CCI Series | Preparing your organization for NIS2 with SG2CI. 6 steps in 6 months

CCI Series | Preparing your organization for NIS2 with SG2CI. 6 steps in 6 months

CCI Series | Preparing your organization for NIS2 with SG2CI. 6 steps in 6 months 6912 3456 Centro de Ciberseguridad Industrial

Many organizations still wonder where to start to prepare for NIS2. The good news is that there is no need to tackle everything at the same time. As with any transformation process, it is best to move step by step, first building the foundations on which the rest of the capabilities will progress.

During the next six weeks, we will publish a series of posts where we will develop a practical six-step roadmap in six months to help industrial organizations build the capabilities that NIS2 demands.

Each week we will delve into one of these 6 steps, linking them to the SG2CI domains and the CCI Suite platforms that will facilitate their implementation.

Week Capability SG2CI Platform
1 Governance D1-D2
2 Architecture and critical assets D3-D4 RECIN
3 Cyber incidents D5-D7 ESCIM
4 Supply chain D8-D10 Catalog
5 Maturity D11-D12 MACIN
6 Transformation program All CCI Suite

 

Month 1. Who really governs industrial cybersecurity? 

Questions you should ask yourself:

  • Does Management know and accept the risk they are assuming?
  • Who can accept a risk? Who can only recommend?

  • Do we have clearly defined responsibilities for the Board, CISO, CIO, plant managers, and suppliers?

  • Is there a specific industrial cybersecurity strategy?

In this first month, you should focus on implementing Pillar 1 “Govern” of the SG2CI, especially Domains D1 (Strategy and Policy) and D2 (Governance, leadership, and accountability), establishing a governance model that will subsequently support the rest of the capabilities.

 

Month 2. Do we really know what we must protect?

It is impossible to protect what is not understood, which is why you should ask yourself:

  • What are our truly critical industrial processes?

  • What assets support those processes?

  • Where does each industrial zone begin and end?

  • What channels or conduits exist between zones to communicate?

  • Does our architecture meet cybersecurity criteria or has it evolved due to operational needs?

This is where the RECIN platform comes into play, which will allow you to define an architecture for each critical industrial process, analyze it by zones and conduits, evaluate security requirements, and build a technical plan aligned with IEC 62443.

In this second month, work with Pillar 2 “Identify and Design”, through Domains D3 (Risk assessment and industrial context) and D4 (Cybersecurity by design and development).

Month 3. Are we prepared to survive a cyber incident?

Many organizations know how to protect themselves, but very few know how long they will hold out, some key questions:

  • What would happen if we lose the engineering station?

  • What if ransomware affects the SCADA?

  • What capabilities do we have to detect an attack?

  • Who decides during a crisis?

  • How long would it really take us to recover operations?

To answer this question, the ESCIM platform will help you evaluate high-impact cyber incident scenarios, analyze detection, response, and recovery capabilities, and prioritize those improvements that will truly increase the organization’s resilience.

During this month, work on Pillar 3 “Protect, Detect, and Respond”, especially Domains D5, D6, and D7, turning technical controls into operational capability.

Month 4. Do we trust our suppliers too much?

Today, a large part of the risk is no longer inside the plant; it is in the supply chain, ask yourself:

  • Which suppliers could stop our production?

  • How do we evaluate their cybersecurity capabilities?

  • What critical dependencies have we generated?

  • Could we replace a critical supplier?

  • How do we verify that our integrators apply good practices?

The CCI Catalog allows you to evaluate both the capabilities of industrial suppliers and identify specialized industrial cybersecurity solutions.

This month, develop Pillar 4 “Collaborate”, especially Domains D8 (Governance and trust in the supply chain), D9 (Supplier capability and performance management), and D10 (Collaboration with public and private organizations).

Month 5. Where are we really?

After analyzing governance, architecture, incidents, and suppliers, it is time to measure. Some important questions:

  • What is our real level of maturity?

  • In which capabilities are we furthest behind?

  • Which actions will have the greatest impact?

  • What indicators will we show to Management?

In this month, we should work with MACIN to objectively evaluate the organization’s maturity and build a prioritized roadmap for continuous improvement. Mainly employ Pillar 5 “Resilience and Improvement”, especially Domains D11 (Operational resilience and continuity) and D12 (Evaluation, maturity, and continuous improvement).

Month 6. How do we turn all of this into a transformation program?

The last month consists of putting all the pieces together. It is time to build a multi-year industrial cybersecurity program. We can base this on these final questions:

  • What risks will Management accept?

  • What investments does the organization need?

  • Which projects will we prioritize?

  • Which indicators will we review periodically?

  • How will we demonstrate continuous improvement for NIS2?

Next week we will start with the first step, the governance of industrial cybersecurity. Because before deploying controls, monitoring networks, or responding to incidents, an organization must answer a fundamental question: who is responsible for deciding what risks it is willing to accept?

Access to the SG2CI publication

José Valiente

CCI Director