Risk management
Concepts for risk analysis and information system security, incident handling, business continuity and crisis management.
focus area · cybersecurity as an obligation
The NIS 2 Directive extends the EU's cybersecurity obligations to far more companies. In Germany it is implemented by the NIS 2 implementation act; the BSI is the competent authority. Affected are not only operators of critical infrastructure but many mid-sized companies from 50 employees in 18 sectors — and indirectly their suppliers. We help with classification, implementation and the interplay with AI systems.
NIS 2 distinguishes “particularly important” and “important” entities. Sector and size are decisive: as a rule, companies from 50 employees or €10 million turnover are affected if they operate in one of the sectors — including energy, transport, health, water, digital infrastructure, ICT service management, postal services, waste, chemicals, food, manufacturing (incl. mechanical engineering, vehicle construction, medical devices, electronics), digital service providers and research.
Unlike earlier rules there are no official notices: companies must check themselves whether they are affected and register with the BSI. Suppliers not covered by the law themselves are effectively included via their customers' supply chain obligations.
The law requires a minimum level of risk management — appropriate, proportionate and documented.
Concepts for risk analysis and information system security, incident handling, business continuity and crisis management.
Significant security incidents: early warning within 24 hours, notification within 72 hours, final report within one month to the BSI.
Security in the supply chain and with service providers; requirements for procurement, development and maintenance.
Cryptography, access control, multi-factor authentication, vulnerability management, employee training.
Registration with the BSI including a point of contact; evidence obligations for particularly important entities.
Management must approve and monitor measures and be trained itself — and is personally liable for violations.
AI systems are information systems within the meaning of the law. Anyone operating language models, agents or automations must include them in risk management: access, data flows, interfaces, providers. External AI providers are service providers in the supply chain — with the corresponding requirements for contracts and review.
At the same time AI helps with implementation: evaluating logs, detecting anomalies, prioritising vulnerabilities and preparing notifications within the tight deadlines. Here too: people decide, AI prepares — and its use is documented.
Those already working to ISO 27001 or TISAX have structurally met a large part of the NIS 2 requirements — what is usually missing is registration, reporting processes and the formal involvement of management. Conversely, NIS 2 provides the occasion to build an information security management system that also serves the EU AI Act and GDPR. We plan implementation so that measures are built once and evidenced for all frameworks.
For particularly important entities, fines of up to €10 million or 2% of global annual turnover are provided, for important entities up to €7 million or 1.4%. Add BSI orders and the personal liability of management. The law is in force; registration and evidence deadlines are running. We check specific deadlines and the current state of implementation with you at project start, as details are updated through regulations and BSI requirements.
privacy first ai
Management must approve, monitor and understand measures. We translate the law into an implementation plan that leadership can carry — and into measures that work day to day.
Applicability, entity type and sector documented traceably — as the basis for registration and audits.
Risk management, reporting processes and supply chain requirements with clear owners and evidence.
Management and employees are trained — eligible for funding through our AZAV-certified offerings.
process
Four steps from applicability check to verifiable operation.
Classification by sector and size, comparison of existing measures with the obligations, assessment of the supply chain.
Prioritised measures for technology, organisation and reporting processes; inclusion of AI systems and providers.
Introduction of measures, registration with the BSI, training of management and employees.
Regular operation with monitoring, exercises for the reporting case, documentation for evidence and audits.
contact
Happy to help with anything AI. We will get back to you promptly.
We will get back to you shortly. If it is urgent, you can reach us at +49 371 524 99 140 or contact@sellium.ai.