Skip to content

Topic

NIS2

All articles on NIS2.

Diagram of the relationship between the CER directive and NIS2 for critical entities

Regulations

CER Directive: Resilience of Critical Entities Beyond NIS2

NIS2 protects the digital, the CER directive protects the physical. They are two sides of the same European design for critical infrastructure, and NIS2 entities often fall under the CER too.

3 min read
Connected medical devices in a hospital environment monitored for security

Cybersecurity

OT Cybersecurity in Healthcare: Connected Medical Devices, Hospitals and NIS2

Hospitals are OT environments in their own right: thousands of connected medical devices, often unmanageable with traditional IT tools. How to secure the IoMT fleet under NIS2.

3 min read
Port terminal with automated cranes and connected control systems

Cybersecurity

Port and Maritime Cybersecurity: Terminals, Intermodal Logistics and Onboard Systems

Ports and ships are complex, under-protected OT ecosystems: automated cranes, onboard systems, terminals and intermodal logistics. A map of risks and obligations for a critical sector that is often overlooked.

3 min read
Audit document with technical evidence and OT system logs on screen

Compliance

How to Prove NIS2 Compliance in an Audit: The Technical Evidence That Really Counts

NIS2 is not proven with policies: it is proven with technical evidence. What auditors look for in an OT audit, how to prepare evidence before they arrive, and the role of continuous monitoring as documentary proof.

6 min read
NIS2 notification timeline diagram showing the 24-hour and 72-hour windows, evidence documents and CSIRT-IT contacts

Cybersecurity

OT incident notification under NIS2: obligations, timelines and what to have ready before it happens

NIS2 sets tight deadlines for notifying significant incidents: 24 hours for the early warning, 72 hours for the detailed notification. In OT, being ready to meet them takes preparation that starts long before the incident.

6 min read
NIS2 compliance checklist against an industrial backdrop with control equipment

Compliance

NIS2 for a Manufacturing SME: a Practical Checklist Without Getting Lost in Bureaucracy

NIS2 is not just for large companies. Manufacturing SMEs within scope have concrete obligations: OT asset inventory, vulnerability management, detection, incident notification. A practical checklist.

5 min read
Railway network architecture with SCADA and signalling systems

Cybersecurity

Railway Cybersecurity: Specific Challenges and a Regulatory Approach

Railway networks are becoming more connected and more exposed. An analysis of systems at risk, the regulatory framework and defence strategies for an often overlooked critical infrastructure.

3 min read
Water treatment plant with SCADA systems and field IoT sensors

Cybersecurity

Cybersecurity in Water Networks: The Water/Wastewater Sector as a Forgotten Critical Infrastructure

Water and wastewater treatment plants are critical infrastructures with often obsolete OT systems and exposed remote connections. A sector that industrial cybersecurity still struggles to reach.

3 min read
Stylized map of ransomware attacks focused on industrial plants and OT assets

Cybersecurity

Ransomware landscape, summer 2025: manufacturing in the crosshairs

In spring and summer 2025 ransomware mostly hit manufacturing. Data, active groups and what it means for industrial OT environments.

2 min read
Control panel of an industrial plant showing NIS2 compliance indicators and an OT asset map

Regulations

NIS2 Is Here: Now What? An Operational Guide to Your Next Steps

The NIS2 directive has been transposed: what matters now is what to do in practice. From entity classification to OT asset visibility, an operational checklist.

2 min read
MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna
© 2026 MON5 · All rights reserved