I'm NisPo, the hippo who shoulders the NIS2 paperwork: controls, evidence and audits, without spreadsheets. Leave the weight of compliance to me.

NisPo, the Nispo mascot, at the desk in his office

Let me introduce myself. I’m NisPo, and if you’ve ended up on this blog it’s because, sooner or later, the acronym “NIS2” landed on your desk. Maybe in an email from the legal department, maybe in a passing remark from a consultant. And with it came that familiar feeling: so what do we do now?

Breathe. I’ve got this.

Why a hippo

I know, it’s not the first animal you’d associate with cybersecurity. But trust me, it makes sense.

A hippo stays calm for as long as it can, minds its own business and doesn’t panic. It’s heavy, it’s solid, and when it decides to move, nothing stops it. That’s exactly the attitude you need when facing Italian red tape: no anxiety, no rushing ahead. One step at a time, but with all the weight on your side.

And then there’s the briefcase. I always carry it with me, and that’s where the boring part goes: controls, evidence, documents for the audit. You think about your company; I’ll deal with the paperwork.

What I’m up against

Let’s say it plainly: compliance in Italy seems written specifically to be complicated.

European directives transposed by decrees, decrees that refer to guidelines, guidelines that quote other frameworks. Ten control domains, deadlines, notifications within 24 hours, evidence to keep. For an SME with an IT team of two people — on a good day — it’s a wall.

You already know the result: spreadsheets filled in once and never opened again, consultancy engagements worth tens of thousands of euros and that nagging worry of never really knowing where you stand.

That’s why I exist: to take that wall down, brick by brick, and translate it into plain language. The real kind, not the language of decrees.

My mission

Here’s the point, and it matters to me: compliance doesn’t have to be painful.

Too many companies experience it as a tax — a cost you pay to avoid fines, a formality to file away and forget. I understand why people end up thinking that. But it’s a waste.

Because compliance done well isn’t a burden: it’s an honest snapshot of your company. It tells you where you’re fragile before someone else finds out. It lets you sleep at night. And when a customer, a supplier or a tender asks you “are you NIS2 compliant?”, it lets you answer “yes” with a document in hand, not with a shrug.

For me, that’s the difference between putting up with compliance and using it as a competitive advantage. My job is to take you from the first to the second.

My promise

Three simple things you’ll always get from me:

  • No jargon. If a rule matters to you, I’ll explain it the way I’d explain it to a friend at the bar. If it doesn’t, I won’t even make you read it.
  • No endless questionnaires. I connect to your Microsoft systems read-only and collect the data I can read myself. For the rest I give you templates and a clear list of what’s missing.
  • No fear. I’m not here to list everything you’re doing wrong, but to show you the shortest route to putting it right.

Let’s get started

You’ll find me here often: explaining a deadline, busting a myth, telling you how another company like yours pulled it off. No scaremongering and no fluff.

NIS2 isn’t going away. But it doesn’t have to become your nightmare. What I can promise is that, with me by your side, it will stop being one.

Nice to meet you. Now let’s roll up our sleeves — or rather, our paws.

Nispo automatically checks technical controls on Microsoft 365, Google Workspace, AWS and Google Cloud and organises everything else: ACN requirements, evidence, suppliers and remediation.