Diese Seite ist derzeit nur auf Englisch verfügbar.

Zurück zum Blog

NIS2 network monitoring: a mid-market checklist

NetSenX Team4 Min. Lesezeit
nis2network-monitoringchecklistmid-market

NIS2 does not prescribe a particular monitoring tool, but it does require essential and important entities to handle incidents (Article 21) and to report significant ones within 24 hours, 72 hours and one month (Article 23) — so in practice you need to see what happens on your network and keep evidence of it. This checklist turns those two articles into eleven concrete steps for a mid-market IT team.

Who this applies to

NIS2 — Directive (EU) 2022/2555 — covers medium-sized and large organisations in the sectors listed in its Annexes I and II (energy, transport, health, digital infrastructure, manufacturing of certain products, food, waste management and others), and some entities regardless of size. A medium-sized enterprise, in the EU definition, has 50 or more employees or more than €10 million in annual turnover or balance-sheet total.

Each member state applies NIS2 through its own law — for example the Cyberbeveiligingswet in the Netherlands and the amended Act on the National Cybersecurity System (KSC) in Poland — so check your national authority for scope, registration and the CSIRT you report to.

What the directive actually asks for

  • Article 21 requires "appropriate and proportionate technical, operational and organisational measures". Its list includes incident handling, business continuity, supply-chain security, and policies to assess whether the measures work.
  • Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification.

You cannot meet a 24-hour clock for an incident you have not detected. That is where network monitoring comes in.

The checklist

  1. Confirm your status. Establish whether you are an essential or an important entity, which national authority supervises you and which CSIRT receives your reports.
  2. Map what you must protect. List the network segments and assets that support the services in scope — including OT, building systems and remote sites, not just the office LAN.
  3. Put visibility on every segment. A SPAN or TAP port, or a host sensor, on each segment. Watch east–west traffic between internal hosts, not only the perimeter: most attacks move laterally after the first foothold.
  4. Watch for the behaviour that comes before an incident. Command-and-control beaconing, internal scanning, lateral movement, and unusual outbound data volume are the steps that show up in traffic before data leaves.
  5. Cover encrypted traffic without breaking it. Timing, volume, destinations and the TLS handshake reveal beaconing and exfiltration without decrypting anything — which also keeps the monitoring itself easier to justify under GDPR.
  6. Keep OT monitoring passive. Read industrial protocols from a mirror port; never actively probe PLCs or SCADA devices.
  7. Decide who looks at alerts, and when. Write down the incident-handling procedure: who triages, within what time, and who can declare an incident significant. An alert that explains why it fired is triaged faster than one that does not.
  8. Keep the evidence. For every incident: the alerts, the analyst decisions, a timeline and the actions taken — in an audit log you can hand to an auditor or a CSIRT.
  9. Run the reporting clock. Start the Article 23 timers when you become aware of a significant incident, and rehearse the 24-hour early warning at least once before you need it.
  10. Protect the monitoring data. Network metadata includes IP addresses, which can be personal data. Know where your monitoring vendor stores it, sign a data processing agreement under GDPR Article 28, and assess the vendor as part of your supply chain.
  11. Check that it works. Test detection and reporting periodically and record the result: Article 21 asks for policies to assess the effectiveness of your measures.

Where NetSenX fits

NetSenX is a Network Detection and Response (NDR) platform for EU mid-market organisations that detects attacks from network behaviour, explains every alert in plain language and keeps customer data in the EU. For this checklist it covers steps 3 to 9: one agent on a SPAN or TAP port watches a whole segment, every alert lists the network features behind its score, OT protocols are read passively from the Pro plan, and each incident is tracked against the Article 23 deadlines. NIS2 duties stay with your organisation — a tool supports them, it does not fulfil them.

The Free plan monitors up to 3 devices at no cost; Business, at €249 per month, covers up to 100. See the NetSenX pricing plans, the NIS2 readiness overview, or how NetSenX compares with other NDR vendors.

Sources


Written by the NetSenX Team at TriStiX S.L. This article is general information, not legal advice. Questions: [email protected].

NetSenX Team

TriStiX S.L.