Digital infrastructure
sector entry pointA DDoS wave hits the service. Traffic is rerouted, customers are informed, the service recovers and the notification goes out on time. Three months later the regulator asks: "what did that incident change in your organisation?" The answer sits scattered across tickets, a post-mortem and chat channels. You did learn — you just cannot show it.
The same directives, your regulator
NIS2 and CER apply to essential and critical entities in this sector; supervision lies with the competent authority designated for it. The annex is broad here: from internet exchange points, DNS providers and registries to cloud, data-centre and CDN providers, trust services, and public electronic communications networks and services.
Per anchor: what the directive asks, and what is ready for it.
Go to the law →One yardstick for exercise and real response, recurring threads that get followed through, and readiness from exercise and response data alike.
Go to the approach →