Beyond Paper Compliance: Navigating Cyber Resilience and Board Liability Under NIS2

Watch the episode
Maciej Kłodaś [MK]
Hello, my name is Maciej. I’m the leader of data experience technology practice at C&F and this is C&F Talks, a place where experts discuss challenges, trends and other interesting topics from the perspective of an IT partner. And this is my favorite setup today, two guests, Łukasz Krzewicki and Jan Antoniewicz. Guys, you need to help me with who you are, what you do at C&F.
Łukasz Krzewicki [LK]
Yes. So my role is a governance risk and compliance expert at C&F. I’m involved in the design and development of our solution, which is Adaptive GRC, a solution that helps organizations to manage risk, manage internal control, audits, compliance.
And I work also as pre-sales and I’m involved in work connected with analysis of requirements of our potential customers and existing customers.
Jan Antoniewicz [JA]
My name is Jan Antoniewicz, I’m the head of revenue at Adaptive GRC. So we work together with Łukasz on getting the solution in the market. I’m specifically responsible for coordinating all the marketing and sales activities.
And we’re very often times with Łukasz on calls with customers, learning what they need, what they’re facing, what issues they have. And we are basically trying to help them to solve them.
[MK]
OK, thank you. So today’s topic is a bit different from the usual topics we discuss here at C&F Talks. Governance, risk and compliance.
And we would like to discuss the topic of NIS 2, which is the new version of NIS 1, obviously. So you need to tell me and us what is NIS 2? What do we need to know and why are we discussing the topic today?
[LK]
Yes, so NIS 2 is Network and Information Systems Directive, which was implemented by the EU to help organizations in resilience, in cyber resilience due to the threats that we are facing, cyber information threats. And this regulation is way ahead of the NIS 1. So now the scope has changed, the scope has changed.
So it has expanded to 18 sectors and also it consists of many new elements. And we can say that the most important part of it is connected with incident reporting, supply chain security. But also there are many changes connected with management liability.
So now in this new version of NIS 2, we have a personal accountability of management. So it’s a huge change in comparison to the first version of NIS. Generally speaking, this regulation is designed to help organizations achieve better maturity in the area of cybersecurity, to protect also us as a society, as people.
[JA]
Yes, so I think one of the good sentences that would sum up NIS 2 is basically that with the earlier versions of the regulation, the first version of the regulation, some people tend to say that it was basically compliance on paper. So you had to have your paperwork right. And this was basically the most important thing.
And I think what is important about NIS 2 is it’s focusing heavily on the outcome. So it’s really about creating resilient organizations that have controls implemented that actually work. And there is a set of outcomes that you have to achieve practically, realistically and in a trackable way that will actually make organizations compliant.
For example, you have to be able to report incidents within 24 hours. Right. So basically this is and you have to have this whole framework in place working that if something happens, you are basically prepared to take all the steps necessary as commanded by the regulation to be able to comply with it.
Right. So it’s really there is this change from something that is bureaucratic, say, compliance to a very hands on, efficient, realistic compliance and resilience against cyber threats.
[LK]
Yes, that’s right. So it’s not only policies, procedures, paper, because with paper you will not defend yourself against cyber threats, but you need real activities, real actions and awareness of people. So good training, good internal control safeguards that protects your organization.
And also, I mean, in the case of audit, you need some evidence. So as Jan mentioned, this is also important to show your effort, your due diligence in this area. I mean, you should show that you focus on cyber security and this is somehow embedded into your processes, into your organization systems.
So also it’s important to show this as part of your audit evidence to your auditors.
[MK]
What happens when you are not compliant?
[JA]
Ouch. There are quite severe consequences and penalties. Right.
[LK]
Yes. Yes. So this directive tells about fines, which are up to 10 million euros or 2 percent of your global turnover.
[MK]
Oh, even better.
[LK]
Yeah. Whichever is higher. So it’s huge consequences to each organization.
But also, as I mentioned before, the management liabilities here. So a board might be also fined by this regulation if because right now, in comparison to NIS 1, NIS 2 strictly requires management to take control over cyber security efforts. So before, usually management thought that NIS 1 is just IT and that’s enough.
But now we face this new reality that management board may be also fined. So there might be sanctions like individual sanctions for people that manage organizations.
[MK]
OK, so it’s not only the company, but also a personal responsibility, right?
[LK]
Yes.
[MK]
Yes.
[LK]
So I would say that that management should be aware of this and it’s important this top down approach. So they should prepare a budget for cyber security. They should be aware of all the activities around it.
So it’s also good communication in both directions is important. And also, I mean, there should be people assigned to each areas that are important in overall this. Yeah.
[JA]
And I think this is also a consequence of the change in NIS 1 versus NIS 2, because with NIS 1, you had basically, correct me if I’m wrong, Lucas, but basically it was mostly an area concerning chief information security officers and IT. And now it’s much broader than that. So you actually, in order to be compliant with NIS 2, you have to bring several departments working with each other.
Each of those departments has a couple of bricks that they have to lay down in order to make it a complete structure. And then therefore, you also need the management to be on board with that, to be able to oversee and make this a coherent process across the entire organization.
[MK]
So I assume that the NIS 2 is the regulation is because of the emerging AI threats all over the place. Is that correct?
[LK]
Not only because it was introduced, I mean, started with NIS 1. I would say that it is to make organization resilient for any cyber threats. Of course, AI brings another threats and other vulnerabilities to organization.
So, I mean, people involved, people introducing new AI tools should be aware also about some threats that it poses to organization. So there is a new area here, but this is not the only one area that the NIS 2 is focusing on.
[JA]
I think some time ago, I’ve listened to a quite interesting interview with a former CIA operative who has been asked the question whether he thinks that World War 3 is possible to happen. And he actually said a very interesting thing. He said that in his opinion, World War 3 is already going on.
It’s just that it has very much changed since the last global wars, because with the introduction of nuclear weapons, huge superpowers have refrained quite a lot from going all out. And they basically all the or most of the warfare right now is being led by proxy states, you know, Vietnam, Korea, etc. Ukraine.
Basically, this is probably the same story. And what he said was very interesting that basically each day we as the EU, for example, are being attacked by state-sponsored actors, state-sponsored actors who are acting in accordance or being paid or sponsored again. And as I said, through other countries.
And if you look at the data 10 years ago, there has been 10 times less state-sponsored attacks when it comes to cyber security. So from what I know, the UK is the country with the largest number of cyber attacks. And right after is Poland with the highest dynamic in this area.
Right. So basically, we are being attacked by other countries, not naming them right now, which whichever they are. But basically, there is a high threat going on against all crucial or any and all crucial infrastructure like, you know, with the water system, the sewage system, the banks, online transactions, all those factors and all those mechanics and infrastructure that makes our world work and tick.
Right. So basically, this is a, if you imagine very simple things not working, like not being able to pay with a credit card. Right.
This is a major obstruction for the entire society. And this is a major loss of income, of revenue, of turnover and for an economy. And if you put those small, tiny attacks at the map, it really costs our country or any country in Europe, a lot of money.
Right. So the threat that we had, for example, against the railways, right, where you had thousands of soldiers go out and patrol railways. This is a huge cost.
[MK]
Yeah.
[JA]
This is a huge cost for the entire country that drains out resources. So it’s basically from going over from invading a country to slowly draining and draining resources, creating chaos. So I think this is an important thing to remember about the NIS2.
It’s not, it’s not about paper. It’s actually about really, really creating this resilience on a company level that then translates into a country and regional level.
[LK]
Yes. And I would stress here that it’s also the supply and chain security. So it’s important because a company is one thing, but the company has many partners, vendors, and the risk might be not in the organization, but also in its vendors.
So here also NIS2 strictly points that assessing, managing and addressing risks in your supply chain is also an important part of cybersecurity activities. So you should know what your vendors are. We should know what potential risks there is when they are processing your data, when they are delivering services, important services to your organization.
[MK]
We’ve seen that risk during COVID breakout when supply chain just melted down.
[JA]
Yeah.
[MK]
How about or what about the companies here in Poland? Are they ready and compliant with NIS2? What is the maturity level of companies you’ve worked with?
[LK]
So I think it depends. So the level of maturity in context of NIS2 is different for each organization. So I think we have some sectors which are quite well prepared to NIS2.
Also, there are some standards, frameworks that they use. So, for example, if a company has ISO 27001, which is an information security standard, well established amongst mature organizations, and it helps. It really helps because it covers a lot of area that NIS2 requires to be covered by controls, by safeguards.
So if you have ISO 27001 and it’s good designed, we have good procedures. You have, I mean, this information security culture in your organization. If your people are trained, if they follow the process according to some standards that are implemented into your organization, then you are on a better position.
Of course, you need to add those new elements that NIS2 requires, like this incident reporting that Jan mentioned with those timelines for early warning, for detailed notifications. So you have like 24 hours for early warning, 72 hours for some more notification to authorities what has happened, what might be the root cause of your incident. And then you have those 30 days to prepare a final report.
So this is some new areas, new elements. But ISO implementation helps here. Also, other frameworks might be used.
Some organizations use frameworks like NIST, which is NIST Cyber Security Framework, which is a U.S. standard framework. And it also consists of many controls, safeguards that you should use. So I would say that NIS2 doesn’t say how, it says what should be protected, but it doesn’t specify how you should achieve this resilience, this cyber resilience.
So here there is a role of those additional standards, also some guidelines that are published in accordance to NIS2. So the way how you approach this, you have more flexibility. But I would say that if you have those standards, frameworks implemented or you want to introduce them to your organization, it helps a lot.
[JA]
Yeah. So I think, as Lukasz said, it’s slightly of a mixed bag. Those organizations, for example, energy companies, huge strategic companies that have already had in the past some sort of frameworks in place, they are better off.
However, we also see that the expectations are very high towards them and they are being held to very high standards. There are a lot of medium to bigger sized companies that also might fall into the NIS2 bucket. And they are somewhere, sometimes more advanced, sometimes less advanced.
So there are some that scramble right now to, you know, all hands on deck to make quick moves, to try to comply as much as they can to catch up. And some of them are doing a very good job with how they are and they are approaching it as a methodical, which I think is the best approach, is to have a methodical approach of continuous improvement where you create this delta in the very beginning. Where are we right now in the implementation?
What needs to happen? And you divide this according to your needs and possibilities that you have internally and then work your way through it.
[LK]
Yes. So I think it’s important to start with some gap analysis. So you should know where you are now and what is required by our new regulation.
[MK]
What needs to be stressed out is that it’s not a project with an end state. It’s something that is being continued.
[JA]
Yes. It never ends.
[MK]
It’s ongoing. It’s ongoing. Yes.
OK, so it’s a program.
[JA]
It’s a healthy lifestyle. It’s not about having a short term diet. It’s about changing your lifestyle.
So you’re in 10 years time, you’re even better off that you were. Right. So that’s that’s something like that.
Yeah. Yes.
[MK]
OK, so I’m trying to figure out how to approach this because I don’t know what to do. You don’t need to have certificates in order to start preparing for an IS-2, right? They will help you.
You have ISO or something else that helps, but you don’t need to have anything on board in order to start your journey, right?
[LK]
NIS-2 doesn’t require you to show a certificate. Of course, it helps, but it is not required. So as I said before.
And yeah, so you should start with some gap analysis to know where you are and what you want to achieve. And of course, each organization is different. So there is no universal like procedures, policies.
It should be adjusted to each organization. And also it’s I mean, there are some pillars that should be taken into account that I mentioned by NIS-2. So those areas around risk management, business continuity, incident management, governance.
So you should have all the policies for those areas and for those policies, you should have some safeguards or internal controls that are also implemented into your software, into your daily activities. But what is important also to show that it is working. So it should be designed correctly and it should be effective.
Yes. So you should also verify if those existing controls that you have are enough, are working, are followed by people in your organization. If not, maybe there is some adjustment required or anything or maybe a new way of processing some things to achieve compliance.
[MK]
So how does this implementation works in practice? How do you approach that? You need to have this analysis in the first place, right?
[LK]
The first place is this analysis. But then, first of all, you need to know what are you protecting. Yes.
So services that you are delivering. And so you should focus on the most important services, most important products. And know what are the risks connected with those.
Yes. What are the vulnerabilities, what threats are there and what vulnerabilities are connected with some assets that you use to perform processes. Yes.
So it’s good to map your services to assets. Assets are different type of like, for example, processes asset. But people is the most important asset in many organization, information, infrastructure, server, software, everything that supports your processes, everything that you use to fulfill some actions, fulfill some activities to perform, to deliver service, to deliver a product.
So I mean, you should map everything and identify those risks. And if risks, if you analyze the risk, because you should do the correct risk assessment, so you should identify the risk, then evaluate it and take a decision how to approach the risk. Because sometimes when the risk is high, when you see that the impact of probability is high and it is out of your, I mean, how we call it risk appetite, then you should take action.
You should take action to mitigate it, to mitigate risk. Sometimes you need additional corrective or preventive action, prepare some action plan, assign some people to do something, to introduce some new safeguards or controls to be, to lower this risk.
[MK]
Okay. Is there any, I don’t know, procedure, software that will monitor those areas, risks, incidents, anything like that, or, you know, adaptive GRC, I assume this is the kind of stuff that helps you manage everything.
[JA]
Yes, we highly recommend Excel.
[LK]
Excel is not good here, as we know.
[MK]
Yeah, but yes.
[LK]
No good, no? You said no good?
[MK]
Okay.
[LK]
So such software like that covers governance, risk and compliance, platforms that covers a lot of areas and may help. It’s really useful here because it can assist in your risk management, assist in your preparation of policies, procedures connected with these controls. And also you can track any corrective or preventive actions that are assigned to controls and to risks.
And you can do also business continuity management in such tools to verify if you have all the disaster recovery plans, if something happens. Also, incidents management is important part of such tools.
[JA]
I think while, correct me if I’m wrong, but I don’t think NIS says anything about tools itself. However, there are some common sense best practices that probably should be used. So we mentioned Excel earlier on and a lot of companies, even the biggest ones that we work with, use or used to use Excel.
And while Excel is a great tool for a lot of things, it might not be the best tool for the job here. A story, I don’t know if it’s an urban legend or whether it’s a fact, but the story I like to quote is of the NHS, the British NHS, when COVID broke out and they were tracking cases and using Excel for statistics and they were adding cases to this Excel sheet. And at one point in time, they realized they were adding a lot of entries, but the Excel sheet wasn’t growing.
So it was then when they realized that I think Excel has a limit of 60,000 rows or something like that. And they were adding new cases on the top and they were losing data at the very bottom. So this is one of the places where you realize there are sometimes dedicated tools that do a better job.
And I think my theory on that is that, first of all, what you need is a audit trail where you have all the changes in this documentation trailed. So if I create a record, for example, and you change it, we need to know about it. Right.
It cannot be changed like an Excel sheet, which is the current version, I don’t know. We are sharing this file, it’s being edited by thousands of people and you lose this overview very quickly. So I think this is one of the problems.
And the second problem, I think, is it would make sense, in my opinion, to have a tool that brings all of these areas into one platform, because the change from NIS1 to NIS2, as I mentioned, is that there are a lot of teams working on the general compliance with NIS2, right? So it would make sense to have one tool where all those teams can work together on all the aspects and then the board to be able to have this helicopter perspective on how we are doing in terms of NIS2 in general, instead of looking into 10 separate tools which are siloed off and no one knows the current version and you have to send someone something. And, you know, I think this might be an issue.
[LK]
Yes, that’s right. So logging of all activities around race compliance is important, but also such tools help you in access management because sometimes it’s also an important part of your cybersecurity to know, I mean, to deliver access for some specific information to people that are involved in certain processes, not to all of them. So it’s easier to manage it in such tools.
Also, you may introduce multifactor authentication, which is also an important part and it’s stressed in NIS2. Yes, so some additional encryption. So it helps to achieve this higher level of maturity in management of those requirements.
[JA]
And this is actually a place nicely with what you said earlier, that if you have parts of best practices inside the organizations like multifactor authentication or Entry ID or whichever type of identity management in place, which is a common best practice in large companies or companies at all, then you’re already semi set up for success with NIS2 because you have those building blocks, some of the building blocks for NIS2 already in place, right?
Because you’ve used some existing best practices.
[MK]
When it really makes sense to implement such tools, is it because of the size of the company or a specific sector or, I don’t know, complexity of processes and services inside of the company?
[JA]
Yes, I think all of this is correct. I would say Lucas, right? Yeah.
So basically, yeah, so yes, I think all of this, all of those reasons that you mentioned are correct. In fact, the bigger, I would probably venture to guess that the bigger the company, the more important the tool is, because whenever you have a lot of teams working on specific subjects, some sort of organization framework helps.
[LK]
Yes. So key phrase here is due diligence in cybersecurity. So possessing such tools helps here because you can show that you try, you try to make everything possible to defend your organization against those cyber threats.
And even if you are hit by cyber attack, the authorities may recognize that you did everything possible to protect yourself against such threats, such attacks. So, of course, the more efforts in this area with some tools, which is really helpful in many cases.
[MK]
Are there any specific sectors that regulators have a closer look into or it doesn’t really matter?
[JA]
There are those 18, right?
[LK]
Yeah. So now 18 sectors are in scope of NIS 2, which is a huge change from NIS. But also there are some essential sectors.
So we have like important and essential sectors and companies, organizations from those essential sectors might be audited by authorities, even if there is no incident, no issue. So there is such tool like audit, which is designed to give this additional push from authorities towards those essential sectors.
[MK]
Okay, how do you see the future? Because NIS2, where is the deadline? When is the deadline for NIS2?
[LK]
It depends on the country, because many countries are implemented this directive into their law earlier, because it’s a directive. So each country implementation may be slightly different here in the EU. Poland is quite late in terms of implementation.
So October of this year is the deadline for those organizations to list themselves on special lists prepared by authorities, as this organization is important or essential for NIS2 implementation. But then there is a time when all those requirements connected with these areas in which new controls should be introduced is required, which is a year from October 2026. So it’s like October 2027, when those controls should be implemented here in Poland.
[MK]
So those regulations are different from regulations in the States, for instance. We are more regulated, less regulated, should we feel like safer now here in Europe?
[LK]
I think, yeah, so the aim is to be safer, of course. And but we have to mention that also US organization that have activities in Europe, they need to follow, if they are from those sectors, they need to follow NIS2 if they have activities here in the EU. So, so they will also need some activities around this.
But I think that this approach towards more strict regulation is global. So there are so here in the EU, we we have this, but probably it will be extended. You mentioned also AI, which is a strong factor towards more protection, more, more effort around this area.
[MK]
Does it anyhow complicates or is it a burden for EU companies against companies from from the rest of the world now? Or do we, you know, having those regulation in place really makes us more competitive against different different companies in the world?
[LK]
I think that most of the organization from those sectors are already quite mature in, in cybersecurity. So there is, I wouldn’t say that those areas that are mentioned by NIS2 regulation is something completely different that was before. But it’s more like more ordered, more better prepared in terms of practical approach.
So I mean, here, what is important is that it should work. So I would say that it protects organization because it gives real protection to organization. So we are aware that such ransomware attack for organization might be really harmful, might destroy even big organization if data is stolen by some hackers.
If data is not encrypted, then it’s a real threat for each organization. It may be personal data or confidential data. So each organization should protect itself against such attacks.
[MK]
Do you have any examples like that? Because it’s rarely the case when you hear about such disasters in mainstream media.
[JA]
Very good question. So basically, I think the very often times we are not aware of the consequences of those breaches and activities of those state-sponsored actors on the society. We just see glimpses of it in the news.
For example, we see that one of the bank’s card systems has failed for a couple of hours or a cloud provider has had issues, right? And sometimes it’s just technical glitches. But truth be told, very often times, it’s just the effect of those state-sponsored actors, hackers, whoever they are, but basically the effect of not being fully resilient, right?
So this is basically something we see on a daily basis, really, because those attacks are happening in the hundreds or thousands daily. And it’s just the consequence of being well set up in this general compliance and security area that we don’t have bigger mishaps that we see every day. Like again, not working buses, for example, right?
Which again, major disruption, right? Or not that you have water in your tap, right? Because someone was not able to hack the system and, I don’t know, for example, stop the water from being purified so we can drink it, right?
[MK]
Okay. So we are not being told the truth in order to stay calm.
[JA]
It’s the X-Files.
[MK]
It’s the X-Files. Yeah. I remember one energy grid glitch in Spain last year.
Yes. Has it been connected anyhow to such incident or it was just…
[LK]
Probably not. It was just… Probably it’s the different cause of it, yeah.
[MK]
The problem of the grid itself, right?
[JA]
In this case, it’s also resilience, right?
[LK]
But if you are a CISO and follow, I mean, forums that are connected with cybersecurity, you can see that such attacks happen on a daily basis for very important players, yes?
[MK]
Oh, okay. Sorry to interrupt you, but important players meaning government agencies, government companies or private sector? Both.
[JA]
Any of those falling into this important or strategic, right, categories.
[LK]
So each organization faces a lot of attacks every day. So there are systems that track this. So you have this SIEM systems, which identify such attacks and also help to protect organization against it.
All the firewalls or the VPNs that you use, everything is designed against such attacks, but they happen on a daily basis. And if you follow forums dedicated for cybersecurity specialists, you can see it on, I mean, and you can track it.
[JA]
I don’t know if I would like to.
[LK]
No. Most people, yeah.
[JA]
Most people don’t want to because it’s just, it’s, it’s stressing.
[LK]
It is. Very simple.
[JA]
I mean, you don’t think about all those thieves being caught by the police every day, right? Exactly. But it’s happening.
It’s going on. It’s part of our society. It’s part of our life.
So it’s probably, probably doesn’t make sense to obsess about it too much, but it definitely makes sense to be prepared, right? It makes sense to close the door of your house for the night, right? Because you don’t want to create any vulnerabilities.
But still you don’t want to be obsessing about someone breaking in. But when you are prepared, the better prepared you are, probably the less obsessed you have to be, right?
[MK]
Does this NIS2 help you track down, you know, people, organizations that attack your company or it’s just the authorities that are tracking them down? Do you have any signs of, of, you know, evidence of, of the attack or you are just, you just know that you are being attacked and you are defending and that’s all. Are you learning from, from those attacks?
[LK]
Yes, of course. So we, we talked about the incident reporting. So it is designed also for transparency and communication of such attacks to other companies, other organizations in the sector.
So if you are affected by an incident, cyber attack or anything like that, that’s why you need to register it to the authority. But they may share this information with other companies in this sector, other sectors, because if, for example, you identify, so you have this 72 hours in which you need to specify all the details that you know about this specific attack and it might help other organization, because if there is a vulnerability found in a software that is used by you, but it is commonly used by other players. So there is a reason why this authority can also send this information to information security specialists in all those organizations.
So they will, they will take some action and they will patch servers that will do anything to protect their organization against such vulnerability identified by, by an attack. So also you can contribute from other players that are affected because then you are aware of such activities, such attacks and you can react.
[MK]
OK, tell me, how do you see the future? Because the dynamics of the market and technologies that are emerging, meaning, you know, AI and new models that are really, really complex. NIS2 might be a regulation that needs to be implemented right now, but the market dynamics and as I said, technologies that are being invented or implemented are far more advanced than the, than the regulations being implemented.
So.
[LK]
Yeah. So I think that’s why NIS2 doesn’t mention a specific, specific technologies, yes. So because it may be outdated in a month or in a half of the year.
It’s just the approach. Yes. So they, I mean, in NIS2, NIS2 regulation, you have those areas, I mean, that you need to protect, but the way how you do this, it depends on each organization.
So you need to take into account the risk and the, the controls that you, so it should be weighted somehow because the controls costs, but if the risk is high, then you need to take some additional costs if it is required, but the technology may change. So if there is a new threat, maybe you will need a new tool to help you protect your assets, protect your services against any threats.
[JA]
Okay.
[LK]
Yeah.
[JA]
But, but technology is generally, and it’s as with most cases in companies, technology is a facilitator or tool. It’s not the solution itself, right? So it’s, it’s, it has to be part of a system.
[LK]
Yes. But this constant loop of improvement of constant verification, if those controls that you designed a year ago are still valid, is something that each organization should perform on a daily, monthly basis.
[MK]
Right. Okay. So being aware of, of the, the need of implementing NIS2 regulations is one thing, but you know that companies usually have to know such things, but do the management board knows that they are really accountable for, for, for the NIS2 implementation or is it the CIOs and compliance teams that have been implementing NIS1?
[JA]
It’s again, it’s, it’s, it’s, it’s a mixed bag. We recently have had a workshop with a global company where, where the management board, the majority of the management board came over and sat down, you know, discussing how we can implement the tool to be compliant. And this was a, a, a very good positive sign of the awareness of the management board.
But we also have a lot of feedback from, from compliance officers, risk managers, or they ask us, are you offering some sort of a training for the management board? Because we would love to have such a tool, it would make our life easier and would make our organization more compliant. But we have an issue with, with convincing our management board that it is really necessary.
So there seems to be a lot of, of not aware management boards out there that it is in fact going on and that it is specifically their own responsibility to contribute and to help the organization onboard the necessary frameworks and potentially solutions. But it’s also, you know, something that would give added value to those boards because you have the centralized reporting where you again, see the entire organization, see all the bits and pieces that have to be compliant in one tool, you can have, you know, have centralized reporting in it. So basically it gives not all, it’s not, not just a burden, but it’s really a huge help in managing the entire organization and making sure that it’s actually compliant to potentially avoid those fees on a company level, but also on, on the management board’s personal responsibility level.
Because again, as Lukasz already said, NIS2 introduces personal responsibility for the board members of the, of a company to, to make sure that the company is NIS2 compliant.
[LK]
So, yeah. Yeah. So such tool like Adaptive GRC or any other GRC tool, especially if it’s a platform that covers a lot of areas, might be also helpful for communication to the board, because as board, I mean, the liabilities on the board, they need to be aware of what’s going on in those different areas.
So what risks are we are facing? What are the highest risks that we are facing? Yes.
What controls are in place? If those controls are effective for the specific process, that is also the crucial process for our organization. So this information may be presented in a good way as kind of a dashboard for management board and they can see in real time what is going on, even on a daily basis.
And it gives them, I mean, this visibility. So it helps them to assure that organization is following what they, I mean, what as a whole, how we, I mean, how the process is designed, the cyber security processes are designed in organization.
[MK]
OK. Any kind of, you know, good uncle advice to the companies that need to comply with those NIS2 regulations? Implement Adaptive GRC tool, obviously.
Anything else? That’s right.
[JA]
I think communication would be important to make sure that the company and the departments talk to each other, because from what I see, especially big companies have problems with open communication, with efficient communication. And as we know, like 60 something percent of projects fail due to a bad communication. So this is, I would say this is crucial to build the awareness across the teams that everybody has to chip in.
I would say this is one of the things that I would. Yes.
[LK]
So communication and involvement of people, because if this NIS2 requires board liability, the tone might come from the top to down to people involved in processes. So also it’s important for process owners to know that the board is involved here and that there are some efforts put to introduce this across whole organization, also via some trainings to people, to people involved in those processes, but also to other employees in whole organization.
[JA]
But I would also suggest maybe that to see this entire thing, because right now everyone is stressed out because, you know, deadlines are coming, etc. And this is an expensive and time consuming process, etc. But I would also maybe suggest to take it as on the positive side, because it does give the organization a bit of resilience and potentially less problems in the future.
So I would see this as a as a important effort to be taken right now, but that will have a positive, very positive impact on the company in the long term.
[MK]
You can sleep at night.
[JA]
Yes, exactly.
[MK]
OK, guys, what is the advantage of of implementing such tools as Adaptive GRC early in the process, you know, against building like siloed, I don’t know, Excel spreadsheets or whatever?
[JA]
I think one of the advantages that we see or at least hear from our customers is that, well, if you onboard any solution from this area, you basically onboard a set of best practices, right? This is also touching on the ISO, etc., the best practice that you might already have in the organization. So if you would choose to implement a system, whichever it is, at an early stage, this gives you a good framework of reference, what you should have.
This builds basically the backbone of the of the compliance framework that you can take, which is usually a best practice proven by dozens of organizations before you. So you don’t have to experiment yourself and basically learn from your own mistakes, but you can basically take something that is already tried and tested and spare yourself the potential pitfalls and downfalls that you might encounter while coming up with all of it yourself. I think this might be also something that might be worth mentioning.
Yes, that’s right.
[LK]
And you can start even with some part of those activities that you need to follow in these tools. So, for example, you can start with risk management and add business continuity management, incident reporting. So it depends also where you think that you will achieve the most advantage gain using such a platform like Adaptive GRC.
[MK]
All right. Cool, guys. Thank you very much for a very interesting discussion.
A bit different flavor from the usual stuff we do here. Thanks for being with us and be sure to tune in for another episode of C&F Talks.

From compliance on paper to practical cyber resilience
NIS2 represents a fundamental shift in how organizations need to approach cybersecurity. Rather than treating compliance as a documentation exercise, the directive puts greater emphasis on whether organizations can actually identify, manage, and respond to cyber risks. In the episode, the experts discuss how organizations can use established frameworks such as ISO 27001 and the NIST Cybersecurity Framework to structure their approach, starting with a gap analysis, asset mapping, and risk assessment.

Why cybersecurity is now a board-level responsibility
The consequences of NIS2 extend beyond the IT department. With significant financial penalties and personal accountability for management boards, cybersecurity has become a leadership responsibility. The discussion explores how organizations can maintain a clear view of their security posture, create reliable audit trails, and support informed decision-making through dedicated Governance, Risk, and Compliance (GRC) platforms such as AdaptiveGRC. The goal is not simply to meet a deadline, but to establish a sustainable cybersecurity program based on continuous improvement.
Get more information on NIS2 and its implications for businesses operating in the EU
Meet the experts

Łukasz Krzewicki
Audit, Risk & Compliance Expert, C&FŁukasz Krzewicki is an experienced Audit, Risk and Compliance professional with over 25 years of experience across telecommunications, consulting, and IT. At C&F, he works on the design and development of AdaptiveGRC, helping organizations strengthen their governance, risk management, internal controls, audits, and compliance processes. He also supports clients through requirements analysis and pre-sales activities. His expertise is backed by ISACA CISM and CRISC certifications and an Approved ESG Officer credential from the Institute of Compliance.

Jan Antoniewicz
Head of Revenue, AdaptiveGRCJan Antoniewicz is a business growth and product professional leading revenue activities for AdaptiveGRC. At C&F, he coordinates marketing and sales initiatives, supports product optimization and new product launches, and works with customers to understand their challenges and identify practical solutions. He also contributes to lead generation strategies, CRM initiatives, and the development of C&F’s commercial capabilities.
Let’s connect
Our engineers, consultants, and experts are here to help you uncover solutions tailored to your business needs. Whether you’re looking for targeted support or planning a complex digital transformation, we’re ready to help you achieve more.