Study tracks
NIS2 Track
A path for anyone who has to explain, implement or be interviewed on the EU's NIS2 Directive: compliance leads, security managers at in-scope companies, and engineers at their suppliers. It starts with the law itself, then walks the ten Article 21 measures and points each one at the material in this repo that shows how to implement it.
2 min read
3 sections
Part 1 — Understand the law
- What NIS2 is and why it matters — scope expansion, management liability, supply-chain reach
- Timeline and current status — transposition, infringements, the January 2026 proposal
- Who is in scope — size cap, Annex I and II sectors, essential vs important, DORA
- Article 20 — governance — board approval, oversight, training, liability
- Article 23 — incident reporting — 24 h, 72 h, one month
- Making NIS2 real — the six-step programme for a newly in-scope company
Part 2 — Implement the Article 21 measures
- (a) Risk analysis and security policies — risk management and the document stack
- (b) Incident handling — IR psychology, NIST SP 800-61 and reports and postmortems
- (c) Business continuity, backups, crisis management — business continuity and DR
- (d) Supply-chain security — supply-chain risk management, dependency management and cloud contract design
- (e) Secure acquisition, development and vulnerability handling — secure software development and CI/CD security
- (f) Assessing effectiveness — security assessment and testing
- (g) Cyber hygiene and training — security awareness and patch management
- (h) Cryptography and encryption — cryptography and TLS end to end
- (i) HR security, access control, asset management — access control models and the identity lifecycle and asset security
- (j) MFA and secured communications — MFA methods compared
Part 3 — Sector depth
- IEC 62443 — for energy, water, transport and manufacturing entities with operational technology
- Cloud operations, legal and contracts — for cloud, data-centre and managed service providers
- Detection engineering — spotting significant incidents early enough to meet the 24-hour clock
- Tabletop: run a ransomware scenario end to end and file a mock early warning within 24 hours