Skip to content
A line of container gantry cranes standing against the sky at dusk over a port terminal.

Industries

The same frameworks. Very different conversations.

A hospital, a payment institution and a Kubernetes-native SaaS vendor can all be in scope for NIS2 and reach completely different conclusions about what to do first. Below is where we usually start, by sector.

Financial services

Banks, payment institutions, insurers, asset managers and the ICT providers they depend on.

What is driving it

DORA applies in full, and it is unusually specific: an ICT risk management framework, incident classification against defined thresholds, a register of information covering every contractual arrangement, tested resilience, and threat-led penetration testing for the entities that meet the criteria. Supervisors have started asking for the register rather than asking whether it exists.

Where we usually start

A register of information built from the actual contract base rather than from memory, and a gap review of third-party contracts against the DORA clauses. That work exposes most of the rest: concentration risk, missing audit rights, and exit plans nobody has written.

Bank towers lit at night above a river, their reflections broken on the water.

Relevant packs

Healthcare

Hospitals, clinics, laboratories, medical device makers and health data platforms.

What is driving it

Health entities sit at the intersection of NIS2, the GDPR's special-category rules, national hosting requirements such as HDS in France, and — for device makers — the CRA on top of medical device regulation. Meanwhile ransomware in this sector is not a data problem, it is a continuity problem with clinical consequences.

Where we usually start

Continuity first: backup isolation, restore testing and a crisis exercise with the clinical leadership in the room. Then the regulatory mapping, because a health organisation that can keep operating buys itself the time to do the compliance work properly.

An empty intensive care room, the bed flanked by monitoring and ventilation equipment.

Relevant packs

Energy and utilities

Producers, network operators, suppliers and the industrial systems behind them.

What is driving it

Almost always classified essential under NIS2, with national requirements layered on top and a genuine IT/OT split. The corporate network and the control systems have different owners, different lifecycles, different tolerances for a reboot, and usually no agreed segmentation between them.

Where we usually start

An asset inventory and a zone-and-conduit model across the IT/OT boundary, using passive techniques on production networks. Segmentation decisions follow from that map, and so does a realistic NIS2 position.

Wind turbines spread across open high ground, seen from the air.

Relevant packs

Transport and logistics

Operators, freight forwarders, port and airport services, fleet and warehouse platforms.

What is driving it

NIS2 scope, thin margins, and an operational reality where a system outage stops physical movement within hours. The supply chain is also the attack surface: customs platforms, partner EDI links, telematics and third-party warehouse management systems all sit inside the perimeter.

Where we usually start

Third-party and interconnection security — who connects to what, with which credentials, and what happens if one of them is compromised — followed by continuity planning built around the operations that cannot pause.

Container cranes lit along a bay at night, under a broken cloud sky.

Relevant packs

SaaS and technology

Software vendors, scale-ups and platform businesses selling to enterprise customers.

What is driving it

Compliance arrives through the sales pipeline. A prospect asks for ISO 27001 or SOC 2, security questionnaires start blocking deals, and now the CRA adds product obligations for anything placed on the EU market. All of it lands on an engineering team that ships weekly and has no appetite for a parallel compliance bureaucracy.

Where we usually start

Compliance as code. Map the controls once, implement them as automated checks in the pipeline, and let the evidence collect itself. Certification then becomes an audit of something that already works rather than a documentation project.

A close view of code on a monitor, the individual pixels of the text visible.

Relevant packs

Public sector

Local authorities, agencies, public establishments and their delegated operators.

What is driving it

NIS2 scope for many entities, national security frameworks on top, procurement rules that shape how the work can be bought, and budgets set a year in advance. Sovereignty and data residency are rarely optional, and citizen-facing services cannot simply be taken offline for a migration.

Where we usually start

An applicability and maturity assessment producing a costed multi-year plan that fits the budget cycle, plus a sovereignty and residency position that can be defended publicly.

The European Commission headquarters in Brussels, its glass wings curving along the street.

Relevant packs

Industrial and OT

Manufacturers, process industries and equipment makers with connected products.

What is driving it

Production systems with twenty-year lifecycles, vendors who void support if you patch, and a growing connected-product business that now falls under the CRA. Two separate problems, usually owned by two separate parts of the company, arriving at the same time.

Where we usually start

For the plant: an IEC 62443 assessment with a specialist partner and a segmentation plan. For the products: CRA classification, SBOM and a vulnerability handling process, because that one has a hard market-access deadline.

The head of a computer-controlled milling machine cutting a part on its bed.

Relevant packs

Subsidiaries of international groups

European, African and South American entities of groups headquartered elsewhere.

What is driving it

Group policy written for another jurisdiction, local regulators asking questions the group framework does not answer, and a local team with no authority to change either. NIS2 registration is national. Data protection law is local. Group ISO certification may or may not cover the entity.

Where we usually start

A gap analysis between the group framework and local obligations, producing a short list of genuinely local requirements and the evidence to satisfy them — usually far less work than the local team feared, and defensible to head office.

An airport departure board, destinations and times running down the screen.

Relevant packs

Your sector is not on the list?

The frameworks are the same. The starting point is what changes. Tell us the situation and we will tell you where we would begin.