Validation – datensicherheit.de Informationen zu Datensicherheit und Datenschutz https://www.datensicherheit.de Datensicherheit und Datenschutz im Überblick Thu, 06 Aug 2026 10:06:38 +0000 de hourly 1 NIS-2 Compliance: Proven When It Matters Most https://www.datensicherheit.de/nis-2-compliance-proven-crisis https://www.datensicherheit.de/nis-2-compliance-proven-crisis#respond Thu, 06 Aug 2026 10:06:37 +0000 https://www.datensicherheit.de/?p=56136 In the context of NIS-2 compliance, organizations must determine whether their emergency procedures will remain effective if email, identity services, and collaboration platforms all fail simultaneously.

[datensicherheit.de, 08/06/2026] In his latest statement, Benjamin Schilz, CEO of Wire, explains why NIS-2 compliance will only be proven in a crisis and what role secure communication channels play in enabling organizations to act effectively in this context. With the NIS-2 implementation deadline now past, it will become clear just how resilient these preparations actually are. This raises the question of whether emergency procedures will still function if email, identity services, and collaboration platforms all go down at the same time. He emphasizes the importance of secure communication as part of an organization’s cyber resilience.

wire-benjamin-schilz

Benjamin Schilz, CEO of wire, © wire

Benjamin Schilz notes critically that while many companies have established rules, they cannot always ensure that these are actually followed in day-to-day operations

Under review: The practicality of emergency planning in the NIS-2 context

“Many companies have now largely completed the formal implementation of NIS-2. Responsible parties have been designated, contact information has been submitted to the BSI, and internal projects have been officially concluded” says Schilz. After months of checklists, legal opinions, and impact assessments, however, the temptation is great to now remove this topic from the immediate focus.

“But this is exactly where the hard part begins!” That’s because NIS-2 doesn’t evaluate companies based on how complete their documentation is. What matters is whether they can detect a security incident, assess it within tight deadlines, and act in a controlled manner even under pressure.

For significant incidents, the directive requires an initial alert within 24 hours and a more detailed report within 72 hours. “This only works if responsibilities, reporting procedures, and communication channels have been clarified and sufficiently established in advance!” emphasizes Schilz..

Beyond the Audit: Preparing for Real-World Cyber Incidents

On paper, many organizations appear well-prepared. Ideally, those responsible know exactly who takes action, when decisions must be made, and which communication channels should be used. In reality, however, a real cyberattack rarely follows the structured steps of an audit. “If the email system is compromised, teams switch to messaging apps. If an external consultant cannot access the internal platform, they receive files via a link set up at short notice. If management needs to make a quick decision, a new chat group is created on personal devices.”

But this is precisely where the real gap becomes apparent: “In a survey commissioned by Wire, 62 percent of the IT, security, and compliance managers surveyed considered themselves ‘well’ or ‘very well’ prepared for regulatory requirements.”

At the same time, however, 48 percent reported sharing sensitive information through inappropriate channels at least occasionally. For 61 percent, access to shared files remained active longer than intended. “So many companies have established rules and systems. But they can’t always ensure that these are actually followed in day-to-day work.”

Communication as an Essential Criterion for Cyber Resilience

Companies have rightly invested in attack detection, access protection, and backups. But even good technical safeguards cannot prevent every attack. Ultimately, what matters is whether people can continue to work together securely.

Schilz points out: “A crisis management team needs a trusted space where decisions can be prepared, information evaluated, and tasks assigned! Senior management must remain reachable. ‘IT,’ ‘Legal,’ ‘Communications,’ and external specialists must be able to collaborate without relying on an infrastructure that may have been compromised.”

He warns: “Without this capability, decisions are delayed. It becomes more difficult to verify information, and sensitive content ends up on channels that can no longer be centrally controlled.”

“Shadow IT” is an indication of discrepancies between security policies and workflows

Many companies responded to insecure communication channels with new policies and additional training. “That’s understandable, but it doesn’t solve the underlying problem” Schilz says.

Employees often resorted to private messaging apps, personal email accounts, or freely available file-sharing services when official solutions made their work more difficult. This applies above all to collaboration with external parties, mobile teams, and situations under high time pressure. “A system that is perceived as too complicated during normal workdays will not suddenly become the norm during a crisis. This also applies to emergency channels that, while documented, have never been tested in practice.”

So-called „Shadow IT“ is therefore not always a sign of a lack of awareness—it may indicate that security requirements and workflows are not aligned.

NIS-2 requires a controlled response even when trusted systems fail

“The crucial real-world test begins when familiar systems are no longer available or trustworthy.” Companies should therefore assess how they can remain operational if email, central identity services, and their usual collaboration platform all fail simultaneously.

Schilz remarks: “How does the crisis management team convene? How are external experts brought in? How can identities be verified, information protected, and decisions documented? And can all of this be achieved without employees resorting to private channels?”

In conclusion, he summarizes: “Those who can answer these questions convincingly have achieved more than just formal NIS-2 compliance. Those who merely point to registration, policies, and approved tools have only completed the easy part. The key question is whether the organization can still act in a controlled manner even when its familiar systems are no longer available.”

Important to know:

  • NIS-2 requires demonstrated resilience rather than mere documentation: What matters most is how quickly companies can detect, assess, and manage security incidents in a controlled manner.
  • Operational implementation determines success: Preparation is key. Clear responsibilities, established reporting channels, and well-rehearsed procedures provide security when time pressure and uncertainty increase.
  • Secure communication forms the foundation of crisis resilience: Crisis response teams, management, IT, legal departments, and external partners need reliable and redundant channels for collaboration and decision-making.
  • Shadow IT provides valuable insights into opportunities for improvement: When teams resort to alternative communication and collaboration channels, it becomes clear where security requirements and workflows can be better aligned.
  • The practical validation of NIS2 starts with realistic failure scenarios: Companies strengthen their resilience by regularly testing crisis communication, identity verification, and decision-making processes even under challenging conditions.

More information on this topic:

wire
Sichere Kommunikation aus dem Herzen Berlins / Wir beseitigen die Hürden zwischen produktiver Zusammenarbeit, die Nutzer wünschen, und dem Datenschutz, der Privatsphäre und Compliance, die Unternehmen benötigen und liefern den branchenführenden, sicheren kollaborativen Arbeitsraum auf Enterprise-Niveau.

wire, Hauke Gierow, 09.02.204
Wire ernennt Benjamin Schilz als CEO / Neuer CEO wird die internationale Expansion von Wire vorantreiben

wire, 2026
The State of Secure Collaboration 2026 – Vertrauen ist keine Kontrolle

datensicherheit.de, 31.07.2026
NIS-2-Registrierungslücke als Symptom für ein größeres Problem / Die vielen noch ausstehenden NIS-2-Registrierungen sind laut ein Symptom für ein tieferliegendes Problem: „Cybersicherheit wird vielerorts noch immer nicht genug Priorität eingeräumt!“

datensicherheit.de, 02.07.2026
Die eigentliche Herausforderung beginnt erst jetzt: NIS-2-Registrierung genügt nicht / Nach Beobachtung von Axians sind viele Unternehmen trotz Registrierung nicht in der Lage, die regulatorischen Anforderungen im Ernstfall zu erfüllen

datensicherheit.de, 11.01.2026
KMU-Fitness für NIS-2: Universität Paderborn bietet Online-Tool und Lernplattform zur Stärkung der Cybersicherheit / NIS-2 als die überarbeitete EU-Richtlinie von 2022 betrifft nun ca. 30.000 Unternehmen aus 18 Sektoren – von Gesundheit über Transport bis Telekommunikation

]]>
https://www.datensicherheit.de/nis-2-compliance-proven-crisis/feed 0