Security has become a board-level responsibility
Ransomware, phishing, credential theft, cloud incidents: the threats reach companies of every size, and the regulatory picture — starting with the NIS2 directive, in force in Italy since 16 October 2024 with ACN as the competent authority — asks organisations for a structured approach to risk, incidents and suppliers.
Xion IT Group takes security from the technical plane to the organisational one: assessment, measures, monitoring, procedures and training, proportionate to your situation. It is the natural evolution of our long-standing IT security service, strengthened for today’s regulatory demands.
The services
- Cybersecurity assessment — analysis of networks, endpoints, cloud, access, backup, email and policy;
- NIS2 pre-assessment and readiness — scope, gap analysis, compliance plan and support with ACN obligations;
- Vulnerability assessment — scanning and verification of exposed weaknesses;
- Infrastructure hardening — firewall, VPN, multi-factor authentication, segmentation, patch management, endpoint protection (EDR);
- Ransomware-resistant backup and business continuity — off-site copies, multiple versions, restore testing with XRB;
- Incident response — procedures to detect, contain, document and notify within the required timescales;
- Security awareness — anti-phishing training and safe use of tools, AI included;
- Reports for management — because security can only be governed if it is measured.
The entry package: Xion Cyber & NIS2 Check
A compact starting route: NIS2 pre-assessment, a review of network, endpoints, cloud, backup and email, a prioritised plan with the recommended technical measures, a training proposal and a report for management. Within a few weeks you know where you are exposed and what to do first.
The platform: GAPOFF
NIS2 obligations — measures, incidents, suppliers — have to be documented and maintained over time. That is why Xion built GAPOFF (www.gapoff.it): the compliance operations platform that turns NIS2, GDPR, DORA and ISO 27001 into tracked workflows, ready for inspection at any point.
From the check to a continuous watch
The assessment is the photograph; real security is the film. With support contracts and XION MSP monitoring, the measures stay current, the backups stay verified and incidents get handled — 365 days a year.
NIS2: establishing quickly whether it applies to you
The question every company asks is: “does this apply to me?”. The directive identifies essential and important entities across a list of sectors (energy, transport, health, digital infrastructure, critical manufacturing, waste management, food, space and others) above certain size thresholds. But the real perimeter is wider than it looks, for two reasons: many companies are in scope without knowing it, and — more importantly — anyone supplying an in-scope organisation is drawn in indirectly, because large customers are required to verify the security of their supply chain. In practice, security questionnaires reach suppliers well before direct obligations do. A pre-assessment of a few hours establishes where you stand and what is genuinely needed.
The measures that matter, in the right order
Security is not a shopping list to be bought all at once: it is a sequence of priorities. The order in which we work, judged by risk reduced against effort, is almost always this:
- Multi-factor authentication on email, remote access and critical systems — it stops most attacks based on stolen credentials;
- Off-site, isolated and tested backup — the safety net that turns a disaster into an inconvenience;
- Systematic updates — the overwhelming majority of attacks exploit flaws fixed months earlier;
- Modern endpoint protection (EDR) and email filtering;
- Network segmentation and access control on least privilege;
- Staff training — the human link is the first target;
- An incident response plan — because “what do we do if it happens” has to be decided beforehand, not during.
What happens when the incident arrives
Prepared companies are not the ones that never get hit — they are the ones that know what to do when it happens. NIS2 imposes tight notification timescales (early warning within 24 hours, notification within 72), which makes improvisation impossible. Our incident response work prepares the company to detect the incident, contain it, document it and notify it within the deadlines, with roles, contacts and procedures defined in advance. It is the difference between orderly handling and the panic that multiplies the damage.
Related pages
Three pages on what comes before and after: vulnerability assessment for cataloguing known weaknesses, incident response for the correct order of the first few hours, and what to do after a data breach for the obligations that follow.