NIS2 & Compliance
Organisations face many different requirements for information and cybersecurity. Some come from legislation, others from standards, contracts or frameworks the organisation itself has chosen to work by.
We help create an overview of the requirements relevant to you, assess how your existing practice measures up to them, and identify where further effort is needed.

NIS2 sets requirements for, among other things, risk management, security measures, management responsibility and follow-up.
Many of the requirements can be found in ISO 27001/27002, so it makes sense to start with what you already have.
We help create an overview of what is in place, where the gaps are, and what should be prioritised.
Compliance is not only about having policies and documentation, but about being able to show that the requirements are actually met in practice.
We help bring relevant requirements together in a common structure, reuse documentation and controls across requirements, and create a more complete picture of compliance.
From insight to concrete priorities
We turn external requirements and internal needs into a realistic, focused effort.





Compliance Assessment
If you need a more systematic picture of compliance, Loft Insight offers an independent Compliance Assessment, where we look at documentation, implementation and actual practice.
See Compliance AssessmentCONTACT
We are happy to have an informal dialogue about your challenges.