Vai al contenuto

Advanced cybersecurity and NIS2

Assessment, working protection and regulatory readiness for companies that cannot afford to stop.

In breve

Most attacks do not force the firewall: they arrive through an email opened by somebody who is simply doing their job. The defences that genuinely move the risk are four, in this order: a second factor on remote and administrative access, network separation, one backup copy nobody can delete, and a written procedure for the first few hours. Xion starts with an assessment rather than a quotation.

From the picture to the plan

The assessment records real risks across networks, endpoints, cloud, email and backup - and produces a concrete order of priorities.

NIS2 readiness

Scope, security measures, incident handling and suppliers - the complete route to NIS2 compliance.

Incident response

Procedures ready to detect, contain and document an incident - within the tight timescales the directive requires.

Security has become a board-level responsibility

Ransomware, phishing, credential theft, cloud incidents: the threats reach companies of every size, and the regulatory picture — starting with the NIS2 directive, in force in Italy since 16 October 2024 with ACN as the competent authority — asks organisations for a structured approach to risk, incidents and suppliers.

Xion IT Group takes security from the technical plane to the organisational one: assessment, measures, monitoring, procedures and training, proportionate to your situation. It is the natural evolution of our long-standing IT security service, strengthened for today’s regulatory demands.

The services

The entry package: Xion Cyber & NIS2 Check

A compact starting route: NIS2 pre-assessment, a review of network, endpoints, cloud, backup and email, a prioritised plan with the recommended technical measures, a training proposal and a report for management. Within a few weeks you know where you are exposed and what to do first.

The platform: GAPOFF

NIS2 obligations — measures, incidents, suppliers — have to be documented and maintained over time. That is why Xion built GAPOFF (www.gapoff.it): the compliance operations platform that turns NIS2, GDPR, DORA and ISO 27001 into tracked workflows, ready for inspection at any point.

From the check to a continuous watch

The assessment is the photograph; real security is the film. With support contracts and XION MSP monitoring, the measures stay current, the backups stay verified and incidents get handled — 365 days a year.

NIS2: establishing quickly whether it applies to you

The question every company asks is: “does this apply to me?”. The directive identifies essential and important entities across a list of sectors (energy, transport, health, digital infrastructure, critical manufacturing, waste management, food, space and others) above certain size thresholds. But the real perimeter is wider than it looks, for two reasons: many companies are in scope without knowing it, and — more importantly — anyone supplying an in-scope organisation is drawn in indirectly, because large customers are required to verify the security of their supply chain. In practice, security questionnaires reach suppliers well before direct obligations do. A pre-assessment of a few hours establishes where you stand and what is genuinely needed.

The measures that matter, in the right order

Security is not a shopping list to be bought all at once: it is a sequence of priorities. The order in which we work, judged by risk reduced against effort, is almost always this:

  1. Multi-factor authentication on email, remote access and critical systems — it stops most attacks based on stolen credentials;
  2. Off-site, isolated and tested backup — the safety net that turns a disaster into an inconvenience;
  3. Systematic updates — the overwhelming majority of attacks exploit flaws fixed months earlier;
  4. Modern endpoint protection (EDR) and email filtering;
  5. Network segmentation and access control on least privilege;
  6. Staff training — the human link is the first target;
  7. An incident response plan — because “what do we do if it happens” has to be decided beforehand, not during.

What happens when the incident arrives

Prepared companies are not the ones that never get hit — they are the ones that know what to do when it happens. NIS2 imposes tight notification timescales (early warning within 24 hours, notification within 72), which makes improvisation impossible. Our incident response work prepares the company to detect the incident, contain it, document it and notify it within the deadlines, with roles, contacts and procedures defined in advance. It is the difference between orderly handling and the panic that multiplies the damage.

Three pages on what comes before and after: vulnerability assessment for cataloguing known weaknesses, incident response for the correct order of the first few hours, and what to do after a data breach for the obligations that follow.

Frequently asked questions

Why should a smaller company carry out a cybersecurity assessment?

To identify vulnerabilities, weak access, inadequate backups, unpatched systems and organisational gaps before they become incidents. It is the security investment with the best cost-benefit ratio - the work then goes where it is genuinely needed.

What are the minimum measures recommended for a company?

Verified off-site backups, multi-factor authentication, modern endpoint protection (EDR), systematic patch management, a properly configured firewall, anti-phishing training, password management and an incident response plan.

Does NIS2 apply to my company?

If you operate in one of the sectors listed in the directive's annexes and exceed the size thresholds, yes. But NIS2 also arrives indirectly - organisations in scope have to identify their significant suppliers and ask them for security assurances. In practice, security questionnaires reach suppliers long before direct obligations do. Our pre-assessment establishes your position quickly.

What does the NIS2 readiness route cover?

Establishing scope, a gap analysis against the measures required by ACN (Italy's national cybersecurity agency), a prioritised compliance plan, implementing the technical measures (access, backup, monitoring, segmentation), incident handling procedures with the notification timescales, supply chain management and training.

Do you also offer continuous monitoring?

Yes - with Xion managed services security is not a one-off project but a continuous watch: monitoring, updates, periodic backup verification and reports for management.

Does NIS2 actually apply to you?

Many companies are caught indirectly, through a client or a supplier. It is worth establishing that before a deadline rather than after one.