NIS2 in practice: where Czech companies most often go wrong
The NIS2 directive widened the group of companies that must demonstrably manage cybersecurity. We summarise the most common mistakes we run into while preparing companies for an audit.
Over recent months, the NIS2 directive has become topic number one for many medium and smaller companies that used to treat cybersecurity only in passing. The scope of obligations is broader than most companies think — and so are the consequences if the preparation is underestimated.
During gap analyses at clients we keep coming back to the same handful of mistakes. Here are the most common ones.
1. The company does not know whether NIS2 even applies to it
The most common mistake does not appear at the documentation stage, but right at the start — the company never verifies whether, and in what regime, the directive affects it. The result tends to be two opposite extremes: either needless panic and over-sized measures, or the reverse — underestimation and no preparation at all. Both cost unnecessary money and time.
The fix is simple: a short analysis of the scope of obligations at the start saves months of extra work.
2. Security is treated as a one-off project
NIS2 compliance often starts well — an audit is carried out, policies are written, processes are set up. The problem is that most companies then consider themselves "done." In reality, managing cybersecurity is an ongoing process: new employees, new systems, and shifting threats all require the documentation and measures to stay current.
The companies that handle this best have a simple review rhythm in place — not a complicated security apparatus, but a regular check that things still hold true.
3. The documentation does not match how operations actually work
The second most common problem: a security policy written from a template that does not match how the company actually works. In a real incident or audit, it then turns out that the document exists but no one follows it.
Functional documentation comes from how the company actually manages access, backups, and incidents — not from a generic template downloaded off the internet.
4. There is no clear responsibility for incidents
NIS2 emphasises the ability to recognise, report, and resolve an incident within defined deadlines. Without clearly assigned responsibility — who assesses the incident, who decides on escalation, who communicates with the regulator — even a smaller problem easily drags past the set deadlines.
How we approach it
Our goal in NIS2 preparation is not to produce as much paperwork as possible, but to find the balance between what the law requires and what makes operational sense. The approach we use has three steps: a gap analysis against the current state, preparation of documentation that matches reality, and a phased remediation plan based on risk and impact.
If you are not sure to what extent NIS2 applies to you, that is the fastest question worth answering first.
