Apply to Join Us

Join the BAIT Service team

0/1000 characters
This form is protected by reCAPTCHA v3 for security

Request Support

Choose your preferred method

Phone call

02 93799330

Email

info@baitservice.it

Remote support

TeamViewer QuickSupport

SOS - Cyber Emergency

Urgent technical support

Important: This service is reserved exclusively for IT emergencies. Requests unrelated to urgent cyber security, IT infrastructure or compromised system issues will not be considered.

This form is protected by reCAPTCHA v3 for security
Compliance & Cybersecurity

Compliance
NIS2 Directive

Directive (EU) 2022/2555, transposed in Italy by Legislative Decree 138/2024. We take you from gap analysis to compliance, with certifiable technical, organisational and incident response measures.

18
Sectors covered by NIS2
€10M
Maximum penalty for essential entities
24h
Deadline for incident early warning
2025
Year of full application in Italy

Our NIS2 journey

A five-phase programme to bring your company to full compliance.

PHASE 1

Gap Analysis

Check of applicability (essential/important), assessment of existing technical and organisational measures, report with a prioritised list of non-compliances.

PHASE 2

Risk Management

Mapping of critical assets and suppliers (supply chain), threat analysis, risk assessment using the ISO/IEC 27005 methodology, treatment plan.

PHASE 3

Governance & Policy

Definition of roles and responsibilities (CISO, DPO), drafting of operational policies and internal rules, accountability of the management body as required by Article 23.

PHASE 4

Technical measures

Implementation of the 10 minimum measures required: MFA, encryption, backup, vulnerability management, network segregation, EDR, access control.

PHASE 5

Incident Response

Incident management procedure, integration with CSIRT Italia, early warning within 24h, notification within 72h, final report within 30 days.

CONTINUOUS

Training & Audit

Mandatory awareness training for employees and the management body, periodic maintenance audits, attack simulation exercises (red team / tabletop).

Sectors affected by NIS2

The directive applies to essential and important entities in these sectors:

Energy
Transport
Banking
Financial markets
Healthcare
Drinking water
Waste water
ICT Service Mgmt
Public admin.
Space
Postal & courier
Waste
Chemicals
Food
Manufacturing
Digital providers
Research
Other critical

Frequently asked questions about NIS2

What is the NIS2 Directive?

Directive (EU) 2022/2555, known as NIS2, is the new European cybersecurity legislation replacing the previous NIS. In Italy it was transposed by Legislative Decree 138/2024 and imposes stricter requirements for cyber risk management and incident reporting.

Is my company subject to NIS2?

NIS2 applies to essential and important entities in 18 sectors that exceed certain size thresholds (generally 50 employees or EUR 10 million turnover). BAIT Service offers a free gap analysis to check whether it applies to you.

What are the penalties for non-compliance?

For essential entities, up to EUR 10 million or 2% of global annual turnover. For important entities, up to EUR 7 million or 1.4% of turnover. Personal liability is also provided for management bodies.

Are you NIS2 compliant?

Find out in 30 minutes whether your company is in scope and what your current level of compliance is. Free preliminary gap analysis.

Request a gap analysis
Contact

Talk to us

Fill in the form and one of our consultants will get back to you

Our contact details