Blog

Field notes from security operations and the audit room.

Notes on NIS2, ISO 27001, incident reporting and supply-chain risk, written by the people who run the platform.

NIS2 for MSPs and MSSPs: From Vendor to Regulated Entity
NIS2 · 8 min read · 13 May 2026

NIS2 for MSPs and MSSPs: From Vendor to Regulated Entity

NIS2 scope for MSPs and MSSPs: understand how managed service providers become regulated entities under Annex I, Sector 9.

Daniel Grigorovich
Daniel Grigorovich · Founder
NIS2 and GDPR: Where Cybersecurity Meets Data Protection
NIS2 · 8 min read · 11 May 2026

NIS2 and GDPR: Where Cybersecurity Meets Data Protection

Understand NIS2-GDPR overlap: how cybersecurity obligations under NIS2 Articles 21, 35 complement GDPR Articles 32, 33-34 data protection requirements.

Daniel Grigorovich
Daniel Grigorovich · Founder
What Makes an Incident 'Significant'? Understanding the Reporting Threshold
NIS2 · 9 min read · 8 May 2026

What Makes an Incident 'Significant'? Understanding the Reporting Threshold

Understand NIS2's significant incident threshold under Article 23(3): criteria for mandatory 24-hour reporting to authorities and CSIRTs.

Daniel Grigorovich
Daniel Grigorovich · Founder
NIS2 for Transport: Aviation, Rail, Maritime, and Road
NIS2 · 8 min read · 6 May 2026

NIS2 for Transport: Aviation, Rail, Maritime, and Road

NIS2 for transport sector: understand obligations for aviation, rail, maritime, and road operators under Annex I, Sector 2.

Daniel Grigorovich
Daniel Grigorovich · Founder
The NIS2 Institutional Architecture: Authorities, CSIRTs, and Contact Points
NIS2 · 8 min read · 4 May 2026

The NIS2 Institutional Architecture: Authorities, CSIRTs, and Contact Points

Understand NIS2's governance structure: competent authorities, CSIRTs, single contact points, and their roles in incident response and coordination.

Daniel Grigorovich
Daniel Grigorovich · Founder
Administrative Fines Under NIS2: The EUR 10M and EUR 7M Frameworks
NIS2 · 9 min read · 1 May 2026

Administrative Fines Under NIS2: The EUR 10M and EUR 7M Frameworks

Understand NIS2 administrative fines under Articles 34-35: EUR 10 million for major violations, EUR 7 million for non-compliance. Enforcement, appeals, and mitigation.

Daniel Grigorovich
Daniel Grigorovich · Founder
NIS2 for Healthcare: Hospitals, Pharma, and Medical Device Manufacturers
NIS2 · 9 min read · 29 Apr 2026

NIS2 for Healthcare: Hospitals, Pharma, and Medical Device Manufacturers

NIS2 for healthcare sector: understand obligations for hospitals, pharmaceutical manufacturers, and medical device makers under Annex I, Sector 5.

Daniel Grigorovich
Daniel Grigorovich · Founder
NIS2, CER Directive, and DORA: Navigating Overlapping Frameworks
NIS2 · 6 min read · 27 Apr 2026

NIS2, CER Directive, and DORA: Navigating Overlapping Frameworks

Navigate overlapping EU cybersecurity regulations: NIS2, DORA, and CER. Understand scope, Article 4 distinctions, and governance architecture.

Daniel Grigorovich
Daniel Grigorovich · Founder
The All-Hazards Approach: Why NIS2 Goes Beyond Digital Threats
NIS2 · 10 min read · 24 Apr 2026

The All-Hazards Approach: Why NIS2 Goes Beyond Digital Threats

NIS2 Article 21 mandates all-hazards approach: cyber, physical (fire, theft, flooding) and environmental security. Learn what this means in practice.

Daniel Grigorovich
Daniel Grigorovich · Founder