Does NIS2 apply to me as a small or medium-sized business?
Directly affected are companies in one of the 18 regulated sectors with at least 50 employees or more than 10 million euros in annual turnover. Many smaller businesses are affected indirectly, because their larger customers demand evidence of security along the supply chain. In a short scope assessment we clarify your situation – and tell you honestly what is actually needed.
What happens if I do not meet my NIS2 obligations?
NIS2 makes IT security the responsibility of company management – which can be held personally liable. Breaches can attract substantial fines depending on your classification. More important than the penalty is the actual risk: an incident without any preparation quickly costs many times what proper protection would. We help you meet the obligations pragmatically and in a way that stands up to an audit.
What does cyber security cost at NK IT Service?
That depends on the size and condition of your IT. Baseline protection with firewall, endpoint protection, backup and monitoring is available for a predictable monthly fee, well below the cost of a single security incident. After a free check we quote you a fixed price – transparent and with no hidden costs.
Is a traditional virus scanner not enough?
A virus scanner is one building block, but not a strategy. It mainly detects known malware, while modern attacks run through phishing, stolen credentials or unpatched software. Effective protection only comes from firewall, endpoint protection, multi-factor authentication, separate backups and an alert team working together.
Why would anyone attack my company in particular?
In most cases the attack is not personal but automated. Bots scan the internet constantly for vulnerable systems – regardless of industry or size. Hijacked networks are used for extortion, sending spam and further attacks. Small companies without professional protection are therefore an easy and worthwhile target.
How important are backups really?
They are the single most important safety net. In a ransomware attack, a separate, tested backup decides whether you are working again within hours or at a standstill for days. What matters is this: the backup must be kept off the network and tested regularly to confirm it can be restored – otherwise it is worthless when you need it.
What does staff training achieve against cyber attacks?
A great deal – it is often the most effective and at the same time the cheapest measure. Most successful attacks begin with human error: a click on a phishing link, a forged invoice, an email impersonating the boss. A trained team recognises such attempts and reacts correctly. We train with practical examples and in plain language, not by lecturing.
We suspect an attack – what now?
Disconnect affected devices from the network immediately, but do not switch them off in haste, and delete nothing. Do not pay a ransom. Call us straight away – in an emergency every hour counts. We analyse the incident, restore systems from clean backups, close the gap and support you with any reporting obligations.
Do we have to report a security incident?
If NIS2 applies to you, clear deadlines are in force: an initial early warning within 24 hours, a more detailed report within 72 hours and a final report within one month. If personal data is involved, the GDPR reporting duty applies as well. We help with the assessment, the deadlines and the documentation.
Does this also work if another provider looks after our IT?
Yes. We are happy to start with a neutral security check and tell you honestly where your IT stands. On request we work alongside your existing provider, add specific layers of protection or take over the support entirely – whichever makes most sense for you.
Is all this not excessive for a small company?
An understandable concern – but reality looks different: small and medium-sized businesses are popular targets precisely because they are often less well protected. This is not about expensive corporate solutions but about sensible basics: up-to-date systems, a firewall, MFA, backups and a trained team. That foundation is affordable and prevents the vast majority of incidents.