NIS2 is coming, and many SMEs are asking themselves: “Does this apply to us — and what do we need to do right now?” This article gives you a practical checklist in plain language. No legal smoke and mirrors, just concrete actions.
1) Determine whether NIS2 applies to your organisation
Do you fall under essential or important sectors, or do you deliver critical services in the supply chain? Then preparation is wise — even if you’re only indirectly affected through customers or contract requirements.
2) Map your critical systems
Which systems absolutely need to keep running? Think:
- Microsoft 365 / email
- Accounting
- CRM
- Production/operations
- Backups
3) Enable MFA everywhere you can
MFA on email, admin accounts, VPN and cloud environments is one of the fastest ways to reduce risk.
4) Restrict admin rights
Not everyone needs to be a local admin. Fewer rights means less impact in the event of an incident.
5) Patch policy: rhythm and ownership
Define who patches, when it happens, and how you verify updates were actually applied.
6) Test backup and recovery
Not just “we make backups” — but also: can you actually recover within an acceptable time?
7) Incident response on one page
Who do you call first? Who decides? Who communicates internally/externally? A simple runbook page prevents chaos.
8) Check suppliers and supply chain risks
Which parties have access to your data or systems? Document minimum security requirements.
9) Security awareness for employees
Short, repeated training works better in practice than one long annual session.
10) Start with a baseline assessment
Have your current situation assessed and create a realistic quarterly improvement plan.
A common mistake
Waiting for “full clarity” and therefore doing nothing. Most of the gain comes from basic measures you can take right now.
Conclusion
NIS2 doesn’t have to be a panic project. With a clear baseline, priorities and monthly improvement steps, you get in control quickly.
Want to know where your organisation stands right now?
Schedule a short security intake with MonkeysICT.
Related articles
- AI security and pentesting
- AI and advanced exploits
- Pentest in Hoofddorp and Amsterdam
- API pentest
- Web application pentest
- Request a quote
More information
