Risk is operational before it is technical
An industrial or commercial company feels a cybersecurity incident as an operational shutdown: it cannot invoice, produce, receive orders, dispatch, consult drawings, pay salaries or access critical documents. That is why the first conversation should be about the business: which processes cannot stop, and for how long?
The technical strategy stems from this answer. It makes no sense to buy tools without knowing which systems are critical, which data needs priority recovery and which teams should decide in the event of an incident.
NIS2: what changes in practice
The NIS2 directive raises the bar on risk management, security measures, governance, incident reporting and accountability. Even companies that are not directly covered may be put under pressure by customers, business groups, insurers and supply chains.
In practice, this means documenting measures, testing recovery, managing suppliers, controlling access, monitoring events and preparing incident response. Cybersecurity is no longer a matter for IT alone and becomes a matter for management.
- Identification of critical assets and dependencies.
- Access policies, MFA and identity management.
- Monitoring, detection and incident response.
- Tested continuity and recovery plans.
- Risk management for suppliers and external services.
Identity: protecting the front door
Many incidents begin with compromised credentials. That is why MFA, password management, account reviews, least privilege and rapid deactivation of access are high-impact measures. The company should know who has access to what, why and until when.
Administrative accounts deserve special attention. They should be separated from day-to-day accounts, protected with strong authentication and monitored. The principle is simple: reduce the attack surface and limit damage if an account is compromised.
EDR, firewall and segmentation
Protection tools remain essential. EDR helps detect suspicious behaviour on endpoints. Firewalls and network rules reduce exposure. Segmentation prevents a problem in one area from easily spreading to servers, backups or industrial systems.
Maturity lies not just in having tools, but in configuring them, monitoring them and responding to alerts. A critical alert with no defined owner is almost the same as having no alert at all.
Immutable backup and recovery testing
Backup is the last line of defence, but it is only worthwhile if it can be recovered. Immutable backups help protect copies against alteration or deletion by ransomware. Even so, immutability without a restore test gives a false sense of security.
The company should define RPO and RTO: how much data it is willing to lose and how long it is willing to be down. It should then test recovery of critical systems under realistic conditions. Testing reveals dependencies that often do not appear in the initial design.
Practical checklist
- Separate backups from production and limit administrative access.
- Enable immutability where applicable.
- Document RPO and RTO per critical system.
- Test restore at a defined frequency.
- Keep evidence of tests for audit and improvement.
Response plan: who decides what
In a real incident, the team should not be discovering responsibilities on the spot. Who isolates systems? Who talks to senior management? Who contacts the supplier? Who communicates with customers? Who decides to recover? Who validates the data? These answers should be in a simple, accessible plan.
The plan should be tested in short exercises. Simulating a ransomware attack, ERP unavailability or loss of email helps identify contact gaps, dependencies and priorities.
30-60-90 day roadmap
In the first 30 days, the company should map assets, critical accounts, backups and main risks. At 60 days, it should strengthen MFA, review privileges, validate EDR/firewall, create a response plan and fix priority vulnerabilities. At 90 days, it should test restore, simulate an incident and finalise documentation.
This roadmap does not replace a full strategy, but it creates traction. Cybersecurity improves through cycles: measure, fix, test and repeat.
Conclusion: resilience is the goal
Modern cybersecurity does not promise zero risk. It promises to reduce probability, limit impact and recover with discipline. For industrial SMEs, the objective is to protect business continuity.
With an integrated approach to identity, endpoint, network, backup and response, the company is better prepared for NIS2 requirements and for the practical reality of incidents.
