Skip to content
Blog
6 min read

NIS2 and ISO 27001: what we see in practice at small businesses

Who is in scope and since when is covered in our FAQ. This is about something else: what happens once a small business actually has to deal with it.

The factual basis of NIS2 and ISO 27001 (who is in scope, which thresholds apply and since when) is set out in the frequently asked questions on our cybersecurity page. This article is about something else: what we actually encounter when guiding a small business through such a programme.

What a small business actually notices

For most business owners, NIS2 starts as something abstract: legislation mentioned in an email from a sector federation or an accountant. It becomes concrete the moment they realise it is not only about their own company.

What usually lands first is a questionnaire. A client who is themselves in scope forwards it to their suppliers. Suddenly someone has to answer questions about incident handling, access management and awareness training, and that someone often has no IT background.

What people notice next is that it does not stop at technology. Board-level responsibility comes into play. Directors and managers must be able to demonstrate they have the necessary knowledge, and can be held personally liable for negligence. That realisation usually shifts the tone of the conversation, from “is this really necessary” to “how do we take this seriously”.

ISO 27001 works differently. That programme rarely starts out of fear of a fine, but almost always because a client or partner makes it an explicit condition, or because the company wants its information security structured and demonstrable.

The questions we hear most

“Do we really need to act, or can we wait?” By far the most common question. The answer depends more on your sector and your client relationships than on the legal threshold itself.

“Can we absorb this alongside our existing IT, or does someone need to work on it full time?” The reality usually sits in between. It needs sustained attention, but certainly at the start not necessarily a full-time role.

“What if we do not get it perfect? Is somewhat better than nothing enough?” Here we often see relief when we explain that this is a journey. A first, genuine step is worth a great deal, as long as that step is actually taken.

“Can our current IT partner not simply take this on?” Sometimes yes, sometimes no. Many traditional IT partners are strong on infrastructure and support, but less at home in the governance side: policy, documentation and awareness among staff. That is exactly where we step in.

How such a programme actually starts

Almost never with a big, planned initiative. There is usually a concrete trigger: a client questionnaire that needs answering, an insurer asking about the security policy, or a director hearing at a networking event that a peer company is already well underway.

From there the same pattern nearly always follows. First a conversation in which we map out together where the business stands today: which systems exist, who is responsible for what, and what policy and procedure is already in place, even if none of it is written down yet. Only then comes an action plan, with priorities that match the real risk and the pressure from clients or the sector.

What we strongly recommend as a first step, and what companies rarely do on their own: a baseline assessment. Not to fix everything at once, but to know where the biggest risks sit and to be able to prioritise with real knowledge.

The misconceptions that cost the most

The biggest misconception is that NIS2 and ISO 27001 are essentially IT projects. They get pushed towards “the IT person” or the external IT partner, while most of the work is about people and processes: who is allowed to do what, how an incident gets reported, who decides, how staff are trained.

A second misconception is that compliance is an end point, something you achieve and then it is done. In reality it is a continuous process. Policy has to be maintained, staff need refreshers, and risks change along with the business. Those who treat it as a one-off project fall back over time and end up redoing part of the work.

Finally, we often hear the assumption that small companies naturally stay under the radar. In practice it is precisely supply chain pressure that gets smaller businesses moving: a larger client who has to be compliant and passes that on to their suppliers, whether or not those suppliers are strictly in scope themselves.

Curious where your business stands today? A first conversation costs nothing and gives an immediate, realistic picture of the next step.