1Security

NIS2

Meet NIS2's 24-hour and 72-hour incident reporting deadlines with three years of forensic history, live risk visibility, and evidence for every Article 21 measure - on standard Microsoft 365 licenses.

NIS2 Readiness

NIS2 turns incident response into a race against statutory clocks: an early warning within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours, and a final report within a month. Most organizations cannot answer the underlying questions - what happened, who was affected, is it still happening - in that window, because the evidence lives in 90-day logs and disconnected admin centers. 1Security's job is to make the deadline the easy part.

What NIS2 Actually Requires

The directive (EU 2022/2555, transposed into national law since October 2024) applies to essential and important entities across 18 sectors, and it is not a checkbox exercise:

  • Article 21 mandates risk-management measures: incident handling, logging and detection, access control and asset management, supply-chain security, cyber hygiene, and - critically - policies to assess the effectiveness of those measures.
  • Article 23 sets the reporting clock: 24-hour early warning (including whether malicious action is suspected), 72-hour notification with severity, impact, and indicators of compromise, and a one-month final report covering root cause and mitigation.
  • Management is personally accountable. Boards must approve and oversee the measures, and can be held liable for violations - with fines up to €10M or 2% of worldwide turnover for essential entities (€7M / 1.4% for important ones).

Beating the Reporting Clock

DeadlineWhat the regulator needsWhere you get it
24 h - early warningIs it real? Is it malicious? Is it cross-border?Activity Logs: the account's full timeline with every action attributed to actor, resource, app, device, and location. Location Intelligence separates a genuine foreign sign-in from Microsoft backend noise in one glance.
72 h - notificationSeverity, impact assessment, indicators of compromiseBlast radius on demand: everything the account touched, every file it can still reach, whether sensitive or regulated data was in scope, and which device - managed, personal, or shadow - carried the activity.
1 month - final reportRoot cause, full chronology, mitigation appliedUp to three years of retained history reconstructs the entire attack path - including entry points months old - and the remediation trail (revoked links, stripped permissions) documents your response.

Evidence for the Article 21 Measures

NIS2 doesn't just ask you to have controls - it asks you to demonstrate they work. That's the hard part, and it's where continuous visibility replaces the annual PDF:

  • Incident handling & detection - Trends run 50+ prebuilt and unlimited custom detections over the permission graph: mass downloads, insider-risk patterns, sensitive data exposed to AI. Alerts arrive in minutes, not at the next audit.
  • Logging & forensic readiness - three years of unified, searchable audit history on standard licenses, instead of a log-storage bill that punishes you for being prepared.
  • Access control policy - the permission graph shows effective access (nested groups and inheritance resolved), so least-privilege is something you measure, and access reviews audit reality instead of intentions.
  • Asset management - live inventories of devices (including shadow devices that never registered), sites, and connected apps - the assets you can't protect are the ones you don't know about.
  • Supply-chain security - every third-party app and AI agent with a foothold in your tenant, its publisher verification, its access channel, and who let it in.
  • Effectiveness assessment - sensitivity-label coverage measured against actual sensitive-data locations: the difference between "we have a data classification policy" and "here is its coverage, as a number, trending quarterly."

The 72-Hour Drill

Run this as an exercise before you run it as an incident: pick a user account, and within one sitting produce (1) their complete 90-day activity timeline with devices and locations, (2) every file, site, and mailbox item they can currently reach, (3) how much of it carries regulated data, and (4) one revoked permission as remediation evidence. If you can do it in a drill, the 72-hour notification stops being frightening.

Scope, Honestly

1Security provides the forensic record, the live risk visibility, and the remediation trail that NIS2 obligations rest on. Whether a given incident is "significant," which national authority receives your report, and how your sector's transposition applies - those are calls for your compliance counsel. Bring them the evidence; 1Security makes sure you have it.

On this page