ith security

Implementing NIS2 for Your Business

Audits, security implementation, and ongoing monitoring—all in one place. ITH will guide you through the entire process—from assessment to certification.

:

:

:

:

What is the NIS2 Directive?

EU DIRECTIVE 2022/2555

Network and Information Security – Version 2

  • icons8-document-96 (1) 1
    It replaces the 2016 NIS Directive—with a scope expanded to include new sectors and stricter penalties
  • icons8-company-72 1
    Applies to key and important entities, companies with 50 or more employees or annual revenue of €10 million or more
  • icons8-law-100 (1) 1
    Implemented into Polish law as an amendment to the Act on the National Cybersecurity System

Penalties and Personal Liability for Non-Compliance

Failure to comply with NIS2 regulations carries real risks—not only financial, but also personal for management:

  • The maximum administrative fine for critical entities may amount to up to 10 million euros or 2% of the organization’s annual turnover. The higher amount applies.
  • The board of directors bears personal liability for failure to properly implement compliance. Penalties for board members include a ban on holding executive positions. Additional sanctions may include fines of up to 300% of their compensation.

Cybersecurity is therefore no longer solely the responsibility of the IT department; it has become part of management’s responsibilities, on par with the financial and legal security of the entire organization.

ith-nis-kary-img
More than 38,000 entities in Poland

Who is affected by NIS2?

Digital infrastructure
Transport
Energy
Banking and Finance
Healthcare
ICT Service Management
Digital service providers
Waste management
Postal and courier services
Food production
Public administration
Industrial production
Scientific research
Financial market infrastructure
Outer space

Don't risk fines. Check whether NIS2 applies to your company

NIS2 Implementation Model

Four stages, one supplier, full engineering support
01

Compliance Audit
Assessment of gaps against NIS-2, ISO 27001, and KSC, including a roadmap for corrective actions.

  • NIS-2 Compliance Audit Report
  • Identification of Gaps and Non-Compliances
  • Recommendations for Corrective Actions
  • Compliance Roadmap
02

Documentation & Compliance
A complete NIS-2 documentation package, ready for inspection by the supervisory authority.

  • Consistent NIS-2 documentation package
  • Formal compliance with regulations
  • Readiness for implementation and inspection
  • Security policies and BCP/DRP
03

Training & Organization
Trained management and staff with proof of completion.

  • Training for management
  • Training for staff
  • Training materials
  • Training Completion Certificates
04

Closure & SOC
Closing report, launch of 24/7 monitoring, and formal preparation of the organization.

  • Confirmation of documentation implementation
  • Closing audit report
  • Launch of 24/7/365 SOC
  • Readiness for supervisory inspection

SIEM + XDR

security monitoring platform
6-n

24-hour monitoring

5-n

Incident Analysis

7-n

Support in responding

8-n

Threat detection

SIEM collects logs from:

EDR/XDR systems
Cloud systems
Active Directory
Backup systems
Firewall/IDS/IPS
Windows / Linux servers
Windows/Linux/macOS client stations
Network devices

Reporting

Monthly Report
(incidents, statistics, recommendations)

Quarterly Management Report (Risk Overview)

Reporting to authorities (NIS-2)

SOC for Your Company

A cyberattack can paralyze a company's operations and expose it to costly downtime and data loss. The ITH team provides 24/7 monitoring of the IT infrastructure and responds to threats before they cause significant damage:

  • 24/7/365 Monitoring – ITH continuously ensures the security of your organization.
  • Real-time threat detection, with a response time of less than 15 minutes and immediate isolation of compromised systems.
  • Ransomware Protection – We detect characteristic file encryption patterns before your company’s documentation is locked.
  • Phishing and BEC Detection, one of the most common ways to breach administrative systems.
  • Complete documentation of computer security incidents compliant with NIS2 requirements and timely reporting to the appropriate authorities.
  • Periodic Report (monthly and quarterly risk overview report) for management, free from technical jargon.

Cybersecurity training tailored to your organization's needs

Even the most secure infrastructure won't help if someone on your team opens a malicious attachment or provides login credentials in response to a fraudulent call. Our training combines theory with practice. The practical aspects of the training help employees understand that their daily decisions impact the security of the entire company.

Select package:

2 HOURS

Basic Security Training

An ideal introduction for all employees. Increased awareness of everyday threats.

  • Due Diligence in Data Protection—Legal Basis
  • Password Creation and Multi-Factor Authentication (MFA)
  • Phishing detection
  • No limit on the number of participants—the ability to train the entire organization simultaneously
6 HOURS

Premium Security Training

Advanced response procedures and crisis management for IT and security officers and management.

  • Attack simulations—deepfakes, spoofing
  • Documentation as proof of due diligence to the supervisory authority
  • “Before” and “after” knowledge tests
  • +1 hour of consultation in areas requiring additional support

The service was designed to:

take the load off internal IT departments
improve the organization's cybersecurity
ensure compliance with the requirements of NIS-2, ISO 27001, and KSC
minimize the risk of downtime and data breaches
niko-nis2-cytat
“NIS2 isn't a compliance cost—it's an investment in trust, business continuity, and the ability to continue selling”
Niko Balazy, CEO ITH

Write to us

Support
Maintenance

ITH NOC
Management Center
Infrastructure ITH
Open all week, 24 hours a day

Solutions
for you

ITH sales team
Open Monday through Friday from 9:00 a.m. to 8:00 p.m.

    Expand This offer does not constitute an offer within the meaning of the Civil Code. This offer is intended solely for business customers. All prices listed are net prices. * Pursuant to Article 23 of the Act of August 23, 1997, on the Protection of Personal Data (Journal of Laws of 2016, No. 922 of June 28, 2016, consolidated text), I hereby consent to the processing of my personal data provided in the form above (i.e., Tax Identification Number (NIP), phone number, email address) by ITH Sp. z o.o., with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, Tax ID (NIP): 7010389026, REGON: 146777630, for the purpose of presenting and fulfilling a commercial offer. I have been informed of my right to access the data I have provided, to modify it, and to object to its further processing. The controller of personal data is ITH Sp. z o.o., with its registered office in Warsaw, at ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630.
    _DSC6603