Generic filters
FS Logoi
Generic filters

NIS-2: What Industrial Companies Should Learn from DORA Now

With NIS-2, the European Union is tightening requirements for cybersecurity, risk management, and supply chain security.

von | 28.07.26

Robin Schmeisser, Managing Director of Fabasoft Contracts GmbH (Source: Fabasoft)
Robin Schmeisser, Managing Director of Fabasoft Contracts GmbH (Source: Fabasoft)

For industrial companies, this brings new questions to the forefront: Which systems and service providers are essential for production and business operations? Where do critical dependencies exist? And can risks, measures, and responsibilities be fully documented in the event of an audit?

Banks and insurance companies are already familiar with these requirements from the “Digital Operational Resilience Act,” or DORA for short. Since early 2025, this EU regulation has required financial firms to implement comprehensive measures to strengthen their digital resilience. While DORA applies exclusively to the financial sector, NIS-2 extends these obligations to a much wider range of industries.

“Many companies initially view cyber resilience primarily as a technical challenge,” says Robin Schmeisser, Managing Director of Fabasoft Contracts GmbH. “However, experience with DORA shows that the biggest hurdles often lie in transparency, the ability to provide evidence, and organizational implementation.”

Specifically, five lessons can be drawn for companies affected by NIS-2:

1. Security Does Not End at the Corporate Boundary

For a long time, cybersecurity focused primarily on securing a company’s own systems and processes. However, experience from the financial sector shows that risks are increasingly arising outside a company’s own boundaries: According to the Austrian Financial Market Authority (FMA)1, more than 50 percent of the security incidents reported since DORA came into effect originated with a third-party ICT service provider.

For this reason, DORA and NIS-2 place significantly greater emphasis on managing third-party and supply chain risks than previous regulations. For NIS-2 companies, this yields a clear lesson: Their own security strategy must not end at the company’s boundaries. Resilience requires a holistic view of the digital value chain—from cloud and IT service providers to production and automation systems. “Today, a company’s security depends increasingly on the security of its service providers,” Schmeisser emphasizes. “Those who focus solely on their own systems overlook a significant portion of the actual risk.

2. Identifying Critical Dependencies

As part of the DORA implementation, financial institutions had to systematically assess their actual dependence on individual IT service providers. In the process, it became clear that numerous business processes depend on a small number of providers, for which there were often no robust exit strategies or plans.²

Even though NIS-2 does not require explicit exit plans like DORA does, an important lesson can be drawn from this: Organizations should identify critical dependencies early on and explore possible alternatives. Those who understand their digital dependencies can avoid production outages and respond more quickly in the event of a crisis.

“It’s not just a matter of whether a service provider is operating reliably today,” explains Schmeisser. “Companies also need to know what the consequences of an outage would be, how quickly an alternative could be activated, and what contractual or technical hurdles stand in the way of a switch.”

3. Actively Manage Third-Party Service Providers

According to an analysis by the Austrian Financial Market Authority (FMA), third-party ICT risk management posed the greatest challenge for many financial firms in implementing DORA.3 Requirements include, among other things, documentation and reporting obligations, risk assessments, due diligence, the ongoing updating of supplier information, and the amendment of existing contracts. On-site inspections by regulatory authorities revealed incomplete inventories, inadequate functions and processes, unclear responsibilities, and poor data quality. In addition, third-party ICT service providers were often not sufficiently integrated into the processes, and necessary contractual adjustments were lacking.2

“The management of third-party service providers goes far beyond traditional supplier management,” says Schmeisser. “It is an ongoing governance task that requires robust processes and up-to-date data.”

Companies subject to NIS 2 should not underestimate this effort. Today, industrial companies work with a multitude of external IT, cloud, and automation partners. Centralizing all relevant service provider information early on and establishing structured processes for third-party management can significantly prevent future hurdles. AI-powered contract management helps efficiently review contracts for regulatory risks and implement necessary adjustments more quickly.

4. Compliance Must Be Verifiable

Established processes alone are not sufficient to meet regulatory requirements.

“Many financial institutions generally had procedures in place for outsourcing management,” says Schmeisser. “The challenge, however, was being able to demonstrate the actual execution of each individual process step in an audit situation.”

This applied, for example, to risk analyses, criticality assessments, approvals, regular controls, and the reassessment of existing service providers. The necessary information was often scattered across emails, spreadsheets, and various specialized applications. Consequently, it was difficult to trace decisions and process steps seamlessly.

To prepare for NIS-2, it is therefore essential to design governance, risk, and control processes to be transparent and traceable from the very beginning. Digital workflows can automatically manage process steps, clearly assign responsibilities, and document activities in an audit-proof manner. Audit trails and electronic workflow signatures make it possible to verify at any time who performed assessments, made decisions, or granted approvals, and when.

5. NIS-2 Is Not an IT Project

Both NIS-2 and DORA address the responsibilities of senior management and require an organization-wide approach to cyber risks. Experience with DORA shows that digital resilience is a cross-functional discipline: IT, supplier management, risk management, compliance, procurement, business units, and senior management must work closely together.

However, during the first year of DORA implementation, it became apparent that senior management at many financial institutions was not sufficiently involved in the necessary processes. As a result, required measures were often not approved or monitored.2

“Organizations subject to NIS 2 should view implementation as a company-wide governance project,” advises Schmeisser. “If all relevant stakeholders are involved early on, responsibilities are clearly assigned, and senior management is actively engaged, decisions can be made more quickly, measures can be implemented more consistently, and regulatory requirements can be permanently embedded within the company.”

Conclusion

Cyber resilience does not result solely from technical security measures. Transparency regarding ICT service providers, clear lines of responsibility, and fully traceable processes are crucial. Companies subject to NIS 2 should therefore identify their digital dependencies early on, systematically manage service providers, and document governance processes in an audit-proof manner. Those who establish these foundations not only meet regulatory requirements more efficiently but also strengthen the resilience of their production and value chain.

Sources

  1. KPMG Cybersecurity in Österreich 2026
  2. IT-Aufsicht im Finanzsektor: Das erste Jahr DORA – Bafin
  3. DORA – FMA-Aktivitäten – FMA Österreich
(Source: Fabasoft Contracts GmbH)

Bildquelle, falls nicht im Bild oben angegeben:

Jetzt Newsletter abonnieren

Die ganze Welt der Metallurgie, immer in Ihrem Postfach.

Hier anmelden

The Universal “Workhorse” — SECO/WARWICK Secures New CAB Contract in Turkey

The Universal “Workhorse” — SECO/WARWICK Secures New CAB Contract in Turkey

RASA ALÜMİNYUM RADYATÖR SANAYİ A.Ş., a Turkish manufacturer of industrial cooling systems and various types of heat exchangers, has ordered a universal CAB batch furnace with a vacuum purging system from SECO/WARWICK. The solution will increase production capacity, expand the company’s plate-bar heat exchanger offering, and provide a technological foundation for the continued development of its new plant.

mehr lesen

Fachinformationen für Sie