NIS2 compliance
Applicability file, registration with DNSC, policies and procedures for all ten categories of measures, approved by management.
Applicability and registration
We do not filter ports and IP addresses alone. Each control interrupts a concrete stage of the attack, and the measures become verifiable evidence for the obligations NIS2 legislation places on your organisation.
Four phases, each interrupted by a different control.
The target is profiled from public addresses and information exposed through unencrypted DNS. Encrypted resolution and a reduced footprint make enumeration difficult.
Open ports are searched for in the range 1–65535. The controls respond with a silent drop, returning nothing useful to the attacker.
The attacker exploits a vulnerable service, attempts brute-force or credential stuffing and delivers malicious payloads. The pattern is identified and the source blocked.
Persistence, Command and Control, and lateral movement towards critical data. This stage is limited by network segmentation and continuous monitoring.
Five areas of work, each delivering the document or the control the law requires, not just a recommendation.
Applicability file, registration with DNSC, policies and procedures for all ten categories of measures, approved by management.
Applicability and registration
Assessment of the risk level, maturity self-assessment, gap analysis against the applicable level, and a prioritised measures plan.
Risk and maturity
Firewall with Layer 7 inspection, segmentation and VLANs, multi-factor authentication, hardening, encryption, logging and vulnerability management.
Implementation and hardening
Outsourced security officer, continuous monitoring and response, incident response, backup and restore tests.
Monthly subscription
Early warning, notification with an initial assessment and a final report, within statutory deadlines counted in hours, not working days.
24 h · 72 h · 1 month
Each stage is clearly delimited, produces a required document and prepares the next step.
An inventory of services, mapping to the annexes, the entity type and the article 9 analysis, with a documented conclusion.
Standard form, supporting documents, electronic signature and correspondence with the competent authority.
The risk level in the national platform, the impact of disruption and a register kept up to date.
Maturity self-assessment, gap analysis and remediation priorities, with deadlines approved by management.
Our own platform installed at a single point of control, through which all traffic between the internet and the internal network passes.
Isolated zones that limit lateral movement and the blast radius of a compromise.
Behavioural detection, continuous monitoring and automatic blocking of sources showing attack patterns.
Containment, eradication and recovery, with reporting to DNSC within the statutory 24 hours and periodic restore tests.
The applicability analysis answers that question and stands as evidence whatever the conclusion. Falling outside the law is not assumed: it has to be documented.
Your browser appears to be rendering this page without GPU acceleration, which can cause stutter on this site.