Compliance

Compliance: NIS2, data protection and Microsoft Purview

Turn regulatory requirements into concrete measures and Microsoft configuration.

  • NIS2: determine applicability, derive measures, organise evidence
  • Microsoft Purview: classification, data loss prevention and retention
  • Implement and document data protection requirements technically

Compliance requirements read as abstract; implementing them is anything but. Between “appropriate technical and organisational measures” and a Purview policy lies translation work. That is what we do: we map requirements to the systems you run and configure whatever can be configured.

NIS2

The NIS2 directive widens the circle of organisations that must meet minimum cybersecurity requirements and report incidents. The first step is to find out whether, and in which category, your organisation is in scope. Our free NIS2-Guardian quick check gives a first indication; the reliable assessment is something we do together with you.

  • Applicability analysis by sector, company size and role in the supply chain
  • Gap analysis of the Article 21 measures against the current state, in particular risk management, incident handling, business continuity, supply chain security and access control
  • Implementation plan with priorities, responsibilities and evidence an auditor can follow
  • Incident reporting processes and how they are anchored in daily operations

National implementation differs between member states. We work with the versions currently in force and are open about the questions that are not yet finally settled.

Microsoft Purview

Many compliance requirements concern data in Microsoft 365. Microsoft Purview lets you classify and label information, protect it from leaving the organisation, and retain or delete it according to rules.

  • Sensitivity labels with encryption and marking, applied automatically or by users
  • Data loss prevention policies for email, Teams, SharePoint, OneDrive and endpoints, starting in test mode
  • Retention policies and records management according to legal and internal periods
  • Audit logs, eDiscovery and insider risk scenarios with clear responsibilities

Data protection, implemented

We are not a law firm. We implement what your data protection officer or legal department specifies: access concepts, logging, deletion concepts, settings for data locations and telemetry, and we deliver the documentation that goes with it.

Talk to us about this

Tell us what it is about. A person will reply.

German office (sales and engineering)

Berlin, Germany