Aktuelles, Branche - geschrieben von cp am Donnerstag, August 6, 2026 12:06 - noch keine Kommentare
NIS-2 Compliance: Proven When It Matters Most
In the context of NIS-2 compliance, organizations must determine whether their emergency procedures will remain effective if email, identity services, and collaboration platforms all fail simultaneously.
[datensicherheit.de, 08/06/2026] In his latest statement, Benjamin Schilz, CEO of Wire, explains why NIS-2 compliance will only be proven in a crisis and what role secure communication channels play in enabling organizations to act effectively in this context. With the NIS-2 implementation deadline now past, it will become clear just how resilient these preparations actually are. This raises the question of whether emergency procedures will still function if email, identity services, and collaboration platforms all go down at the same time. He emphasizes the importance of secure communication as part of an organization’s cyber resilience.

Benjamin Schilz, CEO of wire, © wire
Benjamin Schilz notes critically that while many companies have established rules, they cannot always ensure that these are actually followed in day-to-day operations
Under review: The practicality of emergency planning in the NIS-2 context
“Many companies have now largely completed the formal implementation of NIS-2. Responsible parties have been designated, contact information has been submitted to the BSI, and internal projects have been officially concluded” says Schilz. After months of checklists, legal opinions, and impact assessments, however, the temptation is great to now remove this topic from the immediate focus.
“But this is exactly where the hard part begins!” That’s because NIS-2 doesn’t evaluate companies based on how complete their documentation is. What matters is whether they can detect a security incident, assess it within tight deadlines, and act in a controlled manner even under pressure.
For significant incidents, the directive requires an initial alert within 24 hours and a more detailed report within 72 hours. “This only works if responsibilities, reporting procedures, and communication channels have been clarified and sufficiently established in advance!” emphasizes Schilz..
Beyond the Audit: Preparing for Real-World Cyber Incidents
On paper, many organizations appear well-prepared. Ideally, those responsible know exactly who takes action, when decisions must be made, and which communication channels should be used. In reality, however, a real cyberattack rarely follows the structured steps of an audit. “If the email system is compromised, teams switch to messaging apps. If an external consultant cannot access the internal platform, they receive files via a link set up at short notice. If management needs to make a quick decision, a new chat group is created on personal devices.”
But this is precisely where the real gap becomes apparent: “In a survey commissioned by Wire, 62 percent of the IT, security, and compliance managers surveyed considered themselves ‘well’ or ‘very well’ prepared for regulatory requirements.”
At the same time, however, 48 percent reported sharing sensitive information through inappropriate channels at least occasionally. For 61 percent, access to shared files remained active longer than intended. “So many companies have established rules and systems. But they can’t always ensure that these are actually followed in day-to-day work.”
Communication as an Essential Criterion for Cyber Resilience
Companies have rightly invested in attack detection, access protection, and backups. But even good technical safeguards cannot prevent every attack. Ultimately, what matters is whether people can continue to work together securely.
Schilz points out: “A crisis management team needs a trusted space where decisions can be prepared, information evaluated, and tasks assigned! Senior management must remain reachable. ‘IT,’ ‘Legal,’ ‘Communications,’ and external specialists must be able to collaborate without relying on an infrastructure that may have been compromised.”
He warns: “Without this capability, decisions are delayed. It becomes more difficult to verify information, and sensitive content ends up on channels that can no longer be centrally controlled.”
“Shadow IT” is an indication of discrepancies between security policies and workflows
Many companies responded to insecure communication channels with new policies and additional training. “That’s understandable, but it doesn’t solve the underlying problem” Schilz says.
Employees often resorted to private messaging apps, personal email accounts, or freely available file-sharing services when official solutions made their work more difficult. This applies above all to collaboration with external parties, mobile teams, and situations under high time pressure. “A system that is perceived as too complicated during normal workdays will not suddenly become the norm during a crisis. This also applies to emergency channels that, while documented, have never been tested in practice.”
So-called „Shadow IT“ is therefore not always a sign of a lack of awareness—it may indicate that security requirements and workflows are not aligned.
NIS-2 requires a controlled response even when trusted systems fail
“The crucial real-world test begins when familiar systems are no longer available or trustworthy.” Companies should therefore assess how they can remain operational if email, central identity services, and their usual collaboration platform all fail simultaneously.
Schilz remarks: “How does the crisis management team convene? How are external experts brought in? How can identities be verified, information protected, and decisions documented? And can all of this be achieved without employees resorting to private channels?”
In conclusion, he summarizes: “Those who can answer these questions convincingly have achieved more than just formal NIS-2 compliance. Those who merely point to registration, policies, and approved tools have only completed the easy part. The key question is whether the organization can still act in a controlled manner even when its familiar systems are no longer available.”
Important to know:
- NIS-2 requires demonstrated resilience rather than mere documentation: What matters most is how quickly companies can detect, assess, and manage security incidents in a controlled manner.
- Operational implementation determines success: Preparation is key. Clear responsibilities, established reporting channels, and well-rehearsed procedures provide security when time pressure and uncertainty increase.
- Secure communication forms the foundation of crisis resilience: Crisis response teams, management, IT, legal departments, and external partners need reliable and redundant channels for collaboration and decision-making.
- Shadow IT provides valuable insights into opportunities for improvement: When teams resort to alternative communication and collaboration channels, it becomes clear where security requirements and workflows can be better aligned.
- The practical validation of NIS2 starts with realistic failure scenarios: Companies strengthen their resilience by regularly testing crisis communication, identity verification, and decision-making processes even under challenging conditions.
More information on this topic:
wire, Hauke Gierow, 09.02.204
Wire ernennt Benjamin Schilz als CEO / Neuer CEO wird die internationale Expansion von Wire vorantreiben
wire, 2026
The State of Secure Collaboration 2026 – Vertrauen ist keine Kontrolle
datensicherheit.de, 31.07.2026
NIS-2-Registrierungslücke als Symptom für ein größeres Problem / Die vielen noch ausstehenden NIS-2-Registrierungen sind laut ein Symptom für ein tieferliegendes Problem: „Cybersicherheit wird vielerorts noch immer nicht genug Priorität eingeräumt!“
datensicherheit.de, 02.07.2026
Die eigentliche Herausforderung beginnt erst jetzt: NIS-2-Registrierung genügt nicht / Nach Beobachtung von Axians sind viele Unternehmen trotz Registrierung nicht in der Lage, die regulatorischen Anforderungen im Ernstfall zu erfüllen
datensicherheit.de, 11.01.2026
KMU-Fitness für NIS-2: Universität Paderborn bietet Online-Tool und Lernplattform zur Stärkung der Cybersicherheit / NIS-2 als die überarbeitete EU-Richtlinie von 2022 betrifft nun ca. 30.000 Unternehmen aus 18 Sektoren – von Gesundheit über Transport bis Telekommunikation
Aktuelles, Experten, Veranstaltungen - Aug. 6, 2026 8:53 - noch keine Kommentare
Reges Interesse am 4. KI-Tag der Wirtschaft des Landes Brandenburg
weitere Beiträge in Experten
- Digitalisierung der Schiene: TÜV-Verband fordert Modernisierung sicherheitsrelevanter Verfahren
- Deutschland im EU-Digitalranking auf Platz 17
- „Archetyp Market“: Nach Abschaltung der Darknet-Handelsplattform nun Anklage gegen mutmaßlichen Betreiber
- Entwicklung zur verlässlichen Geschäftstechnologie: KI-Kennzeichnung gemäß EU AI Act erst der Anfang
- AI Act: Ab 2. August 2026 weitere Regeln in Kraft – indes noch viele offene Fragen
Aktuelles, Branche - Aug. 6, 2026 12:06 - noch keine Kommentare
NIS-2 Compliance: Proven When It Matters Most
weitere Beiträge in Branche
- NIS-2-Compliance beweist sich erst in der Krise
- ElringKlinger modernisiert Identity- und Access-Management mit Omada Identity
- EU AI Act: Aktuelle KI-Vorfälle unterstreichen Notwendigkeit der Regeln
- Kompromittierte Nutzerkonten – Deutschland weltweit auf Platz 10
- Cyberrisiken schneller eindämmen: Qualys erkennt Schwachstellen in Minuten
Aktuelles, A, Experten, Service, Wichtige Adressen - Jan. 13, 2026 1:08 - noch keine Kommentare
Registrierung bei ELEFAND: Krisen- und Katastrophenvorsorge bei Auslandsaufenthalten
weitere Beiträge in Service
- DigiCert-Umfrage: Manuelle Zertifikatsprozesse führen zu Ausfällen, Compliance-Fehlern und hohen Verlusten im Unternehmen
- Threat Hunting: Bedeutung und Wertschätzung steigt
- Umfrage: 71 Prozent der IT-Entscheidungsträger besorgt über Mehrfachnutzung von Passwörtern
- Fast die Hälfte der Unternehmen ohne geeignete Sicherheitsrichtlinien für Remote-Arbeit
- Umfrage: Bedeutung der Konsolidierung von IT-Sicherheitslösungen



Kommentieren