- Regulated-market focus: we work with enterprises and public-sector organizations in Germany and Europe, and design architectures aligned with BSI C5, NIS2 and GDPR.
- End-to-end delivery: assessment, architecture, implementation and operations from one team — founded and led by Martin-Peter Lambert in Ingolstadt.
- Engineers who ship: we build and operate our own products — Secretary42, Unimatrix-OI and InheritanceVault — and bring the same production discipline to client work.
- Sovereignty by design: data residency, key custody (BYOK/HYOK) and a documented exit strategy are design inputs from day one.