{"id":20115,"date":"2026-08-13T06:33:39","date_gmt":"2026-08-13T04:33:39","guid":{"rendered":"https:\/\/nexer.nl\/nis2-preparation-for-smes-this-is-how-you-do-it\/"},"modified":"2026-08-13T06:33:39","modified_gmt":"2026-08-13T04:33:39","slug":"nis2-preparation-for-smes-this-is-how-you-do-it","status":"publish","type":"post","link":"https:\/\/nexer.nl\/en\/nis2-preparation-for-smes-this-is-how-you-do-it\/","title":{"rendered":"NIS2 preparation for SMEs: this is how you do it"},"content":{"rendered":"<p>A ransomware attack that halts your planning, a supplier who is temporarily unavailable or an employee who clicks on a phishing email: for many SMEs, these are not abstract IT risks. With good NIS2 preparation for SMEs, you can turn separate security measures into an approach that protects your business continuity. Not because every organization will soon have the same rules, but because digital resilience is increasingly a prerequisite for continuing to serve customers, chain partners and growth.<\/p>\n<p>NIS2 does not ask for a folder full of policies that no one opens. The core is that you demonstrably know what digital risks your organization runs, take appropriate measures and assign responsibility at board level. Especially for companies without an extensive internal IT department, this is an opportunity to finally bring structure to security, management and continuity.<\/p>\n<h2>What does NIS2 mean for SMEs?<\/h2>\n<p>The European NIS2 Directive is intended to increase the cyber resilience of essential and important organizations. The Dutch elaboration ultimately determines which companies formally fall under the law. That depends, among other things, on your sector, size and role in the chain. Think of organizations in or around energy, transport, healthcare, digital services, production, waste management and critical supply.<\/p>\n<p>Many SMEs do not fall directly within the formal scope. Yet waiting is often not a wise choice. Larger customers can translate NIS2 requirements to suppliers. In tenders and contract renewals, questions about information security, incident notification, backup and access management are increasingly recurring. In addition, the same measures also limit your own risk of outages, data loss and reputational damage.<\/p>\n<p>The question is therefore not only: do we have to comply? A better question is: can we demonstrate that we have control if a cyber incident affects our operation?<\/p>\n<h2>NIS2 preparation for SMEs starts with business risks<\/h2>\n<p>A technical checklist is a useful tool, but not a starting point. Start with the processes that keep your organization running. Which systems are needed to produce, help customers, register hours, send invoices or have employees work? Which data should not be leaked? And what happens if a cloud application, internet connection or workplace is unavailable for a day?<\/p>\n<p>Then map out the dependencies. For example, a company may be well protected against an attack in the office, but still shut down if the external planning tool is unavailable. Suppliers also deserve attention: who manages your Microsoft 365 environment, who has access to your network and what agreements have been made about security and recovery?<\/p>\n<p>Make risks concrete. Not: &#8216;<a href=\"https:\/\/nexer.nl\/en\/what-is-phishing\/\">phishing is a risk<\/a>&#8216;, but: &#8216;a financial employee can make an incorrect payment via a forged payment instruction&#8217;. Then it will also become clear what combination of measures is needed: technical e-mail security, payment procedure, segregation of duties and targeted awareness.<\/p>\n<h3>Determine who is responsible<\/h3>\n<p>NIS2 explicitly places responsibility on the board or management. That does not mean that a director has to install patches himself. However, the management must be able to make decisions about priorities, budget, risk acceptance and follow-up. Entrusting security entirely to an external supplier without internal ownership is therefore insufficient.<\/p>\n<p>Therefore, appoint a responsible person who monitors progress and brings the right people together. In a smaller company, this can be the operational manager or financial director, with the support of an IT partner. Define who reviews incidents, who informs customers, and who decides on temporarily disabling systems. In the event of an incident, speed is important, but unclear roles actually slow down.<\/p>\n<h2>Build measures in the right order<\/h2>\n<p>The temptation is great to immediately purchase a new security tool. Sometimes this is justified, but often the biggest improvements lie in basic management that has not yet been set up consistently. Work in phases and start with measures that reduce multiple risks at once.<\/p>\n<p>First, make sure you have a reliable overview of <a href=\"https:\/\/nexer.nl\/en\/req-p4ijzgjlylkelvru0pbrt-jpeg-2\/\">devices, accounts, applications,<\/a> and administrator privileges. You can&#8217;t protect what you don&#8217;t know. Remove old user accounts, restrict local administrative privileges, and introduce multifactor authentication for email, cloud applications, remote access, and administrative accounts. Administrator accounts in particular deserve extra protection, because an attacker can quickly cause major damage.<\/p>\n<p>This is followed by management discipline. Updates to operating systems, software and network equipment must be demonstrable and timely. This does not necessarily mean that every update is rolled out immediately without checking. For business-critical software, testing may be necessary. In that case, record who makes the assessment, what exceptions there are and when you will reassess them.<\/p>\n<p>Backups are a second foundation. A backup that only exists is not yet a recovery strategy. Verify that copies are separated from your production environment, that they are protected from deletion, and that recovery is actually being tested. Also discuss the recovery order: restoring a file server is of little value if employees cannot log in yet or the internet connection is missing.<\/p>\n<p>For most SME organizations, these components deserve first attention:<\/p>\n<ul>\n<li>strong access management with multi-factor authentication and minimal privileges;<\/li>\n<li>up-to-date patch and device management for workstations, servers, and network equipment;<\/li>\n<li>tested, segregated backups with clear recovery priorities;<\/li>\n<li>monitoring and logging that make deviations and incidents visible;<\/li>\n<li>an incident procedure with contact persons, decision moments and communication agreements.<\/li>\n<\/ul>\n<p>This basis is not spectacular, but it is decisive. An advanced detection tool is of little use if accounts are left unmanaged or remediation has never been tested.<\/p>\n<h2>Make incident reporting and remediation actionable<\/h2>\n<p>NIS2 also includes the ability to recognize, assess and, where necessary, report significant cyber incidents in a timely manner. The exact legal reporting periods and competent authority follow from the Dutch regulations and your situation. Don&#8217;t wait until an incident to find out where the relevant information is.<\/p>\n<p>Create a practical incident plan of a few pages. Describe how employees report a suspicious message, lost device, or potential data breach. Capture the telephone numbers of IT, management, insurer and legal support. Determine who retains evidence, who can isolate systems, and who communicates externally. A pre-coordinated approach prevents employees from switching off systems in a panic or from sharing incomplete information too early.<\/p>\n<p>At a minimum, practice this plan with a realistic scenario. For example: all employees receive a notification that files have been encrypted and order processing has come to a standstill. Who is calling whom? Which environment will be closed off? Can you still take orders by phone? How long does recovery take? Such an exercise reveals gaps that go unnoticed in a policy document.<\/p>\n<h2>Take a critical look at your IT partners and suppliers<\/h2>\n<p>Your own level of security is partly determined by parties that have access to systems or data. Therefore, do not only ask whether a supplier &#8216;works safely&#8217;, but make agreements that can be verified. Think of access levels, incident notification, backup responsibility, patch management, logging, data residency and termination of access at contract end.<\/p>\n<p>Here too, the approach must match the risk. A supplier that sends your newsletter requires different checks than a party that hosts your financial administration. Heavy contract requirements for every small supplier take time and do not always provide extra security. Focus most of your attention on parties that directly affect your critical processes, personal data, or network access.<\/p>\n<p>A <a href=\"https:\/\/nexer.nl\/en\/when-do-you-really-need-an-it-partner\/\">managed IT partner<\/a> can help translate these agreements into daily practice. Nexer does not only look at individual technical measures, but at the question of which IT dependencies your organization has and what continuity you need to continue to grow.<\/p>\n<h2>From a baseline measurement to a workable plan<\/h2>\n<p>Good preparation does not have to start with a large project. Carry out a baseline measurement and determine which measures are already in place, where the greatest risks are and which actions can be implemented within three months. Give each action an owner, deadline and clear result. &#8216;Improving security&#8217; is too broad. &#8216;Activate and test multi-factor authentication for all external access&#8217; is measurable.<\/p>\n<p>In addition, schedule fixed evaluation moments. IT landscapes are changing due to new employees, cloud applications, acquisitions and changing customer requirements. A one-off audit quickly becomes outdated. By periodically discussing risks, incidents, suppliers and remediation tests, security becomes part of your business operations rather than an annual obligation.<\/p>\n<p>The best first step is often surprisingly simple: schedule a meeting in which management, operations and IT together determine which incident your company should absolutely not shut down. From that answer, a preparation arises that is not only aimed at NIS2, but especially at an organization that can continue to work under pressure.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIS2 preparation for SMEs: get a grip on risks, roles and measures with a practical approach that fits your organization and growth plans now.<\/p>\n","protected":false},"author":2,"featured_media":20114,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[45],"tags":[],"class_list":["post-20115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/posts\/20115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/comments?post=20115"}],"version-history":[{"count":0,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/posts\/20115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/media\/20114"}],"wp:attachment":[{"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/media?parent=20115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/categories?post=20115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nexer.nl\/en\/wp-json\/wp\/v2\/tags?post=20115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}