Bechtle IT-Security NIS2

Ready for NIS2? A 360° security approach you can rely on.

As digitalisation accelerates and organisations continue to adapt their processes and ways of working, the risk of cyberattacks continues to rise. Against this backdrop, the EU’s NIS2 Directive raises cybersecurity requirements across the board and introduces stricter, more consistent sanctions – comparable to those under GDPR. NIS2 does not only apply to organisations that fall directly within its scope. It also affects companies within the supply chains of critical or regulated organisations, which must be able to demonstrate that appropriate technical and organisational measures are in place. The overarching objective of the Directive is to strengthen cyber resilience across the EU. 

For many organisations, this raises two fundamental questions: Am I affected? And if so, how can these requirements be implemented effectively in practice? Bechtle’s 360° security approach provides clear direction. We support you in addressing NIS2 requirements while strengthening your cybersecurity capabilities as a whole – not as a box‑ticking exercise, but as a sustainable, strategic foundation.

Our approach gives you an integrated cyber‑defence strategy built around coordinated security solutions. Whether you need an information security framework, a resilient network or endpoint security architecture, or a Security Operations Centre (SOC) on site or as a managed external service, Bechtle supports you end to end. Through seven dedicated practices, Bechtle Security helps organisations protect their IT environment end to end. This holistic approach enables organisations to identify and assess threats at an early stage – and to respond proactively before risks escalate. 

  • Application security
  • Cloud security
  • Cybercrime and defence
  • Data centre security
  • Data protection and information security
  • Infrastructure and perimeter security
  • Workplace security
Video on demand | NIS2 Focus Week

Our NIS2 Focus Week featured five days of webinars and practical deep dives, from core concepts to initial insights into Austria’s first draft legislation implementing the EU’s NIS2 Directive.

Couldn’t join us live? No problem. You can watch all session recordings on demand here.

Tip: Are you interested in a specific solution related to NIS2?

Working closely with our focus partners, we have created additional on‑demand videos covering solutions designed to get your organisation ready for NIS2. These are also available in our on‑demand video library.

Your benefits.

How Bechtle’s 360° security solutions support your NIS2 readiness.

Dataprotection Icon

Holistic security instead of siloed solutions.

Dataprotection Icon

B‑hard cybersecurity assessment tool.

Create case for help support Icon

End-to-end support: from analysis to delivery.

Eye visible Icon

Full visibility into cybersecurity risks.

Education Training Icon

Cutting-edge cybersecurity expertise.

Security Icon

A stronger IT security posture.

Erich Butta

Through our structured gap analysis and the B‑hard tool, our security experts help organisations build forward‑looking cybersecurity strategies.

Erich Butta, Consultant

Gap analysis – Establishing your security baseline.

A gap analysis provides a clear picture of an organisation’s current cybersecurity maturity. It identifies where risks exist today and defines which measures need to be addressed first – turning insight into concrete priorities. To support this process, Bechtle uses B‑Hard, a tool developed by our own specialists. Deployed across numerous customer projects, B‑Hard helps translate assessment results into targeted cybersecurity measures that can be implemented in practice.

Objectives of the analysis

  • Identify security gaps across the IT environment
  • Highlight urgent areas for action
  • Translate findings into a clear, prioritised action plan
  • Provide guidance on suitable security products

Background: The EU NIS2 Directive.

The objective of NIS2 is to strengthen cybersecurity across the EU. Compared with its predecessor, NIS1, the Directive applies to a broader range of organisations and introduces expanded obligations alongside significantly stricter sanctions. NIS2 extends the scope of regulated entities. In addition to so‑called essential entities, a new category of important entities has been introduced.  The Directive also affects companies within the supply chains of these organisations, as essential and important entities are required under Article 21(2) to manage supply‑chain risks and to ensure that minimum cybersecurity measures are in place across their suppliers. Organisations that fall within the scope of NIS2 should familiarise themselves with its implications and requirements at an early stage. Early preparation is critical to meeting timelines and avoiding compliance gaps. As with GDPR, penalties for non‑compliance can be substantial, and management may be held personally accountable for serious breaches.

 

Who is affected by NIS2?

Highly critical sectors  (Essential entities)

  • Energy
  • Transport
  • Wastewater
  • Banking
  • Financial market infrastructures
  • Healthcare
  • Drinking water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space infrastructure 

Medium‑sized organisations operating in these sectors are classified as important entities under NIS2.

 

 

   

Other critical sectors (Important entities)

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production
  • Manufacturing
  • Digital service providers
  • Research (subject to national implementation)
     

How company size is determined

Category

Small enterprise: < 50 employees (FTE) and ≤ €10 million annual revenue or ≤ €10 million balance sheet total

Medium enterprise: < 250 employees (FTE) and ≤ €50 million annual revenue or ≤ €43 million balance sheet total 

Large enterprise: < 250 employees (FTE) or > €50 million annual revenue and > €43 million balance sheet total

 
   
   

Focus of the directive – Stronger cybersecurity across the EU.

 

Background: The EU NIS2 Directive.

The objective of NIS2 is to strengthen cybersecurity across the EU. Compared with its predecessor, NIS1, the Directive applies to a broader range of organisations and introduces expanded obligations alongside significantly stricter sanctions. NIS2 extends the scope of regulated entities. In addition to so‑called essential entities, a new category of important entities has been introduced.  The Directive also affects companies within the supply chains of these organisations, as essential and important entities are required under Article 21(2) to manage supply‑chain risks and to ensure that minimum cybersecurity measures are in place across their suppliers. Organisations that fall within the scope of NIS2 should familiarise themselves with its implications and requirements at an early stage. Early preparation is critical to meeting timelines and avoiding compliance gaps. As with GDPR, penalties for non‑compliance can be substantial, and management may be held personally accountable for serious breaches.

Who is affected by NIS2?

Highly critical sectors

(Essential entities)

  • Energy
  • Transport
  • Wastewater
  • Banking
  • Financial market infrastructures
  • Healthcare
  • Drinking water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space infrastructure 

Medium‑sized organisations operating in these sectors are classified as important entities under NIS2.

 

Other critical sectors

(Important entities)

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production
  • Manufacturing
  • Digital service providers
  • Research (subject to national implementation)
   

 

     

How company size is determined

Category

Employees (FTE)

Annual revenue

Balance sheet total

Small enterprise

< 50 and

≤ €10 million or

≤ €10 million

Medium enterprise

< 250 and

≤ €50 million or

≤ €43 million

Large enterprise

≥ 250 or

> €50 million and

>  €43 million

Focus of the directive – Stronger cybersecurity across the EU.
Dataprotection Icon

Stricter security requirements.

Security Icon

Stronger supply-chain security.

Documents Icon

Incident reporting and notifications.

Eye visible Icon

Continuous visibility of security risks.

Education Training Icon

Employee and management training.

Bechtle’s service portfolio is aligned with the requirements set out in Anne  3.

Risk‑management areas:

  • Responsibility and accountability of management bodies
  • Security policies
  • Risk management
  • Asset management
  • Human resources
  • Basic cyber hygiene and cybersecurity training
  • Supply‑chain security
  • Access control
  • Procurement, development, operation and maintenance
  • Cryptography
  • Incident handling and response
  • Business continuity and crisis management
  • Environmental and physical security

Network security with Bechtle.

Protective technologies such as next‑generation firewalls, intrusion‑prevention systems, anti‑spam and anti‑virus solutions are now standard practice. They play a crucial role in reducing the attack surface and limiting opportunities for cybercriminals.

A key element of modern network security is network segmentation, increasingly implemented through a zero‑trust approach using Zero Trust Network Access (ZTNA). Modern network security must account for a growing number of mobile and remote endpoints that operate beyond the traditional corporate perimeter. These devices require the same level of protection and access control as systems within the internal network.

As a consequence, the security perimeter must move closer to the endpoint, ensuring protection at the point of access itself. Unlike traditional models, a zero-trust architecture assumes that no device, user or connection can be trusted by default. Even within an active session, access can be continuously verified and reassessed. Software‑defined perimeters apply zero-trust principles to protect networks and data by shifting the traditional perimeter into the applications that manage access. Users and applications are granted access only to the specific resources they need at that moment – without visibility into the wider network structure.

Bechtle Cyber Defence Centre.

With the Bechtle Cyber Defence Centre, we offer two proven models for establishing a Security Operations Centre (SOC) tailored to your organisation. The primary objective is to identify suspicious activity at an early stage, investigate it systematically, and respond effectively.

In the traditional model, a SIEM (Security Information and Event Management) platform is used to collect and correlate events from multiple customer systems. These events are normalised and analysed using defined rule sets and threat‑intelligence information. Potential threats are identified when individual events – or specific combinations of events – trigger alerts. This enables security teams to detect suspicious patterns, assess possible attack scenarios, and take appropriate countermeasures in a timely manner.

The next‑generation model combines highly automated technologies with forensic tools for monitoring networks and operating systems, enabling real‑time threat detection. Using artificial intelligence and behavioural analytics, the platform continuously learns and can distinguish between normal and anomalous behaviour. This allows threats to be contained immediately, before they escalate. Endpoint and network technologies are centrally managed and orchestrated via a Security Orchestration, Automation and Response (SOAR) platform and are operated around the clock by Bechtle security analysts.

Protect your systems actively and effectively against internal and external threats. With Bechtle’s support, cyberattacks lose their impact. We advise on, implement and operate your Cyber Defence Centre around the clock, 365 days a year. Get in touch with us to protect sensitive data from theft and sabotage.

Want to find out more?

Have questions about our solutions or products? Just drop us an e-mail. We’re happy to help.