All news

9 July 2026 / 17 minutes of reading

NIS2: 10 Mistakes Organizations Still Make During Implementation

Even today, many organizations are still asking the same questions about NIS2.


Key Takeaways

  • NIS2 is not a one-time compliance project. It is a continuous cybersecurity risk management process.
  • The biggest mistake organizations make is focusing on documentation before understanding their risks and critical assets.
  • Cybersecurity is no longer just an IT responsibility. Executive management, HR, legal, procurement and business owners all play a key role.
  • Technology alone is not enough. Without regular testing, you cannot be sure your security controls are actually working.
  • Organizations should pay close attention to their internal environment, cloud services and supply chain, as these are among the most common attack vectors.
  • Passing an audit is not the goal. The objective is to continuously improve the organization's cyber resilience.
  • Continuous monitoring, vulnerability management and regular validation of security controls are essential for successful NIS2 implementation.

NIS2 is already reshaping cybersecurity across the European Union. Organizations should now focus on validating whether their technical and organizational security measures are actually effective, rather than simply preparing for compliance assessments. After reading this article, you can download the NIS2 Executive Readiness Assessment free of charge. This practical document will help you assess your organization's readiness to meet the requirements of the NIS2 Directive.

Free Checklist

Find out in minutes how prepared your organization is for NIS2

Download the free NIS2 Executive Readiness Assessment to evaluate your organization's readiness and identify the areas that require your attention.

Assess your organization's readiness
Identify your biggest risks
Receive practical next-step recommendations
Download the Free Checklist

The biggest change introduced by NIS2 is not additional documentation or regulatory requirements. It is a fundamental shift in how organizations approach cybersecurity. In other words, NIS2 is not a project. It is a risk management framework. Organizations invest in new security technologies without understanding which systems are truly critical to their business. They produce dozens of security policies without ever validating whether they could recover from a ransomware attack. They complete compliance assessments while remaining unaware that a single misconfigured account could provide an attacker with administrative privileges. Even successfully passing an NIS2 audit does not necessarily mean an organization is prepared for a realistic Red Team exercise. An audit verifies compliance with regulatory requirements, while Red Teaming evaluates an organization's ability to detect, withstand and respond to real-world attacks. This is not a legislative problem. It is a prioritization problem.

Organizations invest in new security technologies without understanding which systems are truly critical to their business. They produce dozens of security policies without ever validating whether they could recover from a ransomware attack. They complete compliance assessments while remaining unaware that a single misconfigured account could provide an attacker with administrative privileges. This is not a legislative problem. It is a prioritization problem.

security.png

Rather than analyzing legal requirements article by article, this guide focuses on the practical side of NIS2 implementation. We will examine the most common mistakes organizations make and explain how to build a cybersecurity program that not only supports compliance but also improves resilience against real-world cyber threats.

Where Does NIS2 Implementation Stand Today?

The NIS2 Directive is already being implemented across the European Union through national legislation. Organizations operating in sectors covered by the Directive are now moving from planning to execution, implementing technical and organizational measures designed to improve their cybersecurity resilience.

Compared to the original NIS Directive, NIS2 significantly expands the scope of regulated organizations. It applies to a much broader range of essential and important entities operating in sectors such as energy, healthcare, transport, digital infrastructure, manufacturing, public administration and managed IT services.

This is the right time to verify whether your security controls actually work in practice. Successful NIS2 implementation is not measured by the amount of documentation an organization produces, but by its ability to withstand real cyber threats.

A practical implementation roadmap may look like this:

NIS2 Implementation Roadmap (EN)-selection (1).pngAlthough this sequence appears straightforward, many organizations take the opposite approach. Instead of identifying risks first, they immediately focus on technologies, documentation or compliance audits.

This often leads to unnecessary costs, duplicated work and delayed implementation. The following chapters explain the most common mistakes and how to avoid them.

Mistake #1: Starting with Documentation

One of the first reactions to NIS2 is often an attempt to produce every required policy, procedure and security document. Information security policies, Incident Response Plans and Business Continuity Plans are all important. The problem begins when documentation becomes the objective instead of the tool.

Imagine two organizations. The first has comprehensive security documentation but has never tested its backup recovery process or its ability to respond to a cybersecurity incident. The second has fewer documents but performs regular penetration tests, validates the configuration of critical systems and exercises its incident response procedures. Which organization is better prepared for a real cyberattack?

Documentation exists to support security processes. It does not protect an organization by itself. NIS2 therefore focuses not on the existence of documents, but on an organization's ability to manage risks and demonstrate that implemented security measures are effective in practice.

Mistake #2: Treating Cybersecurity as an IT Problem

Cybersecurity has long ceased to be an IT-only discipline. Modern attacks exploit business processes, human error and weaknesses in third-party relationships just as often as technical vulnerabilities. This is why NIS2 extends well beyond IT infrastructure. Effective implementation requires involvement from the entire organization.

Executive management approves investments and accepts business risks. HR manages onboarding, offboarding and employee awareness. Procurement selects vendors who may gain access to critical systems. Legal teams handle contractual obligations and regulatory requirements. If any of these functions are missing from the process, technical controls alone will not provide adequate protection.

Successful NIS2 implementation is therefore not an IT project. It is an organizational project.

Mistake #3: Investing in Technology Before Understanding Your Risks

When organizations become subject to NIS2 requirements, one of the first reactions is often to invest in new security technologies. EDR, SIEM, PAM and other security solutions are deployed with the expectation that they will significantly improve the organization's security posture.

Technology is an essential part of cybersecurity, but it is not the starting point.

Organizations first need to understand their own environment. Which systems are critical to business operations? What data do they process? Which services must remain available during an incident? What would be the business impact if these assets were compromised?

Without answering these questions, it is impossible to prioritize investments effectively. An organization may deploy best-in-class security solutions while overlooking the single weakness that represents its greatest risk. This is why NIS2 places risk assessment and risk management at the core of every cybersecurity program.

Mistake #4: Assuming Your Security Controls Actually Work

Many organizations believe their security controls are effective simply because they have been in place for years. They use multi-factor authentication, firewalls, network segmentation and regular backups. However, that does not automatically mean these controls are properly configured or capable of stopping modern attacks.

Security cannot be measured by the number of technologies you have implemented. It must be validated regularly.

Penetration testing demonstrates how a real attacker could compromise your environment. Security assessments identify configuration weaknesses before they are exploited. Red Team exercises evaluate how well the organization can detect and respond to sophisticated attacks. Equally important is regularly testing backup recovery procedures and the readiness of the Incident Response team.

The greatest risk is not the absence of security technology. The greatest risk is assuming everything works simply because nobody has ever verified it. Our own findings from the Ethical Hacking Report 2025 confirm this. More than 53% of the projects we tested contained at least one high-severity vulnerability, 30% contained a critical vulnerability, and every single project contained at least one medium-severity vulnerability.

If you are not confident that your security controls work in practice, we can help you validate them independently.

Mistake #5: Overlooking Supply Chain Risk

Cybercriminals increasingly avoid attacking their primary target directly. Instead, they look for the weakest link in the supply chain. That may be an IT service provider, a software vendor, a cloud platform or any third party with access to internal systems.

This is one of the reasons why NIS2 places much greater emphasis on supply chain security than previous legislation. Organizations should understand which suppliers have access to critical systems, what security requirements apply to them and how supplier-related risks are assessed on an ongoing basis.

This does not mean auditing every single supplier. It means identifying the third parties whose compromise could have the greatest business impact and applying an appropriate level of security oversight.

Mistake #6: Focusing Only on External Threats

When people think about cyberattacks, they often imagine attackers attempting to break through an internet-facing firewall. In reality, many attacks begin much more simply. An attacker steals a user's credentials, compromises a workstation and then moves laterally through the internal network.

Protecting the perimeter is no longer enough. Organizations must also understand the security of their internal environment.

One of the most common targets is Active Directory. Once attackers obtain privileged access, they can often take control of a significant portion of the organization's infrastructure. In many cases, this is not the result of sophisticated exploits, but of excessive privileges, outdated configurations or poorly managed identities.

Regularly reviewing identities, privileged accounts and internal security configurations should therefore be a fundamental part of every organization's cybersecurity program.

Mistake #7: Assuming Cloud Security Is the Cloud Provider's Responsibility

Moving systems to the cloud improves flexibility and scalability, but it also introduces new security challenges. Many organizations mistakenly believe that once workloads are migrated to the cloud, cybersecurity becomes the provider's responsibility.

In reality, cloud security follows a shared responsibility model. While the provider is responsible for securing the underlying infrastructure, the organization remains responsible for identity management, access control, data protection, service configuration and security policies.

Misconfigured cloud services remain one of the leading causes of data breaches. Publicly accessible storage, excessive permissions and missing multi-factor authentication are rarely the provider's fault. They are usually the result of incorrect configuration.

Cloud adoption does not eliminate security responsibilities. It changes them. Our own findings support this. According to the Ethical Hacking Report 2025, 42% of cloud security projects contained at least one critical vulnerability, while cloud environments recorded the highest average number of vulnerabilities per project.

Mistake #8: Treating Cybersecurity as an Audit Exercise

Many organizations devote most of their cybersecurity effort to the months leading up to an audit or regulatory assessment. Documentation is updated, obvious weaknesses are addressed and, once the audit is complete, security initiatives gradually lose momentum.

This approach was already ineffective before NIS2. Under the new regulatory framework, it makes even less sense.

Cybersecurity is constantly evolving. New vulnerabilities emerge every day, infrastructures change, new applications are deployed and cloud environments continue to grow. A single audit provides only a snapshot of the organization's security posture at a specific point in time.

Organizations with mature cybersecurity programs treat security as a continuous process. They regularly assess their environment, validate security controls, monitor emerging threats and remediate weaknesses before attackers can exploit them.

This continuous improvement mindset lies at the heart of NIS2. The objective is not to prepare for a single audit, but to establish a cybersecurity program that continuously improves the organization's resilience against evolving threats.

Mistake #9: Underestimating Incident Response

Many organizations have an Incident Response Plan. Far fewer know whether it would actually work during a real cyber incident.

Responding to an incident is not simply about knowing who to call. Teams must understand their responsibilities, management must be able to make decisions under pressure and the organization must know how to communicate with customers, business partners, regulators and the public.

A ransomware attack or a major data breach rarely happens under ideal conditions. Decisions have to be made quickly, information is incomplete and every minute of downtime increases the business impact. Organizations that have never tested their Incident Response process often discover during the incident that contact lists are outdated, responsibilities are unclear or recovery procedures cannot be executed as planned.

Incident response readiness cannot be measured by the existence of a document alone. It requires regular exercises, realistic technical scenarios, executive involvement and continuous improvement. A good Incident Response process is not the one that looks impressive on paper. It is the one that works when the organization has no time to think.

Mistake #10: Treating Compliance as the Finish Line

Audits and compliance assessments are valuable. They help organizations identify weaknesses, improve governance and demonstrate that appropriate security measures have been implemented.

However, compliance should never become the ultimate objective.

Organizations that focus exclusively on passing an audit often optimize their efforts around the assessment itself. Documentation is updated, missing controls are implemented and visible issues are addressed. Once the audit is over, security improvements often slow down.

Attackers do not care whether an organization passed an audit. They care whether it has vulnerable applications, misconfigured cloud services, excessive privileges or unpatched systems.

NIS2 should not be viewed as a one-time obligation that ends with a successful audit. It is a framework for continuous cybersecurity risk management. An audit can confirm the state of security at a specific point in time, but it cannot guarantee that the same level of protection will exist months later.

The real objective is not to pass an audit. The real objective is to build a cybersecurity program that continuously identifies risks, validates security controls and strengthens the organization's resilience throughout the year.

What Does an Organization Prepared for NIS2 Look Like?

There is no universal technology stack or security architecture that guarantees compliance with NIS2. Every organization has different risks, business priorities and levels of cybersecurity maturity. Nevertheless, organizations that successfully implement NIS2 typically share several common characteristics.

NIS2 Readiness Infographic-selection.pngIf your organization identifies more closely with the left-hand column, there is no reason to panic. Most organizations are somewhere between these two extremes. The important thing is to understand your current level of maturity and establish a structured plan for continuous improvement.

NIS2 Is Not About Technology. It Is About Cyber Resilience

Cyber resilience cannot be achieved through technology alone. Organizations can no longer rely on one-time projects, periodic audits or the assumption that implemented controls will remain effective indefinitely. Cyber threats evolve every day, and organizations must continuously identify, assess and manage risk.

Penetration testing, security assessments, configuration reviews, vulnerability management and supplier risk assessments should not be one-off activities performed before an audit. They should become part of an ongoing cybersecurity program.

This is why more and more organizations are adopting the principles of Continuous Threat Exposure Management (CTEM), an approach that focuses on continuously identifying, validating, prioritizing and remediating real security exposures before attackers can exploit them.

NIS2 is not the finish line. It is a framework for building long-term cyber resilience.

Free Checklist

Is your organization ready for NIS2?

Evaluate your organization's readiness in just a few minutes with the NIS2 Executive Readiness Assessment. This practical checklist helps you identify security gaps and prioritize the next steps toward NIS2 compliance.

Download the Free Checklist
logo

Sign up for our newsletter for all the important cybersecurity and ethical hacking news.

Home

GDPR

Contacts

Code of ethics

News

© 2024 citadelo AG. All rights reserved.

facebooklinkedinxyoutube