
The ITH Security Operations Center (SOC) is a fully managed security operations center that provides continuous monitoring of infrastructure, threat detection, and real-time response to security incidents—all without the need to invest in building your own team.

(promotional offer valid through the end of July)
Freedom and growth without financial risk
Support from a dedicated SOC engineer may be available
(with a 60-month contract)
For market leaders who rely on
to maximize their ROI
Support from a dedicated SOC engineer may be available
NIS2 covers a wide range of digital service providers and telecommunications operators. Check which of the categories listed below apply to your business.
Do you build and operate cable, radio, or fiber-optic infrastructure? The mere fact that you own a public communications network qualifies you as a key...
Do you provide broadband Internet access services to residential or business customers? This is the basis for ISP classification under NIS2. The law leaves no...
Do you manage a DNS system for your own customers? The DNS infrastructure is listed in the NIS2 Directive as a critical component. Its failure...
Do you offer virtual servers, dedicated servers, or managed cloud environments? Even if hosting is just one segment of your business, it is classified separately...
Do you manage a content distribution network or an internet exchange point? NIS2 treats these services as critical infrastructure. Their unavailability has a cascading effect...
Do you provide IP-based voice services to business customers, call centers, or as part of a subscriber package? Over-IP voice services are subject to the...
An ISP infrastructure failure is not just a problem for a single company; it is a real threat to public safety, the functioning of the economy, and the proper functioning of public administration. Therefore, under the directive, operators of essential services have been given the highest priority in terms of cybersecurity. Member States are required to enforce the NIS2 requirements on critical entities with particular rigor. The lack of a systematic approach to cyber risk management puts not only the operator at risk, but also your customers and the country’s entire digital infrastructure.
Formal security policies, risk analysis of network infrastructure and IT systems, and a cyber risk register available to the supervisory authority. Risk management must be an ongoing process, not a one-time event.
Incident response procedures with required deadlines: initial incident reporting to the CSIRT within 24 hours, detailed report within 72 hours. Without a 24/7 SOC, meeting these deadlines is operationally impossible.
A business continuity plan covering scenarios involving ISP infrastructure failures, with a disaster recovery plan that is tested regularly. Crisis management must be documented and practiced, not just put on paper.
Network security architecture, including segmentation, firewalls, traffic monitoring, DDoS protection, and intrusion detection and prevention systems (IDS/IPS). The security of the information systems used to manage the infrastructure must be documented.
The policy for controlling access to network and infrastructure management systems is implemented using MFA, the principle of least privilege, and full logging. All administrative access must be audited for a minimum of 12 months.
Verification and documentation of security standards for business partners and subcontractors: hardware and software vendors, and colocation providers. DNS service providers and external partners require a formal risk assessment.
Regular cybersecurity training for employees and training for management on the responsibilities under NIS2. Employee awareness is essential for an effective system and is a formal requirement of the directive.
Policies for encrypting data in transit and at rest within the ISP's infrastructure. Information security management covers customer data, log data, network device configurations, and billing data.
Regular security scanning of IT systems, patch management for network devices, and documentation of vulnerabilities. Potential threats must be identified before they become actual threats to the network.
Comprehensive audit of an ISP’s network infrastructure in accordance with NIS2 and KSC. Report with priorities for the management board—compliance assessment ready for review by regulatory authorities.
Regular CVE scans of network devices, management systems, and ISP infrastructure. Documentation of the results for the supervisory authority in accordance with the NIS2 standard.
Perimeter protection and network segmentation for the operator, managed by ITH engineers. Network security that includes all documentation required by NIS2 as standard.
ISP infrastructure is a prime target for DDoS attacks. NIS2 requires measures to ensure business continuity—DDoS protection is the technical foundation of compliance.
A security center that monitors the ISP's infrastructure 24/7. Automated incident management procedures with reporting to the CSIRT.
Automatic, tested backups. A recovery plan compliant with and the requirements of the NIS2 Directive. Encryption and redundancy included as standard.

Yes—the NIS2 Directive (EU 2022/2555) explicitly classifies providers of public electronic communications networks and services as critical entities in the digital infrastructure sector. If you provide internet access, voice services, or data transmission to external customers and employ 50 or more employees or have a turnover of 10 million euros or more—you are a critical entity without exception. Smaller ISPs may be designated as such by a decision of the national regulatory authority if they provide critical services. Contact us—we’ll conduct a free assessment.
Key entities (which include ISPs) are subject to a stricter supervisory regime than important entities. The differences are significant: higher financial penalty thresholds (€10 million vs. €7 million), active and proactive oversight by authorities (not merely reactive after an incident), and an obligation to register and report regularly. For key entities, supervisory authorities may conduct unannounced inspections, require external audits, and issue orders to immediately cease operations. For important entities, supervision is reactive—it occurs primarily after an incident.
Business continuity management at an ISP is a formal, documented system that ensures the operator is able to maintain or quickly restore services following a failure or attack. NIS2 specifically requires: a business continuity plan (BCP) describing procedures for maintaining services under various failure scenarios, a disaster recovery plan (DRP) with measurable RTO and RPO objectives, regular testing of both plans (at least once a year), and documentation of the test results. ITH develops and tests both plans as part of the NIS2 implementation for ISPs.
NIS2 imposes a three-stage obligation on ISPs, as key entities, to report serious incidents: (1) an early warning within 24 hours of detection—basic information about the nature of the incident, (2) a full incident report within 72 hours—a detailed assessment, scope, and potential impacts, (3) a final report within 30 days—a description of the corrective actions taken and lessons learned. CSIRT Polska is the primary body responsible for receiving reports. Our 24/7 SOC automates this entire process—from detection and classification to submitting the required report on behalf of your ISP.
Management liability is one of the most significant elements of NIS2 and is very much a reality. The directive requires Member States’ authorities to implement mechanisms for the personal liability of individuals holding management positions. In Poland, this means that penalties of up to 300% of monthly salary may be imposed, and in extreme cases, a ban on holding management positions. This liability is of a supervisory nature—the board of directors is responsible for implementing and maintaining the security system, even if it does not participate in day-to-day technical operations. Therefore, training for management is a mandatory component of our implementation.
Yes—ITH is leading the NIS2 implementation as an external team of experts, minimizing the involvement of the internal IT department. We take on the entire administrative, documentation, and legal burden. This includes: auditing, developing policies and procedures, training, technical implementation of security controls, and continuous 24/7 SOC monitoring. For ISPs without a dedicated security team, this is the most effective and fastest implementation model.