Skip to content
Zyberum Cyber Security Firm
Menu
For your industryITNIS2

Cybersecurity for CISOs and IT Managers: NIS2 Duties, Pentests and Detection

What CISOs and IT managers in mid-sized companies need: NIS2 and BSIG duties, management liability, internal attack surface, typical findings and a first-year plan.

Updated This page as Markdown

In short

CISOs and IT managers in mid-sized companies carry three obligations at once: the German BSIG makes NIS2 risk management measures, 24-hour reporting and personal management accountability binding since 6 December 2025; GDPR Article 32 demands regular testing of security measures; and customers ask for ISO 27001 or TISAX evidence. Internal penetration tests of such environments typically reach domain administrator within a day through Active Directory misconfiguration and missing segmentation, unnoticed. A sensible first year combines a gap analysis, an external and an internal penetration test and 24/7 detection.

Which rules apply to you

Four frameworks shape the job, and one of them is now personal.

BSIG after NIS2. The German NIS2 implementation act took effect on 6 December 2025. A company in one of the 18 NIS2 sectors with 50 or more employees or more than 10 million euros in turnover and balance sheet total is an important entity, from 250 employees or 50 million euros an especially important entity under § 28 BSIG. § 30 lists the risk management measures: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, secure acquisition and development including vulnerability handling, effectiveness assessment, training and hygiene, cryptography, human resources security, access control and asset management, multi-factor authentication and secure communication. § 32 requires an early warning within 24 hours, a notification within 72 hours and a final report within one month. § 33 required registration with the BSI by 6 March 2026. § 38 makes management responsible for approving and supervising the measures and for attending training.

GDPR. Article 32 requires security appropriate to the risk, with a process for regularly testing and evaluating effectiveness; Article 33 sets the 72-hour breach notification. A penetration test is the most common evidence for Article 32.

ISO/IEC 27001:2022 and BSI IT-Grundschutz are the frameworks you build the management system on and the labels customers ask for. In the automotive supply chain the TISAX assessment plays that role.

Sector rules come on top: DORA for financial entities, the IT security catalogue for energy network operators, KRITIS duties for operators of critical installations.

Where attackers start

In mid-sized companies the attack path is almost always identity, then Active Directory, then everything.

  • Phishing and credentials: a user’s password plus a missing or fatigued second factor on mail, VPN or a SaaS portal.
  • Exposed services: VPN appliances, remote desktop gateways, mail and collaboration servers behind on patches, forgotten test systems on old subdomains.
  • Active Directory: Kerberoastable service accounts with weak passwords, certificate services misconfiguration, legacy name resolution protocols, excessive group memberships.
  • Local administration: the same local administrator password on every workstation, stored credentials on jump hosts.
  • Flat networks: clients, servers, backups, building technology and production in one routable space.
  • Suppliers and remote access: maintenance VPNs and managed service provider accounts with standing privileges.
  • Backups: reachable from the domain and deletable with the same account that encrypts the file servers.

What assessments typically find

Typical findings from external and internal penetration tests of mid-sized company environments, anonymised: an externally reachable VPN appliance two major versions behind, with a public exploit; a staging copy of the customer portal with production data and default credentials on a forgotten subdomain; internally, domain administrator rights within a day through a service account whose password was the company name and the year; the local administrator password identical on 400 workstations; certificate services that let any user request a certificate for any other; backups in the same domain, deletable by the account that ran them; log sources not centralised, so none of this would have been detected; and a building management system with a web interface reachable from the guest Wi-Fi.

Each finding maps to a § 30 measure, most often access control, asset management, multi-factor authentication or incident handling.

A sensible first project

Treat the first year as one programme with a gap analysis, two tests and detection, and report it to management as the fulfilment of § 38.

  1. Gap analysis against the § 30 measures and, if you aim for it, ISO/IEC 27001 Annex A: scope, asset inventory, existing controls, missing controls, reporting readiness. Three to five days with IT, legal and management.
  2. External penetration test of everything reachable from the internet, including cloud tenants and remote access. One week.
  3. Internal penetration test in an assumed-breach setup: a standard user account and a laptop on the client network, aiming for domain dominance, backups and the crown-jewel systems. One to two weeks.
  4. Roadmap and detection: findings and gaps merged into one prioritised plan with owners and dates, and 24/7 monitoring set up, for example with a managed SOC at a fixed monthly price per device. Retest the critical findings after three months and repeat the tests annually.

Typical effort for steps 1 to 3 is 15 to 25 person-days, which is 18,000 to 40,000 euros at market rates. Monitoring is a separate monthly cost that scales with the number of devices.

What Zyberum does and does not do here

We do the gap analyses, test externally and internally, help you build the incident response and reporting procedures, run Zyberdome as your 24/7 SOC and train your staff and your management for the § 38 duty. We are not a certification body for ISO 27001 or TISAX, we do not sell firewalls, endpoint protection or other third-party products, and we test only with written authorisation. We support your team; we do not replace it.

FAQ

Frequently asked questions

Is management really personally liable under NIS2?

Article 20 of the Directive requires management bodies to approve the risk management measures, oversee their implementation and attend training, and makes them accountable for infringements. § 38 BSIG transposes this: the management of an especially important or important entity must implement and monitor the measures and take part in training. How liability plays out depends on the case and on company law, but the duty itself is written down, and "IT handles that" is no longer an answer.

External or internal pentest first?

If you have never tested, external first: it covers what any attacker on the internet can reach, takes about a week and often finds the forgotten system that would be the way in. The internal test, started from a standard user account or a connected laptop, shows how far an attacker gets once a phishing email has worked. Most mid-sized companies need both within the first year, and the internal one is where the surprising results are.

Do we need our own SOC for NIS2?

No. § 30 BSIG requires incident handling and, for critical installations, attack detection; it does not say who runs it. A managed SOC gives a mid-sized company 24/7 monitoring and response at a fixed monthly price per device, which is a fraction of three shifts of your own analysts. What stays with you is the decision authority during an incident and the reporting to the BSI.

Sources

Related pages

Get started

What does this mean for your product?

In a free one-hour consultation we go through your product or plant, the regulations that apply and the first steps that bring the most security for the money.

  • Applicable regulations and deadlines for your case
  • Where attackers would start
  • A first project with a fixed price
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usDiscuss your situation

Pick a time that suits you

Open in a new tab