Cybersecurity und Resilienz

← Implement regulatory requirements securely

Cybersecurity & Resilience

Structure cybersecurity requirements so that responsibility, protection measures and operations fit together.

NIS2, Cyber Resilience Act (CRA), DORA and KRITIS address different starting points: organisations, digital products, financial companies and critical infrastructure. Together they require resilient risk management. The sensible way to start is therefore not a collection of individual controls, but rather a clear impact assessment with legal advice as well as an implementable plan for governance, supply chain, incident response and evidence.

Relationship to services and technologies

Cybersecurity und Resilienz

This page classifies regulatory security requirements and evidence. For the selection and implementation of specific security services in the Microsoft stack, the entry leads to the solution IT Security & Compliance.

Background

In many companies, security measures grow historically: a new endpoint product, a process for suppliers, an emergency plan. It often remains unclear to management and IT which risk is being addressed, who decides and which evidence is available in the event of an emergency or to auditors. Regulatory requirements make these gaps visible, but do not replace prioritization.

Technical context

IT-Security-Spezialistin überwacht Systeme in einem Rechenzentrum.

NIS2/BSIG concerns the cybersecurity of certain institutions in Germany. DORA has been applicable to the financial sector since January 17, 2025 and concerns digital operational resilience and ICT third-party risks. KRITIS Umbrella Act has also applied to the physical and organisational resilience of critical systems since March 17, 2026; it must be separated from digital protection according to BSIG/NIS2. The CRA On the other hand, it is aimed at manufacturers and other economic actors for products with digital elements.

For product obligations, the page leads Cyber Resilience Act further. The NIS2 implementation logic explained Implement NIS2 in practice; DORA, KRITIS and standards border DORA, KRITIS and Standards from.

What companies need to clarify specifically

  • Which companies, services, products and supply relationships are relevant – technically and legally.
  • Which decision-making and escalation paths apply to management, IT and information security.
  • Which risks from identities, endpoints, cloud, data, vulnerabilities and service providers are prioritised.
  • How incidents are recognized, evaluated, communicated and followed up.
  • Which documents, tests and operating data clearly demonstrate the implementation.

Which case leads where?

Abstrakte Illustration: Audit-Checkliste und Shield in Blau.
Organisation or Important Service

Relevant in-depth topic: Implement NIS2 in practice

Financial sector or third-party ICT risks

Relevant in-depth topic: DORA, KRITIS and other reference framework

Critical attachment and physical/organisational resilience

Relevant in-depth topic: DORA, KRITIS and other reference framework

Digital product or software component

Relevant in-depth topic: Implement the Cyber Resilience Act in practice

From requirements to implementation

Risk management

Risk: unprioritized gaps
Organisational measure: Risk and measures process
Technical implementation: Security foundation for identities, devices and services
Possible evidence: Risk register, Roadmap

Supply chain

Risk: unknown third party risks
Organisational measure: Supplier assessment and responsibilities
Technical implementation: Access separation, monitoring, secure handovers
Possible evidence: Reviews, contracts, protocols

Incident response

Risk: delayed reaction
Organisational measure: Roles, reporting channels, exercises
Technical implementation: Detection, alerting, recovery
Possible evidence: Playbooks, practice and event logs

Evidence capability

Risk: unprovable controls
Organisational measure: Documentation cycle
Technical implementation: Configuration and operating data
Possible evidence: Approvals, Reports, Review Protocols

Working with ADIUMENTO

Cybersecurity und Resilienz

Within the confirmed service areas, ADIUMENTO supports the analysis of existing security controls, prioritised action planning and their technical operation. Further information is available from IT Security & Compliance and IT Security & Compliance.

Typical Results

  • coordinated overview of risks and measures;
  • Target image with responsibilities and implementation stages;
  • documented technical and organisational control points;
  • Incident response and evidence structure as a working basis.

Limitations and dependencies

IT-Security-Spezialistin überwacht Systeme in einem Rechenzentrum.

ADIUMENTO does not provide legal advice and does not establish any binding impact or compliance. Legal advice, data protection officers, auditors or certification bodies are involved in their respective assessment. The scope and effectiveness of technical measures also depend on architecture, contractual partners and ongoing operations.

Orientation

Frequently asked questions

IS NIS2 the same as KRITIS?

No. There are overlaps in the protection of important services, but the legal basis, scope and specific obligations must be examined separately.

Where does a pragmatic start begin?

With a common picture of business risks, relevant services, responsibilities and the current security level. From this, measures can be prioritised in a comprehensible manner.

Next sensible step

Abstrakte Illustration: Threat Detection und Schutzschild in Blau.

Map out relevant services, risks and existing controls in an initial assessment. The topic overview leads from there Implement regulatory requirements securely to the appropriate in-depth topic.