secria.eu
The cybersecurity obligations of NIS2, and the security questionnaires your major customers send.
NIS2 brings thousands of companies under obligations for risk management, incident reporting and management accountability. But the largest group that notices something, does not even fall under it themselves: the directive also requires companies to demonstrably assess their suppliers. The result is that an installation company or software vendor suddenly receives a security questionnaire of eighty questions in their mailbox, with the message that the contract depends on it.
secria builds the dossier from which you answer those questions. Record once what security measures you have actually implemented, and then fill in every subsequent questionnaire from what is already there — instead of starting from scratch in someone else's spreadsheet each time.
What it does
The measures register
What you have arranged in terms of security, documented in a way you can show a customer. This is the dossier everything else derives from.
Policies and procedures
Information security policy, incident procedure and supplier policy, drawn up from your own dossier — with your own systems in it, not as an empty template.
The questionnaire processor
Your customer's questionnaire in, your answers out, based on what is already in your dossier. What you have not yet arranged comes out as an open item.
Incident reporting support
What you must report, where, and within what timeframe — per country, as the implementation differs. We guide the reporting; you do it yourself.
Awareness training per employee
With a separate certificate of participation for each person, and retraining whenever your dossier changes.
For whom
- Companies that themselves fall under NIS2 and do not know where to start
- Suppliers to larger companies that receive security questionnaires
- SME managers who are personally liable and have only just found out
Where it is found
Entirely new field with the same untapped space that aiacta found with the AI Regulation: "does my company fall under NIS2", "NIS2 supplier questionnaire", "information security policy example SME", sector × requirement.
Frequently asked questions
Do I fall under NIS2?
That depends on your sector and your size, and the check will answer it in a few minutes. Note: even if you do not fall under it, you can still have the obligations imposed on you via your customers.
Will you solve a cyber incident for me?
No. Actual incident response and audits fall outside what we do; for that we refer you elsewhere. We help with the dossier, the documents and reporting on time.
Is this the same as ISO 27001 certification?
No, and we do not pretend it is. Certification is an audit by an accredited party. What is created here is a dossier with which you can demonstrate what you have arranged.
How this platform is built
Like every platform of Theos Group: on one shared foundation, under your own management, with your own automatic administrator — here E.D.I.T.H. — who runs the daily rounds, reports outages and writes the daily report. What we learn from one system is in all the others the week after.