When the platform finds a gap, our specialists help you verify it and close it. Every engagement ends with actions and evidence in the Nispo register, ready for the NIS2 audit.

Platform and services

The gaps the platform highlights define the scope of the work. Results flow back into the register as actions with an owner and a due date: no report left to gather dust in a folder.

One cycle, one register PlatformServices
01 · Platform

The platform spots the gap

  • MFA missing on 3 admin accountsControl
  • Unlisted exposed servicesAsset
  • Backup never testedContinuity
  • Critical supplier without questionnaireSuppliers
02 · Services

Specialists verify it

  • Penetration testingPerimeter
  • External attack surfaceInternet
  • Active DirectoryIdentity
  • Backup and disaster recoveryRecovery
03 · Register

The register tracks the fix

  • Findings as actionsAssigned
  • Owner and due datePer action
  • RetestScheduled
  • Audit evidenceArchived
Featured · Art. 21.2(f) NIS2

Penetration testing

NIS2 requires you to assess how effective your security measures are. A penetration test does that in the most direct way: our specialists try to break in, as an attacker would, and document what works and why.

  • External perimeter, internal network and web applications
  • Active Directory and Entra ID, all the way to domain admin
  • Technical report and executive summary
  • Findings imported into the Nispo register as actions
Penetration test report 5 findings
FindingSeverityIn the register
Admin panel exposed with default credentialsExternal perimeter Critical In remediation · M. Ferri
SMB signing not required on file serversInternal network High Assigned · IT
Service account with Domain Admin privilegesActive Directory High Assigned · IT
TLS 1.0 enabled on the customer portalExternal perimeter Medium Closed · retest passed
User enumeration on the VPNExternal perimeter Medium Scheduled
Nispo services 5 actions with owner and due date

Where to start

You need NIS2 compliance

Start with the platform

NIS2 assessment, gap analysis on the ACN controls and an action plan. Services are added wherever the platform finds a gap.

You already have a security programme

Start with an assessment

Penetration testing, vulnerability assessment or an Active Directory review, even without the platform. Quote-based, on the scope we agree.

Tell us about your scope: we’ll propose the most useful engagement and a quote.