You are personally liable
German law (BSIG) makes management personally responsible for approving and overseeing the measures – not delegable to IT.
Since December 2025, NIS2 has been mandatory – and management is personally liable. As an ex-CISO and lawyer, I find out what you really need – and what you can save. Plain language, not jargon.
What this is about
"Cybersecurity? That's IT's job." Wrong: NIS2 obliges management – not the IT department. Four reasons why this belongs on your desk now.
German law (BSIG) makes management personally responsible for approving and overseeing the measures – not delegable to IT.
Up to €10m or 2% of global annual turnover – plus the loss of reputation and trust that really hurts.
Affected clients must secure their supply chain – and demand evidence. Without it, you lose contracts.
Registration, reporting and evidence apply now – not someday. Start only after an incident, and you pay twice.
Free & in 60 seconds
Three short questions give you a first, well-founded assessment – no sign-up, no data stored. Not theory, but a clear direction to work with.
Pick the closest match. NIS2 covers around 18 sectors – from energy and engineering to digital services.
For NIS2, the size of your whole company counts (headcount or turnover / balance sheet).
Multiple selection possible. These activities are often in scope regardless of company size.
Based on your answers, your company probably falls into the highest NIS2 category. That means the strictest duties – and the closest supervision by the BSI. Acting now is not a luxury, it's an obligation.
Based on your answers, your company is probably in scope as an important entity. The duties are real – but with the right approach they are very manageable and affordable. The key: don't buy everything at once, do the right thing first.
Based on your answers you are probably not directly in scope. But beware: affected customers must secure their supply chain and pass the requirements down. Those who are prepared win contracts; those who aren't lose them. And the scoping itself should be documented cleanly.
This assessment is a first orientation and does not replace a legal review of the individual case. The precise classification – including thresholds, special rules and group structures – is something I clarify with you in the scoping analysis.
Services
From the first assessment to a passed audit – individually or as end-to-end support. On request as your interim CISO.
Someone who takes responsibility, not just hands over a report. As your interim CISO I run your information security operationally and strategically – for as long as you need me.
I clarify whether and how you're in scope, and show you in black and white where the real gaps are – with a prioritised roadmap.
The roadmap becomes reality: a lean ISMS to ISO 27001. As a lead auditor I prepare you so the audit isn't a battle of nerves.
NIS2 requires leadership to understand. Interactive training with simulations – incl. a verifiable certificate of participation.
Also: Business Continuity (ISO 22301) · Data protection (GDPR) · AI compliance (EU AI Act)
About me
I'm Nicolas Abel. I combine two perspectives that rarely meet: the legal understanding of what the law really requires – and the operational experience to implement it day to day.
As a lawyer (University of Cologne) I know the regulatory side; as a former CISO at a large energy company, the operational one – including a state KRITIS evidence audit and the IT-Sicherheitskatalog. I put that combination to work for you: no buzzwords, with the clear goal that you end up more secure and better off financially.
Client voices
Nicolas Abel guided us through the state KRITIS evidence audit with great expertise and pragmatism. In no time he established a full ISMS to ISO 27001 and integrated all KRITIS requirements efficiently and precisely.Holger HämelChief Compliance Officer, Deutsche Windtechnik AG
Nicolas was instrumental in implementing the IT-Sicherheitskatalog. Thanks to his sound legal understanding we could work precisely and efficiently. The subsequent audit was a clear success.Roland StracheManager IT Operations & Deputy CISO, OutSmart Deutschland GmbH
Thanks to Nicolas we now have a clearly structured, DEKRA-reviewed curriculum on information security. His ability to convey complex matters clearly is invaluable, especially for career changers.Marvin GatermannManaging Director, Deutsche Akademie für Informationssicherheit GmbH
Contact
Whether a concrete NIS2 question or a first orientation: in a 30-minute call we clarify your situation and the best next step. Not a sales pitch, just plain talk.
Phone
+49 (151) 561 88540Address
Limassoler Straße 37, 53859 Niederkassel, Germany
Send me a short message with your request. I usually reply within one business day.