
As an investment fund, you are responsible not only for your own security but also, indirectly, for your portfolio companies’ compliance with the NIS2 Directive. Non-compliance by a portfolio company in a critical sector poses a real risk today to valuation, the due diligence process, and a secure exit. ITH supports organizations at every stage of NIS2 implementation. We provide 24/7 security monitoring (SOC) and a SIEM system that detects threats before they disrupt business continuity.
The NIS2 Directive harmonizes cybersecurity requirements across the EU and introduces stronger oversight and enforcement mechanisms than the previous NIS Directive from 2016.
In Poland, the regulation was implemented as an amendment to the Act on the National Cybersecurity System. The new NIS2 provisions have been in force under Polish national law since April 3, 2026. Companies that met the criteria on the date the Act entered into force have until April 3, 2027, to implement the required procedures. Critical entities are additionally required to conduct their first security audit by April 3, 2028.
The NIS2 Directive covers 18 economic sectors that are critical to the functioning of the state and classifies entities as either critical or important. These include financial market infrastructure and the banking sector.
For an investment fund, it is crucial that NIS2 applies not only to financial institutions that manage capital, but above all to portfolio companies operating in the following sectors: medtech and healthtech startups, digital infrastructure companies, medical device manufacturers, and service providers to public administration. Even micro and small portfolio companies may be indirectly subject to NIS2 through the supply chain of a larger counterparty in a critical sector.
NIS2 imposes obligations on both the fund itself and the companies in your portfolio that operate in key sectors. The most important of these include:
commensurate with the estimated risk and actual threats to which the IT systems and the networks and IT systems used to serve customers are exposed.
that demonstrate compliance with safety requirements. You are required to provide up-to-date audit documentation upon request by the competent authorities.
disaster recovery plans and response procedures that must withstand the test of a real-world attack, not just a paper audit.
A portfolio company’s failure to comply with regulations poses not only the risk of administrative sanctions for the fund, but also operational and reputational risks that directly affect the value of the investment.
Failure to comply with NIS2 regulations carries real risks—not only financial, but also personal for senior management:

Institutional investors and buyers in exit transactions are increasingly asking directly about compliance with NIS2 and whether the company has a SOC or SIEM system...
A data breach or ransomware attack at a company in a critical sector creates reputational risk that spreads across the entire portfolio.
An information security management system, audits, and a track record of incident reporting are a strong selling point in discussions with potential investors.
ITH will guide your fund through the entire implementation process: a single audit, a consistent process managed by a single provider.
We start with an audit to identify cybersecurity vulnerabilities. The next step is to prepare comprehensive documentation ready for inspection and to train the entire team. We conclude the implementation process with a final report and the launch of ongoing monitoring.
Our team of analysts monitors your infrastructure around the clock. We provide real-time threat detection and support your organization in responding to incidents, even at night and on weekends.
This system collects and correlates events from servers, network devices, and endpoints in a single location and detects potential threats before they disrupt your business operations.
The goal of these training sessions is to prepare organizations for compliance audits and to increase their overall resilience against cyberattacks. Don’t let your company become an easy target. Regular training helps employees respond effectively to constantly evolving threats.
ITH SOC is a team of analysts that takes on the responsibility of continuously monitoring the fund’s infrastructure and real threats before they lead to serious financial and reputational damage:
The ITH SIEM system collects logs from various sources, correlates security events, and delivers real-time security alerts.
SIEM collects data from:
A managed SIEM eliminates the need to invest in licenses, infrastructure, or your own cybersecurity specialists. You receive a ready-to-use environment maintained by ITH experts.
Even the best-secured infrastructure won’t help if a team member opens a malicious attachment or provides login credentials in response to a fraudulent phone call. Our training programs combine theory with practice. The hands-on components of the training help employees understand that their everyday decisions matter for the security of the entire company.
Choose the plan that's right for your organization:
The perfect introduction for all employees. Raising awareness of everyday hazards.
It expands participants' knowledge of the practical aspects of information security. Each participant receives training materials and a certificate.
Advanced incident response procedures and crisis management for IT and security personnel and executive management.
Audits, NIS2 and SOC implementation, SIEM, training, as well as internet services, colocation, backup, and managed firewalls—all from a single...
ITH is not only a security integrator but also an electronic communications provider with full visibility into network traffic. This...
Is the fund's portfolio growing, with more companies being added to the coverage? The scope of our service grows along...
The ITH team has many years of experience in the IT and telecommunications markets—we design, maintain, and secure networks and...
The documentation, reports, and procedures prepared by ITH serve as ready-to-use evidence during security audits, funding rounds, and exit processes.
Implementing NIS2 is a process that takes time. The sooner you start preparing, the better your chances of avoiding costly consequences.

It depends on the fund’s structure and whether its investment activities qualify as part of the financial market infrastructure within the meaning of the Act on the National Cybersecurity System. Regardless, the obligations under NIS2 almost certainly apply to some of the companies in the portfolio. In most cases, it is these companies that generate the risk, which ultimately falls on the fund.
Yes, this is one of the most common scenarios when working with funds. ITH applies a single, consistent audit methodology to all companies in its portfolio, which allows the fund’s partners to compare compliance levels and risks across investments and prioritize corrective actions.
In accordance with NIS2 security requirements, a multi-stage model is in place: an early warning within 24 hours of detection, a detailed incident report within 24–72 hours, and a periodic report within one month. The ITH SOC maintains this documentation on behalf of the organization, ensuring compliance at every stage.
Yes—the monthly and quarterly risk overview reports, as well as the NIS2 documentation, are materials that effectively shorten the due diligence process conducted by a prospective investor or buyer.