Scope & applicability
We analyze the services, sector, size, jurisdiction and context of the organization to identify obligations to be validated.
Risk management, incidents, continuity, supply chain, identity, vulnerability management and governance — organized into a program that can be operated and demonstrated continuously.
Operational resilience
NIS2 combines risk management, governance, incident readiness, resilience and supplier relationship. Measures must be technical, operational and organizational and tailored to the organization’s risk.
Readiness means starting from real services and systems, identifying gaps and being able to demonstrate in time how relevant measures are operated.
Readiness program
Readiness doesn’t start with a list of products; it starts with the services, risks and responsibilities of the organization.
We analyze the services, sector, size, jurisdiction and context of the organization to identify obligations to be validated.
We link assets, services, threats, dependencies and providers to operational risk and impact scenarios.
We turn gaps into a program of technical, operational and organizational measures with clear owners and priorities.
We define sorting, escalation, communication, evidence retention and the process required for applicable notifications.
Reviews, tests, supplier assessments, training and infrastructure changes remain related to the measures you need to be able to demonstrate.
Risk-management measures
The areas are not isolated technical controls. They cover governance, people, suppliers, continuity, development, identity and verification of effectiveness.
Risk methodology, policies and ownership that reflects real services and systems.
Detection, sorting, containment, communication and response process that can operate under pressure.
Backup, disaster recovery, crisis management and recovery scenarios testing.
The risks posed by suppliers and service providers are assessed and monitored throughout the relationship.
Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
Procedures to check whether cybersecurity measures really work and need to be adjusted.
Basic practices, awareness and training for management and staff, proportionate to roles and risk.
Policies and procedures for the use of cryptography and, where appropriate, encryption.
Human resources security, access control, inventory and ownership of relevant assets.
Multi-factor authentication and secure communication channels where the context demands.
Governance
Ownership, oversight and risk context cannot remain exclusively in the technical team.
Risk management measures do not remain exclusively to the technical team; management must have visibility and ownership over the applicable program.
The status of measures, risks, incidents and gaps must be able to be reviewed at the appropriate level of the organization.
Members of management bodies and relevant staff must have sufficient context to understand the cybersecurity risks and practices affecting their services.
Approvals, risk acceptance and significant actions must be traceable, not just informally discussed.
Incident readiness
If sorting, escalating and communicating are not prepared, the process becomes much harder to execute when the service is already under pressure.
You determine what happened, which services are affected, and whether the incident can fall into the category of those to be.
You enable technical and management owners, limit impact, and keep the information needed for investigation and reporting.
The internal process must be able to support the notification steps provided by the applicable framework, without improvising the recipients and information during the incident.
Recovery, root-cause analysis and corrective actions return to the risk register, controls and continuity program.
Supply chain
A critical service can depend on cloud, software, telecom, identity, hosting, support or other providers. The program must be able to explain these dependencies.
Identify the providers and services on which the operations or security of the systems within the scope depend.
Technical, contractual and operational requirements are aligned with the risk that the relationship introduces.
Evaluations, documents and findings do not remain a one-off check; they are reviewed when the relationship or service changes.
You analyze dependencies that can turn the unavailability of a single provider into a significant business incident.
Technical remediation
GRC readiness does not replace hardening, monitoring, identity security, vulnerability management or incident response.
Vezi Cyber SecurityAttack surface, configurations and technical gaps prioritized by risk.
02WAF, hardening, monitoring and recovery for publicly exposed applications.
03Domain authentication, identity hardening and protection against impersonation.
04Triage, containment, recovery and lessons learned connected to the risk program.
Legal reference
Directive (EU) 2022/2555 was transposed into Romania by OUG no. 155/2024, approved with amendments and supplements by Law no. 124/2025.
The page is oriented towards readiness and operations. For the final legal classification or interpretation of a specific obligation, the legal form in force and, if necessary, the competent legal specialist should be checked.
Practical examples from the platform library about compliance and security programs built for growing organizations.
See all case studies.We can perform a technical and operational scope assessment and identify relevant indications regarding the sector, size, services and jurisdiction. For a final legal classification or a specific exception, the legal form in force and, where appropriate, the competent legal specialist must be used.
No. The framework includes technical, operational and organizational measures on risk management, incident handling, business continuity, supply-chain security, vulnerability handling, access control, training and other areas.
Not automatically. Readiness starts from the existing environment, risks and gaps. Measures must be appropriate and proportionate to the risk, and remediation is prioritized around the actual impact.
AISO27001 ISMS can provide useful structure for risk management, controls and evidence, but the two frameworks are not identical and one does not automatically replace the obligations of the other.
Security assessment, identity hardening, website/email security, vulnerability remediation, incident readiness and secure managed hosting can support controls and measures when they are relevant to the program.
We evaluate the current situation, prioritize measures and build a program that you can maintain after the first evaluation.
Talk about ZBTKEEP
Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.