Build Lasting Resilience

NIS2 readiness for a logistics group

The group knew NIS2 applied to them. Beyond that, the position was honest and common: nobody could say how far they were from meeting it, and no two people gave the same answer about who owned the problem.

They had been quoted for a gap analysis twice. Both would have produced a document. Neither would have produced a plan anyone was accountable for.

Starting from the obligations

We began with which parts of the directive actually apply to this business, because a general readiness assessment against everything is a document nobody reads. That gave a much shorter list than the one they had been carrying.

Against that list we assessed what already existed. A good deal did. Incident handling was informal but real; supplier requirements existed in contracts nobody had connected to security; backups were tested, which is rarer than it should be.

  • Governance and accountability, which was the largest genuine gap
  • Incident reporting, against the directive's timelines rather than their own
  • Supply chain requirements, already half-present in existing contracts
  • Business continuity, largely in place and needing evidence rather than work

The biggest gap was not technical. It was that no named person was accountable for any of it, so every improvement stalled at the point of decision.

The plan

Each item got an owner, a date and a definition of done. Where something already existed we said so and moved on, rather than rebuilding it to look like compliance work.

Where it left them

Named people, dated commitments, and a paper trail that stands up. The management team can now say what state they are in and what remains, which is what the directive asks of them and what neither previous quote would have delivered.

← All customers

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us