Cybersecurity – Focus on NIS2/NISG 2026
Ready for NISG 2026? Our 360° security solutions help you get there.
As digitalisation continues to transform business processes and ways of working, the risk of cyberattacks is increasing in parallel. To address this threat effectively, the NIS2 Directive, implemented in Austria through NISG 2026, imposes stricter security requirements on organisations. At its core, however, compliance is not about ticking a regulatory box. It is about systematically identifying and assessing cyber risks and reducing them through appropriate risk management measures, with the ultimate goal of building genuine resilience against real-world threats.
The impact extends beyond essential and important entities themselves. Organisations that form part of their supply chains must also address the requirements, as cyberattacks rarely target a single company in isolation. Vulnerabilities at suppliers and service providers are a preferred point of entry, allowing attackers to move through the supply chain to reach their intended targets. Essential and important entities must therefore incorporate supplier security into their own risk management processes and pass these requirements on to their partners. Organisations that can demonstrate appropriate safeguards remain reliable and competitive partners within the supply chain.
The focus is not on documentation, but on risk management in practice.
-
Security concept for network and information systems
-
Risk management
-
Incident handling
-
Business continuity and crisis management
-
Supply chain security
-
Security in the acquisition, development and maintenance of IT systems
-
Assessment of the effectiveness of security measures
-
Cyber hygiene and training
-
Cryptography
-
Personnel security
-
Access control
-
Asset management
-
Physical and environmental security
These areas provide the framework for our work with you, assessing your maturity level in each area, identifying gaps and defining prioritised, appropriate measures aligned with your actual risk profile, turning a regulatory requirement into a tangible security benefit.
Two key questions arise: Is my organisation affected, and if so, how can the requirements be implemented in practice? Our Bechtle 360° approach not only helps you prepare for NISG 2026 but also elevates your information security to the next level.
New regulations, increasing requirements and evolving guidance are creating significant challenges for organisations. Our webinar series cuts through the complexity with practical insights, actionable recommendations and clear guidance to help you navigate NIS2 with confidence. Gain the knowledge you need to strengthen your cybersecurity posture and move forward with certainty.
Gain practical guidance, actionable solutions and expert knowledge across 12 dedicated webinars giving you the insight and confidence to navigate the requirements of the NIS2 Directive and strengthen your cybersecurity posture.
How Bechtle’s 360° security solutions support your NIS2 readiness.
Holistic security instead of siloed solutions.
Technical, organisational, personnel and physical measures work together seamlessly.
Comprehensive cyber security assessment.
Establishes your current maturity level across all relevant areas.
Everything from a single source.
A seamless path from analysis and consulting to implementation.
Full visibility into cybersecurity risks.
Building lasting cyber resilience.
Experienced experts.
Accredited NIS2 specialists, ISO 27001 auditors and implementers who continuously expand and update their expertise.
Demonstrably greater resilience.
Strengthening your organisation’s resilience against real-world threats, not just on paper.
Our experts have already helped many organisations establish a sustainable, future-ready cybersecurity strategy by leveraging our GAP analysis and Cybersecurity Assessment.
Erich Butta, Information Security Officer (ISO)
The first step is a GAP analysis, which shows how mature your organisation’s cybersecurity capabilities really are. Based on the results, we define measures that are prioritised according to risk and impact. Our Cybersecurity Assessment provides a reliable overview in a short time.
Objectives of the analysis
-
Identify security gaps
-
Recognise areas requiring urgent action
-
Derive practical recommendations (prioritised action plan)
-
Provide informed recommendations for suitable security measures and products
The objective of NIS2 is to strengthen cybersecurity across the EU. Compared with its predecessor, the Directive applies to a significantly larger number of organisations and introduces broader obligations as well as stricter penalties. In Austria, it is implemented through NISG 2026.
A key change is the distinction between essential and important entities, both of which are required to implement risk management measures. Organisations that form part of their supply chains are also affected indirectly, as those unable to demonstrate appropriate safeguards risk no longer being considered as suppliers or service providers. Addressing the requirements at an early stage helps ensure timely implementation while maintaining status as a reliable business partner.
Two aspects deserve particular attention. As with GDPR, penalties for non‑compliance can be substantial, and responsibility rests explicitly with management, which may be held accountable for failures to meet the requirements.
Who is affected by NIS2?
Highly critical sectors
(Essential entities)
- Energy
- Transport
- Wastewater
- Banking
- Financial market infrastructures
- Healthcare
- Drinking water
- Digital infrastructure
- ICT service management (B2B)
- Public administration
- Space infrastructure
Medium‑sized organisations operating in these sectors are classified as important entities under NIS2.
Other critical sectors
(Important entities)
- Postal and courier services
- Waste management
- Chemicals
- Food production
- Manufacturing
- Digital service providers
- Research (subject to national implementation)
How company size is determined
Category.
Small enterprise: < 50 employees (FTE) and ≤ €10 million annual revenue or ≤ €10 million balance sheet total
Medium enterprise: < 250 employees (FTE) and ≤ €50 million annual revenue or ≤ €43 million balance sheet total
Large enterprise: ≥ 250 employees (FTE) or > €50 million annual revenue and > €43 million balance sheet total
The objective of NIS2 is to strengthen cybersecurity across the EU. Compared with its predecessor, the Directive applies to a significantly larger number of organisations and introduces broader obligations as well as stricter penalties. In Austria, it is implemented through NISG 2026.
A key change is the distinction between essential and important entities, both of which are required to implement risk management measures. Organisations that form part of their supply chains are also affected indirectly, as those unable to demonstrate appropriate safeguards risk no longer being considered as suppliers or service providers. Addressing the requirements at an early stage helps ensure timely implementation while maintaining status as a reliable business partner.
Two aspects deserve particular attention. As with GDPR, penalties for non‑compliance can be substantial, and responsibility rests explicitly with management, which may be held accountable for failures to meet the requirements.
Who is affected by NIS2?
|
Highly critical sectors (Essential entities)
Medium‑sized organisations operating in these sectors are classified as important entities under NIS2.
|
Other critical sectors (Important entities)
|
||
|
|
How company size is determined
|
Category |
Employees (FTE) |
Annual revenue |
Balance sheet total |
|
Small enterprise |
< 50 and |
≤ €10 million or |
≤ €10 million |
|
Medium enterprise |
< 250 and |
≤ €50 million or |
≤ €43 million |
|
Large enterprise |
≥ 250 and |
> €50 million and |
> €43 million |
Stricter security requirements.
Across all areas of the organisation, not just within IT.
Supply‑chain security.
Requirements are passed along the supply chain.
Incident reporting and notifications.
Security incidents must be reported within the prescribed timeframes.
Monitoring effectiveness.
Measures must be reviewed on an ongoing basis rather than implemented as a one-off exercise.
Training for employees and management.
Security starts with awareness.
NISG 2026 establishes the core areas of risk management measures directly in legislation (§ 32). Crucially, these measures encompass not only technical controls but also organisational, personnel-related and physical safeguards. An Information Security Management System (ISMS) provides the foundation for implementing them effectively.
The specific measures that must be implemented are defined in the relevant regulations—for digital sectors, the Commission Implementing Regulation (EU) 2024/2690; for the remaining NIS2 sectors, a national regulation that is expected to align closely with it. Our service portfolio is systematically aligned with these focus areas:
|
|
- Access control
- Procurement, development, operation and maintenance
- Cryptography
- Incident handling and response
- Business continuity and crisis management
- Environmental and physical security
- Responsibility and accountability of management bodies
- Security policies
- Risk management
- Asset management
- Human resources
- Basic cyber hygiene and cybersecurity training
- Supply‑chain security
- Access control
- Procurement, development, operation and maintenance
- Cryptography
- Incident handling and response
- Business continuity and crisis management
- Environmental and physical security
Implementing NIS2 with Bechtle.
Together, we assess whether the requirements apply to your organisation. Guidance is also available from the Austrian Federal Economic Chamber.
Our Cybersecurity Assessment gives you a rapid, comprehensive overview of your current security posture.
Which requirements under § 32 have not yet been met, and where can the greatest improvements be achieved?
Our experts support you all the way through to demonstrable compliance.
Threats and IT systems continue to evolve, making regular reviews essential for maintaining a consistent level of security.
Based on recognised BSI and ISACA methodologies, our Cybersecurity Assessment reviews the security measures already implemented within your organisation and evaluates them against the current threat landscape. The assessment covers organisational, personnel, physical and technical measures in line with established information security standards such as ISO 27001 and BSI Baseline IT Security.
Your benefits
-
An independent, critical external perspective
-
A clear assessment of your current security maturity
-
Concrete, actionable recommendations
-
A solid foundation for your information‑security strategy
-
Seamlessly integrated into your ISMS
-
Measurably greater resilience against cyberattacks
Maintaining business operations and restoring them quickly in the event of an incident are two fundamental pillars of any security strategy and are explicitly required under NISG 2026 as part of business continuity and crisis management.
Business Continuity Management (BCM) ensures that critical business processes can continue during and after a disruption, whether caused by an extended power outage, a natural disaster or a cyberattack. Taking a holistic approach that encompasses processes, people, locations,and operational procedures, BCM relies on documented strategies for maintaining business continuity, ranging from preventive measures and emergency and communication plans to recovery plans. Bringing these together in a comprehensive incident response manual enables a structured and effective response when needed.
As a core component of BCM, disaster recovery (DR) focuses specifically on restoring IT infrastructure and systems. This includes data backup, system recovery, backup system availability and maintaining the continuity of IT services to resume operations as quickly as possible.
Our experts provide comprehensive support through:
-
Consulting and risk analysis, including Business Impact Analysis (BIA)
-
Resource and capacity planning
-
Development of emergency and recovery plans (BCP documentation)
-
Employee training
-
Optimisation of your IT infrastructure and implementation of redundancy measures
-
Backup health checks
-
Testing and regular exercises
Bechtle. Putting network security first.
Protective technologies such as next‑generation firewalls, intrusion‑prevention systems, anti‑spam and anti‑virus solutions are now standard practice. They play a crucial role in reducing the attack surface and limiting opportunities for cybercriminals.
A key element of modern network security is network segmentation, increasingly implemented through a zero‑trust approach using Zero Trust Network Access (ZTNA). Modern network security must account for a growing number of mobile and remote endpoints that operate beyond the traditional corporate perimeter. These devices require the same level of protection and access control as systems within the internal network.
As a consequence, the security perimeter must move closer to the endpoint, ensuring protection at the point of access itself. Unlike traditional models, a zero-trust architecture assumes that no device, user or connection can be trusted by default. Even within an active session, access can be continuously verified and reassessed. Software‑defined perimeters apply zero-trust principles to protect networks and data by shifting the traditional perimeter into the applications that manage access. Users and applications are granted access only to the specific resources they need at that moment – without visibility into the wider network structure.
Bechtle Cyber Defence Centre.
With the Bechtle Cyber Defence Centre, we offer two proven models for establishing a Security Operations Centre (SOC) tailored to your organisation. The primary objective is to identify suspicious activity at an early stage, investigate it systematically, and respond effectively.
In the traditional model, a SIEM (Security Information and Event Management) platform is used to collect and correlate events from multiple customer systems. These events are normalised and analysed using defined rule sets and threat‑intelligence information. Potential threats are identified when individual events – or specific combinations of events – trigger alerts. This enables security teams to detect suspicious patterns, assess possible attack scenarios, and take appropriate countermeasures in a timely manner.
The next‑generation model combines highly automated technologies with forensic tools for monitoring networks and operating systems, enabling real‑time threat detection. Using artificial intelligence and behavioural analytics, the platform continuously learns and can distinguish between normal and anomalous behaviour. This allows threats to be contained immediately, before they escalate. Endpoint and network technologies are centrally managed and orchestrated via a Security Orchestration, Automation and Response (SOAR) platform and are operated around the clock by Bechtle security analysts.
Protect your systems actively and effectively against internal and external threats. With Bechtle’s support, cyberattacks lose their impact. We advise on, implement and operate your Cyber Defence Centre around the clock, 365 days a year. Get in touch with us to protect sensitive data from theft and sabotage.
Cyber hygiene and security awareness training.
Our security awareness training helps protect employees from common pitfalls and risky behaviour, while raising your organisation’s overall security level. After completing the training, participants understand what is expected of them in relation to IT security and data protection, and how to respond appropriately in critical situations.
NIS2 focus: From next year, we will also be offering dedicated training programmes for senior management. If you are interested, please contact your Bechtle account manager or email us at nis.at@bechtle.com.
Microsoft offers comprehensive compliance and data‑governance solutions that help organisations manage risk, protect and govern sensitive data, and meet regulatory requirements.
- Protect sensitive data across cloud services, apps and endpoints
- Identify and mitigate critical risks within the organisation
- Review regulatory requirements using relevant data and respond appropriately
- Assess compliance and meet legal and regulatory obligations
Bechtle offers in‑depth workshops covering the Microsoft M365 portfolio, addressing questions such as:
- What is already included in my existing licence plan? (e.g. through a gap analysis)
- Which features are currently unused?
- Which additional capabilities are actually required?
If you are interested in an M365 workshop, please contact your Bechtle account manager or email us at nis.at@bechtle.com.
Have questions about our solutions or products? Just drop us an e-mail. We’re happy to help.