{"id":5411,"date":"2026-09-10T08:00:00","date_gmt":"2026-09-10T06:00:00","guid":{"rendered":"https:\/\/www.lablogic.pl\/?p=5411"},"modified":"2026-09-13T22:47:56","modified_gmt":"2026-09-13T20:47:56","slug":"nis2-risk-management-measures","status":"publish","type":"post","link":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/","title":{"rendered":"What risk management measures must an essential entity implement?"},"content":{"rendered":"\n<p class=\"ll-art-meta wp-block-paragraph\"><a href=\"https:\/\/www.lablogic.pl\/en\/michal-rutkowski\/\"><strong>Micha\u0142 Rutkowski<\/strong><\/a> \u2022 for boards and those responsible for security \u2022 published September 10, 2026 \u2022 8 min read<\/p>\n\n\n\n<div class=\"wp-block-columns ll-art-shell is-layout-flex wp-container-core-columns-is-layout-7387b849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column ll-art-rail is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-railinner is-layout-constrained wp-block-group-is-layout-constrained\">\n\n\n\n<\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column ll-art-main is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-group ll-art-answer is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\" id=\"krotka-odpowiedz\">Short answer<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NIS2 risk management measures do not take the form of a checklist in the Polish Act on the National Cybersecurity System (KSC). The Act describes an information security management system made up of five parts and opens the catalogue of technical and organisational measures with the words \u201cin particular\u201d. The fourteen items of that catalogue indicate what the system must cover. The depth of each measure is determined by the risk assessment and by the six factors set out in the same provision. Two organisations from the same sector may therefore have different sets of measures and both meet the obligation.<\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"dlaczego\">Why this question arises at all<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Entities that met the criteria on the day the amending act entered into force must carry out the obligations under Chapter 3 within twelve months, that is by 3 April 2027 (Article 33(1) of the amending act). As that date approaches, one question comes up more often than all the others. Organisations look for a list of measures to implement, and vendors are happy to offer one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Act is built differently. It describes a target state and indicates the areas the system must cover, but it does not settle the level of detail. For most entities there is no act that would settle it either. The measures set out in Commission Implementing Regulation (EU) 2024\/2690 apply to the digital entities listed in Article 8b(1). The same regulation covers trust service providers, which come under it through the cross-reference in Article 8b(2). Some entities in the electricity subsector additionally apply Commission Delegated Regulation (EU) 2024\/1366 (Article 8b(3)). For other types of entities the Act refers to implementing acts adopted under Article 21(5) of Directive (EU) 2022\/2555 (Article 8b(2)). For those entities the Directive makes the adoption of such acts optional (Article 21(5), second subparagraph). No such acts had been identified by the beginning of September 2026. The Council of Ministers also has a discretionary power to lay down detailed requirements (Article 8a), and no regulation had been identified on that basis either.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The entity itself therefore sets the level of detail that NIS2 risk management measures must have. This is not freedom without consequences, because the competent authority for cybersecurity may request evidence of the implementation of the requirements of Article 8(1) (Article 53(2)(6)) and information needed to assess the measures themselves (Article 53(2)(4)). In relation to an important entity the authority exercises the same powers as part of ex post supervision (Article 53(3)(2) and Article 53(17)). The choice of measures must therefore be defensible, not merely ticked off.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"co-ustalic\">What has to be established before a decision<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What the system described in Article 8(1) consists of<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The information security management system covers the information system used in the processes that affect the provision of the service. The Act divides it into five parts, and each answers a different question. As a rule the same provision binds both essential and important entities, with exceptions in Article 8(3) and Article 8i(1).<\/p>\n\n\n\n<figure class=\"wp-block-table ll-art-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Part of the system<\/th><th>What the Act settles<\/th><th>What remains for the organisation to decide<\/th><\/tr><\/thead><tbody><tr><td>Risk assessment and risk management (point 1)<\/td><td>the requirement that it be systematic<\/td><td>method, scale, frequency and risk acceptance threshold<\/td><\/tr><tr><td>Technical and organisational measures (point 2)<\/td><td>fourteen areas after the words \u201cin particular\u201d<\/td><td>the choice of measure and its depth in each area<\/td><\/tr><tr><td>Information on cyber threats and vulnerabilities (point 3)<\/td><td>the requirement to collect information<\/td><td>sources, handling and responsible persons<\/td><\/tr><tr><td>Incident management (point 4)<\/td><td>the requirement to manage incidents<\/td><td>division of roles, classification and link to reporting<\/td><\/tr><tr><td>Measures preventing incidents and limiting their impact (point 5)<\/td><td>an open list of actions, including updates and protection against unauthorised modification<\/td><td>update procedure, scope of monitoring and rules for limiting traffic<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The order of these parts matters. Point 2 requires measures proportionate to the assessed risk, so the choice of measures follows from the assessment under point 1, not the other way round.<\/p>\n\n\n\n<div class=\"wp-block-group ll-art-zdanie is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<p class=\"wp-block-paragraph\">Remember<\/p>\n\n\n<p class=\"wp-block-paragraph\">A set of measures copied from the Act without the entity&#8217;s own risk assessment is a set without justification.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">What \u201cin particular\u201d means in the catalogue of measures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The fourteen items in Article 8(1)(2) fall into several thematic groups.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>policies on risk assessment and information system security, cryptography policies and access control policies (letters a, k and n);<\/li>\n\n\n<li>security in the acquisition, development, maintenance and operation of the system including its testing (letter b) and asset management (letter m);<\/li>\n\n\n<li>physical and environmental security and human resources security (letters c and d);<\/li>\n\n\n<li>security and continuity of the supply chain of ICT products, services and processes (letter e);<\/li>\n\n\n<li>business continuity plans, contingency plans and disaster recovery plans (letter f);<\/li>\n\n\n<li>continuous monitoring of the system and assessment of the effectiveness of measures (letters g and h);<\/li>\n\n\n<li>cybersecurity education and basic cyber hygiene practices (letters i and j);<\/li>\n\n\n<li>secure means of electronic communication, where appropriate with multi-factor authentication (letter l).<\/li>\n\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The words \u201cin particular\u201d work in both directions. The catalogue is a thematic minimum, so none of the fourteen areas may be omitted. Only the elements that the provision itself qualifies with the words \u201cwhere appropriate\u201d are conditional, such as encryption in letter k and multi-factor authentication in letter l. The catalogue is not a ceiling, however, because the assessed risk may require a measure outside the list. The letters of the catalogue mainly answer the question \u201cwhat\u201d, and they answer the question \u201chow much\u201d only in a few places, such as continuous monitoring in letter g.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Six factors used to justify the choice of measures<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">NIS2 risk management measures must be appropriate and proportionate to the assessed risk. The provision lists six factors that must be taken into account.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>the state of the art;<\/li>\n\n\n<li>the cost of implementation;<\/li>\n\n\n<li>the size of the entity;<\/li>\n\n\n<li>the likelihood of incidents occurring;<\/li>\n\n\n<li>the entity&#8217;s exposure to risks;<\/li>\n\n\n<li>the societal and economic impact.<\/li>\n\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Article 21(1) of Directive (EU) 2022\/2555 lists similar factors and adds the severity of incidents and, where applicable, European and international standards. Proportionality is sometimes read solely as grounds for doing less, but it also works the other way. An entity for which an interruption of service has a broad societal impact faces a higher bar under Article 8(1)(2) than an entity of similar size with a different profile.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I recommend recording how these factors were applied in every significant decision on the scope of a measure. The record does not need to be long. It is enough to state the risk, the option chosen and the factor that decided against the stronger option. Such a record is useful when the authority requests the information needed to assess the measures (Article 53(2)(4)).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How detailed NIS2 risk management measures must be<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are several points of reference, and none of them replaces the entity&#8217;s own analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first is Implementing Regulation (EU) 2024\/2690. It directly binds the digital entities listed in Article 8b(1) and trust service providers. For other entities it serves as a guide to the expected level of detail in describing measures. It is complemented by the ENISA technical implementation guidance of June 2025, which gives examples of evidence for each requirement. The ENISA document is not binding and says so itself. In my assessment it is currently the best available benchmark for the level of detail, provided the organisation bears in mind that the benchmark comes from a different regime.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second point of reference is standards. Recital 79 of Directive (EU) 2022\/2555 points to European and international standards, including the ISO\/IEC 27000 series, as a point of reference for the physical and environmental security of network and information systems. The Act does not require certification or the implementation of any specific standard. A standard is a way of organising and demonstrating compliance, not an obligation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third point of reference is the result of the entity&#8217;s own review. Comparing the actual state with the catalogue in Article 8(1), with a legal basis assigned to each gap, is described in <a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/\">What should a NIS2 gap analysis contain?<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The supply chain has its own criteria<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Supply chain security is the only measure in the catalogue for which the Act added separate selection criteria. When implementing this measure the entity takes into account the vulnerabilities associated with the supplier of hardware or software and the overall quality of the supplier&#8217;s ICT products, services and processes (Article 8(2)). It also takes into account the results of the coordinated security assessment carried out by the Cooperation Group and the results of proceedings under Article 67b. The catalogue itself also refers expressly to relationships with the direct supplier of hardware or software (Article 8(1)(2)(e)).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who does not apply Article 8(1)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An important entity that is a public entity does not apply Article 8(1). Its information security management system must meet the requirements of Annex 4 to the Act (Article 8(3)). The same provision covers an important entity that is one of the higher education and science entities indicated in it, for example a university. The condition is that it is not a research organisation, and the exclusion concerns public tasks performed using information systems. Separately, entities in the banking and financial market infrastructure sectors apply only point 1 and point 2(j) of Article 8(1) (Article 8i(1)).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Annex 4 divides the requirements into mandatory and additional ones, which is sometimes overlooked. Part I lists eighteen items that the system must cover \u201cat least\u201d, from an inventory of ICT products to procedures in the event of an incident. Part II lists nine elements that the system \u201cmay additionally cover\u201d, including rules for using publicly available cloud services and large generative models. Treating Part II as a requirement raises the bar without a basis in the provision. Part III requires a review of the system at least once a year. A review must also be carried out without delay after a recommendation of the Government Plenipotentiary for Cybersecurity concerning the entity&#8217;s information systems, ICT products or ICT services. The same applies to circumstances that may affect the risk of a significant incident and require the actions to be carried out again or the system to be changed. Part IV requires the performance of the actions to be documented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How an organisation demonstrates that NIS2 risk management measures work<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Evidence is part of the obligation, not an add-on to it. Essential and important entities develop, apply and update security documentation for the information system (Article 10(1)). The Act divides it into normative documentation and operational documentation, the latter being records that attest to the performance of activities required by the normative documents. The second group also includes automatically generated records in information system logs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This division is useful in dealings with the authority. The authority may request evidence of the implementation of the requirements of Article 8(1), not merely a description of the adopted rules. A measure described in a policy and not confirmed by any record is, in dealings with the authority, a measure that cannot be demonstrated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second mechanism for demonstrating compliance is audit. An essential entity carries out a security audit of the information system at its own expense at least once every three years (Article 15(1)). It submits a copy of the report to the authority within three working days of receiving it (Article 15(1a)). Entities that met the criteria for being recognised as an essential entity on the day the amending act entered into force must carry out the first audit by 3 April 2028 (Article 33(2) of the amending act). The period is twenty-four months. Independently of this cycle, the authority may order an essential entity to undergo an external audit at any time (Article 15(1b)).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What applies before 3 April 2027<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Entities that were operators of essential services before the amendment face no regulatory gap in this period. Until they implement a system compliant with the new wording of Article 8, they apply a system compliant with the previous wording (Article 33(6) of the amending act). Telecommunications undertakings that performed obligations under Division VIIa of the Telecommunications Law before the amendment continue to perform them under the previous provisions until they begin performing the obligations under Chapter 3 (Article 33(5) of the amending act). For entities covered by the Act for the first time, the obligation arises in full on expiry of the twelve-month period.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"bledy\">Common mistakes<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-errors\">\n\n<li><strong>Treating the fourteen letters of the catalogue as a checklist.<\/strong> The letters mainly indicate areas, and the scope of the measure in each of them follows from the risk assessment.<\/li>\n\n\n<li><strong>Choosing measures before assessing the risk.<\/strong> The provision requires measures proportionate to the assessed risk, so the assessment must come first.<\/li>\n\n\n<li><strong>Reading proportionality solely as grounds for doing less.<\/strong> The societal impact of a service interruption raises the required level.<\/li>\n\n\n<li><strong>Treating certification against a standard as fulfilment of the statutory obligation.<\/strong> A standard helps to demonstrate compliance, but the scope of the obligation follows from the Act.<\/li>\n\n\n<li><strong>Applying Part II of Annex 4 as a mandatory requirement.<\/strong> Part II is optional, while Parts I, III and IV are mandatory.<\/li>\n\n\n<li><strong>Omitting the evidence layer.<\/strong> Without operational documentation the authority has nothing to assess.<\/li>\n\n\n<li><strong>Putting the work off until spring 2027.<\/strong> Implementing business continuity plans and continuous monitoring takes more than one quarter.<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"wnioski\">Conclusions and next steps<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The question \u201cwhich measures should we implement\u201d makes sense only after the question \u201cwhat risk have we assessed\u201d. NIS2 risk management measures do not have to be a set of top-of-the-range technical solutions. They must follow from a choice that the organisation can justify and demonstrate. The order of work is similar in most organisations.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Define the scope of the system, that is, identify the processes affecting the provision of the service and the information systems supporting them.<\/li>\n\n\n<li>Carry out a risk assessment and record the method, scale and acceptance threshold, because the justification of every further choice depends on them.<\/li>\n\n\n<li>Compare the fourteen areas in Article 8(1)(2) with the actual state and identify the gaps.<\/li>\n\n\n<li>For every decision on the scope of a measure, record the factor that decided it.<\/li>\n\n\n<li>Assign each measure an owner and a record that will serve as evidence of its application.<\/li>\n\n\n<li>Organise the normative and operational documentation, with version and access control.<\/li>\n\n\n<li>Plan the audit in advance so that evidence is produced from the start, not three months before its deadline.<\/li>\n\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"materialy-powiazane\">Related materials<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-should-a-nis2-gap-analysis-contain\/\">What should a NIS2 gap analysis contain?<\/a><\/strong> \u2014 how to describe a gap so that it can be turned into a task<\/li>\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/does-every-organization-fall-under-nis2\/\">Does every organization fall under NIS2?<\/a><\/strong> \u2014 entity qualification, on which the scope of obligations depends<\/li>\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/where-should-the-board-begin-preparing-for-nis2\/\">Where should the board begin preparing for NIS2?<\/a><\/strong> \u2014 the order of decisions before implementation begins<\/li>\n\n\n<li><strong><a href=\"https:\/\/www.lablogic.pl\/en\/what-to-do-after-detecting-an-incident\/\">What to do after detecting an incident?<\/a><\/strong> \u2014 incident management in practice during the first day<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"zrodla\">Sources<\/h2>\n\n\n\n<ul class=\"wp-block-list ll-art-sources\">\n\n<li>Act of July 5, 2018 on the National Cybersecurity System, consolidated text (as at July 7, 2026), Articles 8, 8a, 8b, 8i, 10, 15 and 53 and Annex 4 \u2014 ISAP, Chancellery of the Sejm: <a href=\"https:\/\/isap.sejm.gov.pl\/isap.nsf\/DocDetails.xsp?id=WDU20180001560\" target=\"_blank\" rel=\"noreferrer noopener\">isap.sejm.gov.pl<\/a> (in Polish; accessed September 10, 2026)<\/li>\n\n\n<li>Act of January 23, 2026 amending the Act on the National Cybersecurity System and certain other acts (Journal of Laws 2026, item 252), Articles 33 and 49 \u2014 Journal of Laws: <a href=\"https:\/\/dziennikustaw.gov.pl\/D2026000025201.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">dziennikustaw.gov.pl<\/a> (in Polish; accessed September 10, 2026)<\/li>\n\n\n<li>Directive (EU) 2022\/2555 of the European Parliament and of the Council of December 14, 2022 (NIS2), Article 21 and recitals 79\u201382 \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32022L2555\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed September 10, 2026)<\/li>\n\n\n<li>Commission Implementing Regulation (EU) 2024\/2690 of October 17, 2024 \u2014 technical and methodological requirements for the entities listed in Article 8b(1) of the Act and for trust service providers \u2014 EUR-Lex: <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32024R2690\" target=\"_blank\" rel=\"noreferrer noopener\">eur-lex.europa.eu<\/a> (accessed September 10, 2026)<\/li>\n\n\n<li>ENISA, \u201cTechnical Implementation Guidance on Cybersecurity Risk Management Measures\u201d, version 1.0, June 2025 \u2014 an advisory document \u2014 ENISA: <a href=\"https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2025-06\/ENISA_Technical_implementation_guidance_on_cybersecurity_risk_management_measures_version_1.0.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">enisa.europa.eu<\/a> (accessed September 10, 2026)<\/li>\n\n<\/ul>\n\n\n\n<div class=\"wp-block-group ll-art-cta is-layout-constrained wp-block-group-is-layout-constrained\">\n\n<h2 class=\"wp-block-heading ll-nietoc\">Check how you will justify the choice of measures<\/h2>\n\n\n<p class=\"wp-block-paragraph\">An organisation that already has a task list usually needs an answer on the level of detail and on evidence. NIS2 and KSC readiness support covers a review of the information security management system, an assessment of the choice of measures against the assessed risk and putting the documentation in order before the audit.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.lablogic.pl\/en\/nis2-ksc\/\">NIS2 and KSC readiness support<\/a><\/div>\n<\/div>\n\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>NIS2 risk management measures do not take the form of a checklist in the Polish KSC Act. The catalogue in Article 8 indicates fourteen areas, and the depth of each measure is decided by the risk assessment and six factors set out in the same provision.<\/p>\n","protected":false},"author":2,"featured_media":5555,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ll_stan_prawny":"","footnotes":""},"categories":[74],"tags":[],"class_list":["post-5411","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nis2"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"NIS2 risk management measures follow the assessed risk, while Article 8 KSC sets the areas. Six factors for choosing measures and evidence for the authority.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Micha\u0142 Rutkowski\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"The Act does not give a list of measures to tick off\" \/>\n\t\t<meta property=\"og:description\" content=\"The catalogue sets the areas, and the assessed risk sets the level of detail.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t\t<meta property=\"article:section\" content=\"NIS2 and KSC\" \/>\n\t\t<meta property=\"article:tag\" content=\"nis2\" \/>\n\t\t<meta property=\"article:tag\" content=\"ksc\" \/>\n\t\t<meta property=\"article:tag\" content=\"risk management\" \/>\n\t\t<meta property=\"article:tag\" content=\"isms\" \/>\n\t\t<meta property=\"article:tag\" content=\"compliance\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-10T06:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-13T20:47:56+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"The Act does not give a list of measures to tick off\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The catalogue sets the areas, and the assessed risk sets the level of detail.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#article\",\"name\":\"NIS2 risk management measures \\u2014 scope of Article 8 KSC\",\"headline\":\"What risk management measures must an essential entity implement?\",\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-nis2-risk-management-measures-en-1.jpg\",\"width\":1200,\"height\":630,\"caption\":\"The assessed risk sets the NIS2 measures \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"datePublished\":\"2026-09-10T08:00:00+02:00\",\"dateModified\":\"2026-09-13T22:47:56+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#webpage\"},\"articleSection\":\"NIS2 and KSC, Optional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"position\":1,\"name\":\"LabLogic\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"position\":2,\"name\":\"NIS2 and KSC\",\"item\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#listItem\",\"name\":\"What risk management measures must an essential entity implement?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#listItem\",\"name\":\"LabLogic\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#listItem\",\"position\":3,\"name\":\"What risk management measures must an essential entity implement?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/baza-wiedzy\\\/nis2\\\/#listItem\",\"name\":\"NIS2 and KSC\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\",\"name\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"email\":\"m.rutkowski@lablogic.pl\",\"telephone\":\"+48586231777\",\"foundingDate\":\"2004\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-lablogic-site-icon-512.png\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#organizationLogo\",\"width\":512,\"height\":512},\"image\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"additionalType\":\"https:\\\/\\\/schema.org\\\/ProfessionalService\",\"legalName\":\"LabLogic Consulting Micha\\u0142 Rutkowski\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"ul. Wolno\\u015bci 15\",\"postalCode\":\"81-327\",\"addressLocality\":\"Gdynia\",\"addressRegion\":\"pomorskie\",\"addressCountry\":\"PL\"},\"vatID\":\"PL9580972114\",\"taxID\":\"9580972114\",\"areaServed\":{\"@type\":\"Country\",\"name\":\"Poland\"},\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"founder\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"hasOfferCatalog\":{\"@type\":\"OfferCatalog\",\"name\":\"Services\",\"itemListElement\":[{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"External Data Protection Officer (DPO)\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/external-dpo\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"NIS2 and KSC implementation support\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/nis2-ksc\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"Incident and data breach response\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/incident-response\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"GDPR and NIS2 training\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/training\\\/\"}},{\"@type\":\"Offer\",\"itemOffered\":{\"@type\":\"Service\",\"name\":\"AI Act: roles, obligations and preparation\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/en\\\/ai-act\\\/\"}}]}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/\",\"name\":\"Micha\\u0142 Rutkowski\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Micha\\u0142 Rutkowski\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michal-rutkowski-iod\"],\"jobTitle\":\"Data Protection Officer (DPO), NIS2\\\/KSC and cybersecurity advisor\",\"description\":\"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.\",\"email\":\"m.rutkowski@lablogic.pl\",\"knowsAbout\":[\"GDPR\",\"Data Protection Officer (DPO)\",\"NIS2 Directive\",\"Polish National Cybersecurity System Act (KSC)\",\"Cybersecurity incident and data breach response\",\"EU AI Act\",\"ISO\\\/IEC 27001\",\"Information security management\"],\"worksFor\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#webpage\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/\",\"name\":\"NIS2 risk management measures \\u2014 scope of Article 8 KSC\",\"description\":\"NIS2 risk management measures follow the assessed risk, while Article 8 KSC sets the areas. Six factors for choosing measures and evidence for the authority.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/author\\\/michal-rutkowski\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ll-og-nis2-risk-management-measures-en-1.jpg\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"The assessed risk sets the NIS2 measures \\u2014 LabLogic article graphic by Micha\\u0142 Rutkowski\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/nis2-risk-management-measures\\\/#mainImage\"},\"datePublished\":\"2026-09-10T08:00:00+02:00\",\"dateModified\":\"2026-09-13T22:47:56+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/\",\"name\":\"Micha\\u0142 Rutkowski - LabLogic\",\"alternateName\":\"LabLogic\",\"description\":\"DPO, GDPR, NIS2 and cybersecurity in practice\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lablogic.pl\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"NIS2 risk management measures \u2014 scope of Article 8 KSC","description":"NIS2 risk management measures follow the assessed risk, while Article 8 KSC sets the areas. Six factors for choosing measures and evidence for the authority.","canonical_url":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#article","name":"NIS2 risk management measures \u2014 scope of Article 8 KSC","headline":"What risk management measures must an essential entity implement?","author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg","width":1200,"height":630,"caption":"The assessed risk sets the NIS2 measures \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"datePublished":"2026-09-10T08:00:00+02:00","dateModified":"2026-09-13T22:47:56+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#webpage"},"isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#webpage"},"articleSection":"NIS2 and KSC, Optional"},{"@type":"BreadcrumbList","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","position":1,"name":"LabLogic","item":"https:\/\/www.lablogic.pl\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","position":2,"name":"NIS2 and KSC","item":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#listItem","name":"What risk management measures must an essential entity implement?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/#listItem","name":"LabLogic"}},{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#listItem","position":3,"name":"What risk management measures must an essential entity implement?","previousItem":{"@type":"ListItem","@id":"https:\/\/www.lablogic.pl\/en\/baza-wiedzy\/nis2\/#listItem","name":"NIS2 and KSC"}}]},{"@type":"Organization","@id":"https:\/\/www.lablogic.pl\/en\/#organization","name":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","url":"https:\/\/www.lablogic.pl\/en\/","email":"m.rutkowski@lablogic.pl","telephone":"+48586231777","foundingDate":"2004","logo":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/08\/cropped-lablogic-site-icon-512.png","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#organizationLogo","width":512,"height":512},"image":{"@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"additionalType":"https:\/\/schema.org\/ProfessionalService","legalName":"LabLogic Consulting Micha\u0142 Rutkowski","address":{"@type":"PostalAddress","streetAddress":"ul. Wolno\u015bci 15","postalCode":"81-327","addressLocality":"Gdynia","addressRegion":"pomorskie","addressCountry":"PL"},"vatID":"PL9580972114","taxID":"9580972114","areaServed":{"@type":"Country","name":"Poland"},"knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"founder":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"hasOfferCatalog":{"@type":"OfferCatalog","name":"Services","itemListElement":[{"@type":"Offer","itemOffered":{"@type":"Service","name":"External Data Protection Officer (DPO)","url":"https:\/\/www.lablogic.pl\/en\/en\/external-dpo\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"NIS2 and KSC implementation support","url":"https:\/\/www.lablogic.pl\/en\/en\/nis2-ksc\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"Incident and data breach response","url":"https:\/\/www.lablogic.pl\/en\/en\/incident-response\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"GDPR and NIS2 training","url":"https:\/\/www.lablogic.pl\/en\/en\/training\/"}},{"@type":"Offer","itemOffered":{"@type":"Service","name":"AI Act: roles, obligations and preparation","url":"https:\/\/www.lablogic.pl\/en\/en\/ai-act\/"}}]}},{"@type":"Person","@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author","url":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","name":"Micha\u0142 Rutkowski","image":{"@type":"ImageObject","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","width":96,"height":96,"caption":"Micha\u0142 Rutkowski"},"sameAs":["https:\/\/www.linkedin.com\/in\/michal-rutkowski-iod"],"jobTitle":"Data Protection Officer (DPO), NIS2\/KSC and cybersecurity advisor","description":"Data protection and cybersecurity practitioner, owner of LabLogic. Since 2004 he has supported medium and large organisations: audits, implementations, incidents and training.","email":"m.rutkowski@lablogic.pl","knowsAbout":["GDPR","Data Protection Officer (DPO)","NIS2 Directive","Polish National Cybersecurity System Act (KSC)","Cybersecurity incident and data breach response","EU AI Act","ISO\/IEC 27001","Information security management"],"worksFor":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#webpage","url":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/","name":"NIS2 risk management measures \u2014 scope of Article 8 KSC","description":"NIS2 risk management measures follow the assessed risk, while Article 8 KSC sets the areas. Six factors for choosing measures and evidence for the authority.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.lablogic.pl\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#breadcrumblist"},"author":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"creator":{"@id":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg","@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#mainImage","width":1200,"height":630,"caption":"The assessed risk sets the NIS2 measures \u2014 LabLogic article graphic by Micha\u0142 Rutkowski"},"primaryImageOfPage":{"@id":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/#mainImage"},"datePublished":"2026-09-10T08:00:00+02:00","dateModified":"2026-09-13T22:47:56+02:00"},{"@type":"WebSite","@id":"https:\/\/www.lablogic.pl\/en\/#website","url":"https:\/\/www.lablogic.pl\/en\/","name":"Micha\u0142 Rutkowski - LabLogic","alternateName":"LabLogic","description":"DPO, GDPR, NIS2 and cybersecurity in practice","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.lablogic.pl\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"LabLogic - Micha\u0142 Rutkowski | DPO, GDPR, NIS2 and cybersecurity in practice","og:type":"article","og:title":"The Act does not give a list of measures to tick off","og:description":"The catalogue sets the areas, and the assessed risk sets the level of detail.","og:url":"https:\/\/www.lablogic.pl\/en\/nis2-risk-management-measures\/","og:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg","og:image:secure_url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg","og:image:width":1200,"og:image:height":630,"article:section":"NIS2 and KSC","article:tag":["nis2","ksc","risk management","isms","compliance"],"article:published_time":"2026-09-10T06:00:00+00:00","article:modified_time":"2026-09-13T20:47:56+00:00","twitter:card":"summary_large_image","twitter:title":"The Act does not give a list of measures to tick off","twitter:description":"The catalogue sets the areas, and the assessed risk sets the level of detail.","twitter:image":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg"},"aioseo_meta_data":{"post_id":"5411","title":"NIS2 risk management measures \u2014 scope of Article 8 KSC","description":"NIS2 risk management measures follow the assessed risk, while Article 8 KSC sets the areas. Six factors for choosing measures and evidence for the authority.","keywords":null,"keyphrases":{"focus":{"keyphrase":"NIS2 risk management measures","score":0},"additional":[{"keyphrase":"Article 8 KSC Act","score":69},{"keyphrase":"NIS2 information security management system","score":69},{"keyphrase":"NIS2 requirements for essential entities","score":69},{"keyphrase":"Annex 4 KSC Act","score":69}]},"primary_term":null,"canonical_url":null,"og_title":"The Act does not give a list of measures to tick off","og_description":"The catalogue sets the areas, and the assessed risk sets the level of detail.","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"NIS2 and KSC","og_article_tags":[{"label":"NIS2","value":"NIS2"},{"label":"KSC","value":"KSC"},{"label":"risk management","value":"risk management"},{"label":"ISMS","value":"ISMS"},{"label":"compliance","value":"compliance"}],"twitter_use_og":true,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":0,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-10 19:36:56","updated":"2026-09-13 20:54:23","seo_analyzer_scan_date":null,"focus_keyword":"NIS2 risk management measures","additional_keywords":[{"items":{"functionWordsInKeyphrase":{"score":9},"imageKeyphrase":{"score":3},"introductionKeyword":{"score":3},"keyphraseDensity":{"score":4},"keyphraseLength":{"score":9},"textCompetingLinks":{"score":9}},"score":69,"word":"Article 8 KSC Act"},{"items":{"functionWordsInKeyphrase":{"score":9},"imageKeyphrase":{"score":3},"introductionKeyword":{"score":3},"keyphraseDensity":{"score":4},"keyphraseLength":{"score":9},"textCompetingLinks":{"score":9}},"score":69,"word":"NIS2 information security management system"},{"items":{"functionWordsInKeyphrase":{"score":9},"imageKeyphrase":{"score":3},"introductionKeyword":{"score":3},"keyphraseDensity":{"score":4},"keyphraseLength":{"score":9},"textCompetingLinks":{"score":9}},"score":69,"word":"NIS2 requirements for essential entities"},{"items":{"functionWordsInKeyphrase":{"score":9},"imageKeyphrase":{"score":3},"introductionKeyword":{"score":3},"keyphraseDensity":{"score":4},"keyphraseLength":{"score":9},"textCompetingLinks":{"score":9}},"score":69,"word":"Annex 4 KSC Act"}],"truseo_locale":null},"spectra_blocks_featured_image_url":{"thumbnail":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1-150x150.jpg","width":150,"height":150},"medium":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1-300x158.jpg","width":300,"height":158},"medium_large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1-768x403.jpg","width":768,"height":403},"large":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1-1024x538.jpg","width":1024,"height":538},"full":{"url":"https:\/\/www.lablogic.pl\/wp-content\/uploads\/2026\/09\/ll-og-nis2-risk-management-measures-en-1.jpg","width":1200,"height":630}},"spectra_blocks_author_info":{"display_name":"Micha\u0142 Rutkowski","avatar_url":"https:\/\/secure.gravatar.com\/avatar\/29f5af5a0ce65a4307813722032192bdf08e740cbda98b61aa73b548422ff768?s=96&d=mm&r=g","author_link":"https:\/\/www.lablogic.pl\/en\/author\/michal-rutkowski\/","description":"Micha\u0142 Rutkowski \u2014 praktyk ochrony danych i cyberbezpiecze\u0144stwa, w\u0142a\u015bciciel LabLogic. Od 2004 roku pracuje na styku technologii, ochrony danych i zarz\u0105dzania ryzykiem. Pe\u0142ni funkcj\u0119 zewn\u0119trznego IOD\/DPO, prowadzi audyty RODO, kwalifikacj\u0119 i wdro\u017cenia NIS2 oraz ustawy o KSC, wspiera organizacje przy incydentach i naruszeniach ochrony danych, szkoli zarz\u0105dy, kadr\u0119 kierownicz\u0105 oraz zespo\u0142y IT i compliance. Pracuje ze \u015brednimi i du\u017cymi organizacjami, w tym z sektora finansowego i bran\u017c regulowanych."},"_links":{"self":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/comments?post=5411"}],"version-history":[{"count":2,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5411\/revisions"}],"predecessor-version":[{"id":5414,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/posts\/5411\/revisions\/5414"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media\/5555"}],"wp:attachment":[{"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/media?parent=5411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/categories?post=5411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lablogic.pl\/en\/wp-json\/wp\/v2\/tags?post=5411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}