Step 1. Before implementing cybersecurity, governance capability must be built
When an organization begins to prepare for NIS2, the same question is always asked:
What controls should we implement?
It is a logical reaction, but it is not the best starting point. Before talking about segmentation, monitoring, vulnerability management, or multi-factor authentication, there is a much more important question:
Is the organization prepared to make coordinated decisions regarding cybersecurity?
Because NIS2 does not only require the implementation of technical measures. It requires that the organization can demonstrate that it directs, supervises, and continuously improves risk management. In other words, it requires governance. An organization can have excellent protection technologies and still fail in the face of an incident because it is not entirely clear who should decide, who should coordinate actions, or what level of risk the business is willing to assume.
Governance is not administering documentation
One of the most common mistakes consists of associating governance with the elaboration of policies, procedures, or committees. However, governing means something much more practical, getting all the involved areas, management, operations, engineering, maintenance, OT, IT, purchasing, and main suppliers, to work under the same criteria when they must make decisions that affect industrial cybersecurity risk.
When this model does not exist, each department optimizes only its own objective. Production prioritizes availability, maintenance the speed of interventions, IT the security of infrastructures, and purchasing the cost. All are reasonable decisions individually, but they can prove to be incompatible when nobody governs the whole. For this reason, the first step of SG2CI begins by building the structure that will allow all subsequent decisions to be coherent.
Foundations upon which everything is built
Within SG2CI, this first step is materialized through the first two domains of the model.
-
Strategy and Policy, which establishes where the organization wants to move forward and what its principles of action will be.
-
Governance, Leadership, and Accountability, which defines who decides, who coordinates, how capabilities are supervised, and how management is informed.
These domains constitute the nervous system of the organization. Upon them will later rest risk management, the protection of industrial systems, incident detection, and the response to strengthen the operational continuity and resilience of the organization.

Attempting to develop these capabilities without a solid governance model usually leads to duplications, inefficient investments, and difficulties in demonstrating compliance with NIS2.
How to know if this first step is achieved?
At the end of this first phase, the organization should be able to clearly answer questions as simple as who leads industrial cybersecurity, how relevant decisions are made, which bodies participate in them, and how the evolution of the implemented capabilities is supervised.
It is not about having deployed all security measures, but about having built the structure that will allow them to be implemented in an orderly and sustainable manner.
That is precisely the objective of the first month of the proposed itinerary with the help of SG2CI, to create the foundations upon which the rest of the management system can be built.
A final reflection
Building technical capabilities without previously building a governance model is similar to setting up an industrial plant without defining who will direct the operation.
Once finished, the equipment will work, the technologies will be available, but when a critical situation appears, the organization will discover that the true problem was not the lack of controls, but the absence of a clear model to decide.
That is the first learning proposed by SG2CI, before protecting systems, the organization must be prepared to govern them. In the next post, we will address the second step of the itinerary, which consists of identifying what the organization must really protect and how to design an industrial architecture aligned with risk and with the principles of NIS2.