For organisations / NIS2 technical readiness
NIS2 technical readiness without a report that disappears into a drawer.
An independent, fixed-scope review for European organisations that need to understand which infrastructure weakness could turn an incident into days of downtime.
Situation
Compliance starts on paper. Readiness is proved during an incident.
Policies and asset lists do not show what happens when an administrator account is compromised, a core service fails or ransomware reaches the production environment.
The sprint translates those scenarios into decisions: what to fix first, who owns it, what delay costs and how recovery can be verified.
Who it is for
For organisations where a day of downtime costs more than prevention.
- Approximately 50–250 employees with a small internal IT team
- Microsoft 365 combined with on-premises, network or production systems
- Manufacturing, logistics, technology and availability-dependent operations
- A live NIS2 programme, audit, insurance renewal or recent incident
Scope
A clear view of risk and a remediation plan that can be executed.
Every finding is connected to business impact, priority, ownership and a practical next step.
Identity and access
M365, privileged accounts, MFA, remote administration and emergency access.
Network and availability
Firewalls, VPN, segmentation, resilience and critical single points of failure.
Backup and recovery
Not just backup status, but procedures, responsibilities and actual recoverability.
Operational hygiene
Monitoring, patching, certificates, logging and documentation.
Top ten risks
Ranked by business impact, urgency and remediation effort.
90-day roadmap
A realistic sequence of work plus one agreed quick improvement.
Process
From business context to the first improvement.
Context
Confirm the critical service, business risk and available evidence.
Technical review
Inspect architecture, configuration, dependencies and recovery procedures.
Priorities
Translate findings into impact, ownership and decisions.
Movement
Deliver the roadmap and implement one agreed quick win.
Important boundary
Technical readiness is not legal certification.
The sprint is not a penetration test or a legal compliance audit. It tests whether technology, operational practice and recovery capability are ready for a real incident.
Next step
Let us establish whether the sprint fits your organisation.
In 20 minutes we can cover the size of the environment, its most critical service and why the issue needs attention now.