As a Project or Program Manager, you are used to managing a clearly defined scope, budget and schedule. Your goal is to deliver a specific product or service. Meanwhile, a “KSC/NIS2 project” lands on your desk. - a task that at first glance appears to be a vague legal requirement with no clear framework. It’s a trap. KSC/NIS2 implementation is not a small IT project that can be assigned to a single administrator.
It’s a complex transformation program that touches almost every department in the organization: from management, legal, purchasing, HR to IT and manufacturing (OT). It is you, as PM, who faces the challenge of translating the strategic “roadmap” from the CISO into a concrete timeline, resource allocation and risk register. The success or failure of the entire initiative depends on your ability to manage this complexity.
Shortcuts
- Why is the implementation of KSC/NIS2 a transformational program and not a simple IT project?
- What are the biggest project challenges in implementing KSC/NIS2?
- Who are the key stakeholders (stakeholder) in this program?
- How to define the scope (scope) and key milestones of the program?
- Which project risks (project risks) should be entered into the register first?
- How to manage the “Documentation Implementation (DMS)” stream?
- How will KSC/NIS2 affect all the other IT projects you manage?
- What role does an integration partner play in this program from the PM’s perspective?
- KSC/NIS2 Program Map (WBS): START-CORE-RESILIENCE model for PM.
Why is the implementation of KSC/NIS2 a transformational program and not a simple IT project?
An IT project usually has a single, clearly defined objective, such as “implementing system X.” The KSC/NIS2 program is a collection of multiple, interrelated projects that must be implemented in parallel to achieve a single strategic goal: business resilience.
As PM, you will manage at least five parallel work streams. The first is the GRC stream, which is the creation of all documentation (ISMS) . The second is the IT Technology stream, which is the implementation of systems like SIEM or EDR . The third is the OT Technology stream, or securing production . The fourth is Supply Chain, or auditing and renegotiating contracts with suppliers . The fifth is HR/Culture, or implementing training and awareness program.
Neither of these streams is an “IT project.” It’s a program that fundamentally changes the way the company operates, and it’s sponsored by management itself.
📚 Read the complete guide: Ransomware: Ransomware - czym jest, jak się chronić, co robić po ataku
What are the biggest project challenges in implementing KSC/NIS2?
As an experienced PM, you must immediately identify the key challenges. In the case of KSC/NIS2, these are particularly acute. First, time pressure. This is not a project where you can negotiate a deadline. Deadline is imposed by law and is extremely short . Every day of delay is a real legal risk.
Second, the complexity of the scope. As described above, scope is gigantic and touches many areas. Your challenge will be to control the “scope creep” and ensure that all streams move forward in a coordinated manner.
Third, scarcity of resources. This is probably your biggest challenge. Implementing KSC/NIS2 requires very niche, specialized expertise: GRC experts (who know the standards), security engineers (SIEM implementations), pentesters, and especially OT security experts. It is almost certain that you don’t have all these people on your internal team.
Who are the key stakeholders (stakeholder) in this program?
It is a mistake to think that your only stakeholder is the CTO or CISO. KSC/NIS2 takes this program to a whole other level. Your stakeholder map becomes very complex and you need to actively manage it.
Your absolute key Sponsor is the Board of Directors (CEO, CFO). They are the ones with personal responsibility and they are the ones holding the budget. Your reports and status meetings must be directed to them and must be presented in the language of business risk, not technical jargon.
Key substantive stakeholders are the CISO (defines GRC requirements), CTO/CIO (provides IT resources), Head of Production (key to OT implementations) and Head of Procurement (key to SCRM project ). Without their active involvement and cooperation, the program will stall.
How to define the scope (scope) and key milestones of the program?
Trying to define the scope of KSC/NIS2 from scratch is impossible. Fortunately, the structure of this program is already defined by a logical implementation model such as START-CORE-RESILIENCE. As a PM, you should use this model as your overarching work breakdown structure (WBS - Work Breakdown Structure).
Your project plan should reflect these three phases as major milestones:
-
Milestone 1: START Phase (Diagnosis). Result (Deliverable): Board-approved “KSC/NIS2 Audit Report” and “Implementation Roadmap” . This is your formal “Project Charter” that defines the detailed scope, budget and schedule of the CORE phase.
-
Milestone 2: CORE (Implementation) Phase. Result: an organization in an “Audit-Ready” state. Deliverables are: implemented ISMS (documentation) , implemented technologies (SIEM, EDR, segmentation) and implemented SCRM process.
-
Milestone 3: RESILIENCE Phase. Result: commissioning. Deliverables include: operational SOC service 24/7 , ongoing programs (training, audits) launched .
Which project risks (project risks) should be entered into the register first?
As a PM, you need to distinguish between cyber risks (which the CISO manages) and project risks (which you manage). Your risk register must focus on what can derail your schedule and budget.
Here are the key design risks for KSC/NIS2:
-
Unavailability of specialized resources: Risk that the in-house team lacks expertise (e.g., in OT security) and that it takes too long to find external experts. Mitigation: Early contracting of an end-to-end partner.
-
Organizational resistance: Risk that key departments (e.g., production, purchasing) will treat the program as an “IT problem” and not make their resources available, blocking work in the OT and SCRM streams. Mitigation: Continuous communication and escalation to the Sponsor (Management).
-
Delays on the supplier side: A risk in the SCRM stream where your suppliers delay responses to questionnaires or contract renegotiations. Mitigation: Prioritize suppliers and start this work stream as early as possible.
-
Unrealistic schedule: Risks imposed by the law . Mitigation: Aggressive prioritization of tasks based on risk audit from START phase.
How to manage the “Documentation Implementation (DMS)” stream?
This is not a simple task of “writing some policies.” This is an organizational change management sub-project. As PM, you need to ensure that the GRC department (internal or external) does not create documents “for the drawer.”
Your job is to ensure that this stream includes workshops with business owners. A Business Continuity Plan (BCP) cannot be created without the active participation of the business, which must define its critical processes and RTO/RPO times.
You also need to plan the tasks involved in implementing and communicating these procedures. And, most importantly, you need to plan testing - such as table-top exercises to test the incident response procedure. The deliverable is not a “document,” but a “tested and implemented procedure.”
How will KSC/NIS2 affect all the other IT projects you manage?
This is a hidden challenge that many PMs forget. KSC/NIS2 is not just one big program. This regulation fundamentally changes the way your company will implement ALL future IT projects.
As a Program Manager, you need to work with the CISO and CTO to update your project management methodology. From now on, every new IT project (e.g., implementing a new CRM system, building a mobile app for a customer) must have security gates built into its life cycle (SDLC).
Your standard project plan must be expanded to include new, mandatory tasks: architecture review for security, application penetration testing before deployment, log integration with SIEM, or vendor verification for SCRM. KSC/NIS2 makes security an integral, non-negligible part of any project scope.
What role does an integration partner play in this program from the PM’s perspective?
Trying to manage such a complex program by relying solely on internal resources and contracting 5-10 different small vendors (one for GRC, another for SIEM, a third for pentesting, a fourth for training) is a logistical nightmare for the Project Manager.
Ideally, from a PM’s perspective, the PM should work with a single, ** end-to-end integrator** that plays a dual role: a PMO (Program Management Office) and a specialized service provider.
As a PMO partner, an integrator (such as nFlo) helps you structure your program, manage work streams, monitor progress and prepare reports for management. As a service provider, nFlo takes on the execution of key “work packages” (work packages) for which you don’t have the resources:
-
GRC services (SZBI delivery).
-
Professional Services (IT/OT implementation).
-
Verification Services (penetration testing).
-
Managed Services (SOC operational acquisition).
For you, as a PM, this means reducing complexity. Instead of managing dozens of dependencies, you manage one key partner to ensure consistency and delivery of results across the program.
KSC/NIS2 Program Map (WBS): START-CORE-RESILIENCE model for PM.
The table below shows how the strategic model translates into specific work streams and deliverables in the implementation program.
| Program Phase | Key Work Stream (Workstream) | Main Deliverables | Verification (Definition of Completion) |
|---|---|---|---|
| 1. START | Diagnosis and Planning | Compliance Audit Report (Gap Analysis), Business Risk Register, Roadmap (Schedule and Budget) | Approval of the Roadmap by the Sponsor (Board of Directors) |
| 2. CORE | GRC (SZBI) | Implemented documentation (Policies, Procedures), Implemented Business Continuity Plans (BCP) | Conduct BCP tests and table-top exercises |
| 2. CORE | Technology (IT/OT) | Implemented SIEM, EDR, MFA, Implemented IT/OT network segmentation | Implementation verification report (e.g., configuration audit, testing) |
| 2. CORE | Supply Chain Management (SCRM) | Implemented supplier evaluation process, Renegotiated contracts with key suppliers | Supplier register with risk assessment; signed contract addenda |
| 3. RESILIENCE | Operations (SOC) | Launched SOC 24/7 monitoring service, Implemented response playbooks (IR) | Confirmation of alert flow and successful test of IR procedure |
| 3. RESILIENCE | Process Maintenance | Launched Continuous Training Program, Launched Continuous SCRM Audit Program | Report on first phishing campaign; Schedule of supplier audits |
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- Backup — Backup, also known as a backup copy or safety copy, is the process of creating…
Learn More
Explore related articles in our knowledge base:
- SZBI and the KSC NIS2 supply chain: How should the CISO build and implement procedures and manage supplier risk?
- KSC NIS2 and cyber insurance: How compliance with the act becomes key to lowering the cost of risk.
- KSC NIS2 and the human firewall: How must a CISO build an ongoing security culture program?
- How to strategically implement KSC NIS2 in 3 steps?
- Key Requirements of NIS2 Directive - Actions, Process, Obligations, Preparations, Implementation Deadline, and Incident Reporting
Explore Our Services
Need cybersecurity support? Check out:
- NIS2 Compliance - NIS2 directive compliance
- NIS2 Readiness Check - NIS2 readiness assessment
- Security Audits - comprehensive security assessment
Related topics
See also:
