Security Notes
Study tracks

NIS2 Track

A path for anyone who has to explain, implement or be interviewed on the EU's NIS2 Directive: compliance leads, security managers at in-scope companies, and engineers at their suppliers. It starts with the law itself, then walks the ten Article 21 measures and points each one at the material in this repo that shows how to implement it.

2 min read 3 sections

Part 1 — Understand the law

Part 2 — Implement the Article 21 measures

Part 3 — Sector depth

  • IEC 62443 — for energy, water, transport and manufacturing entities with operational technology
  • Cloud operations, legal and contracts — for cloud, data-centre and managed service providers
  • Detection engineering — spotting significant incidents early enough to meet the 24-hour clock
  • Tabletop: run a ransomware scenario end to end and file a mock early warning within 24 hours