Field notes from the SOC and the audit room.
Two new posts a month. Written by the people who run the platform.
NIS2 in Germany: How the New BSI-Gesetz Transposes the EU Directive
Germany transposed NIS2 through the NIS2UmsuCG of 5 December 2025, replacing the BSI-Gesetz in full. Scope, BSI authority, KRITIS rules, incident reporting, fines and what to do this quarter.
NIS2 in Belgium: How the Law of 26 April 2024 Transposes the EU Directive
Belgium transposed NIS2 through the Law of 26 April 2024, designating the CCB, NCCN and sectoral regulators as the institutional pillars. What every essential and important entity needs to know after twenty months in force.
NIS2 in Luxembourg: How the Law of 5 May 2026 Transposes the EU Directive
Luxembourg transposed NIS2 through the Law of 5 May 2026, designating ILR, HCPN and CIRCL as the institutional pillars. What every essential and important entity needs to know.
Coordinated Vulnerability Disclosure: A New Framework for Researchers
Understand NIS2 Article 12 coordinated vulnerability disclosure framework. Learn how researchers, vendors, and CSIRTs interact in Europe's new CVD process.
NIS2 for Manufacturing: Cars, Electronics, and Machinery
Understand NIS2 requirements for manufacturers of vehicles, electronics, and machinery. Learn what 'important entities' must implement under Annex II.
Proportionality in Practice: Right-Sizing Your NIS2 Measures
Master NIS2 proportionality requirements. Learn how to assess, scale, and justify cybersecurity measures for essential and important entities.
NIS2 for the Financial Sector: Understanding the DORA Relationship
NIS2 and DORA for financial sector: understand how cybersecurity frameworks overlap for banks, payment institutions, and investment firms.
Cooperation Group, CSIRTs Network, EU-CyCLONe: EU Coordination at Scale
NIS2 cross-border coordination: Cooperation Group, EU-CyCLONe platform, and CSIRT network for collective incident response and intelligence sharing.
Cybersecurity Certification and Standards Under NIS2
NIS2 certification and standards under Articles 24-25: EU schemes, ISO 27001, and security certification requirements for designated entities.