There is a moment familiar to anyone who has rolled out regulation in a large organisation: the audit is passed, the binder of documentation sits on the shelf, and yet no one can honestly answer the question “if someone attacked us today, would we be ready?”. This is the gap between formal compliance and real resilience — and it is precisely what the NIS2 directive addresses.
NIS2 is sometimes read as just another set of requirements to tick off. That is a costly misunderstanding, especially in the energy sector, where the consequence of a mistake is not a data breach but a risk to energy supply. In this article we show why compliance “on paper” is not enough and how to move to the approach the regulation actually expects.
Why does compliance “on paper” give a false sense of security?
A document confirms that something exists — a policy, a procedure, an assigned role. It does not say whether it works, whether it is up to date, or whether anyone will act on it during a real incident. An organisation can hold a complete set of documentation and still not know which of its systems are the most exposed.
Formal compliance is necessary, but it gets confused with the goal. The goal is resilience — the ability to anticipate, detect, contain and recover from an incident. Documentation is at best a trace that someone thought about it, not proof that it will work.
What does the risk-based approach required by NIS2 involve?
NIS2 deliberately refrains from imposing one rigid list of safeguards identical for everyone. Instead, it requires that the scope and intensity of measures follow from the risk specific to the given organisation and the services it provides. This is a risk-based approach grounded in the principle of proportionality.
In practice this means a repeatable cycle:
- identification — what we protect, and from what,
- assessment — how large the impact and likelihood of a given scenario is,
- prioritisation — where to allocate limited resources first,
- action and review — implementing measures and regularly verifying that risk has actually fallen.
This is not a project with a closing date. It is a way of managing that is meant to last.
How does a compliance audit differ from a real risk assessment?
The two are often confused, although they answer entirely different questions:
| Aspect | Compliance audit | Risk assessment |
|---|---|---|
| Question | Do we meet the requirement? | What can actually go wrong? |
| Reference point | List / standard | Threats and impact on the organisation |
| Output | ”Meets / does not meet” state | Priorities and investment decisions |
| Nature | Snapshot in time | Continuous process |
The audit tells you where you stand against requirements. The risk assessment tells you what to do first and why. A good security programme needs both, but it is risk, not the checklist, that should set the order of action.
How do you set priorities when not everything can be secured at once?
No organisation — including a power utility — will close every gap simultaneously. The art lies in a conscious choice of order. Three questions asked of every identified risk help:
- How large would the impact be if this scenario materialised? In energy, the measure is the effect on supply continuity and process safety, not just data loss.
- How likely is it to occur given current safeguards?
- How much does it cost to reduce, relative to the risk reduction gained?
Risks with high impact and high likelihood that can be reduced at reasonable cost go to the top of the list. This approach guards against two extremes: scattering the budget across minor gaps, and paralysis in the face of the sheer scale of the task.
Why must risk be measured in process terms in energy?
In a typical IT organisation the worst case is a leak or encryption of data. In energy the stakes are the physical process — generating and delivering energy. That is why a risk assessment must cover not only office systems but, above all, the OT environment and its boundaries with IT.
The consequence is practical: the same incident (e.g. a compromised workstation) carries entirely different weight if that workstation is a path to control systems. Risk-based in energy therefore means looking at the whole chain of potential impact, down to the process layer — and that requires understanding the specifics of OT, not just classic information security.
How do you sustain resilience over time, not just on audit day?
The most common mistake is treating compliance as an event: an intensive project, a certificate, done. But risk does not stop after the audit — new vulnerabilities appear, infrastructure changes, attacker activity grows. Resilience is sustained only through continuity:
- ongoing monitoring and detection within a SOC,
- regular risk reviews and security testing,
- updating response plans as the environment changes,
- recurring assessment of whether the chosen priorities still hold.
This is why more and more organisations opt for continuous oversight of their security programme, for example in a vCISO model, instead of treating compliance as a one-off sprint.
What is the board’s role in a risk-based model?
NIS2 explicitly moves responsibility up to board level — it is the board that approves and oversees risk-management measures. In a risk-based model this means a concrete management decision: the board accepts the level of risk the organisation consciously does not close at once, and is accountable for ensuring the programme is funded and genuinely carried out.
This is a healthy alignment of roles. Security stops being “an IT department matter” and becomes part of running the organisation — which, in critical-infrastructure sectors, is less a good practice than a necessity. More on this dimension in the article on the personal responsibility of the board.
Related concepts
Learn more
- How to conduct a KSC/NIS2 readiness audit — a guide for CISOs
- KSC/NIS2 and the personal responsibility of the board
- NSC Act amendment (NIS2) 2026 — deadlines and obligations
Explore our services
- vCISO — continuous oversight of the risk-management programme
- ISA/IEC 62443 security audit — risk assessment in the OT environment
- SOC 24/7 — continuous detection and response
- NIS2 training for boards — informed risk acceptance at board level
NIS2 is not an exam you pass once. It is a framework that must be filled with substance — and that substance is real, continuous risk management tailored to what the organisation actually has at stake. In the energy sector, the difference between paper and resilience is measured in the security of supply, which is why it is worth getting it right from the start.
