Dashboard

Live
Total Incidents
0
Critical/High
0
Compliance Rate
0%
Pending NIS2
0
Active Alerts
0

No active alerts

Recent Incidents
ID Title Severity Status

SoC

Operational overview for security, compliance, suppliers, and monitored assets.

Open Incidents
0
Compliance Rate
0%
Scanner Health
Unknown
Suppliers Tracked
0
Priority Watchlist

Loading operational watchlist...

Coverage Snapshot

Loading coverage snapshot...

Recent Scanner Activity

Loading scanner activity...

Incident Management

Incident ID Title Severity Status Detected Actions

Compliance Controls

Filter controls, open a control, update status/evidence, and save to refresh compliance KPIs.

Overall Compliance
0%
Controls by Framework
Control Implementation Status
Showing 0 controls
Control ID Name Framework Status Actions

Control Dossier

Loading control dossier...
Task Completion
0%
Open Tasks
0
Blocked / Overdue
0 / 0
Evidence Links
0
Overview
Canonical Objective / Scope
Tasks
Progress Updates
Evidence Links
AI Guidance

Guidance will appear after the dossier loads.

Audit History

No audit history loaded.

Supplier Risk Management

Track supplier questionnaires, evidence links, residual risk, and review cadence per entity.

Suppliers Tracked
0
High / Critical
0
Pending Reviews
0
Open Risk Logs
0
Supplier Register EPC directory not synchronized
Name EPC source Status Criticality Risk Actions
No EPC supplier records loaded.
Questionnaire Template

Loading questionnaire template...

Open Supplier Risks

Loading risk highlights...

Supplier Details

Update the supplier profile, assessments, risks, and evidence records from this page.
Profile
Assessments

Loading assessments...

Risk Logs

Loading risk logs...

Documents

Loading documents...

Entities

Create, edit, and assign users across the entity hierarchy without overloading the active entity selector.

Hierarchy

Loading entity hierarchy...

Entity Details
Select an entity to review or edit it.

Loading entity details...

Entity Members
Assign existing users from the active entity roster to the selected entity.
Assign a new user to this entity or update an existing membership.
Email Role Status Primary Actions

Role-Based Access Control

Users
Creating users without explicit entity scope
Email Role Status Actions
Access Matrix

Threat Intelligence Sharing

Shared Threats
Sharing Agreements
Partner Status Actions
NG-SOC Status

Integrated Scanner

Read-only scanner history routed securely through the portal proxy. Active scans require an owned, explicitly authorized inventory target.

Open Read-only History
Scanner status: not checked.

AI Security Center

Governed visibility for AI agents, security tools, provider APIs, policies, telemetry, and CISO workflow actions.

Select a provider to preview its target scope and data sensitivity.
How to use this page
Start with the action board. If a provider is not configured, add its API key in the deployment environment. External findings are unverified until an analyst validates their evidence. Only validated or internally observed findings can become tasks or incidents. The assistant receives aggregate, sanitized context; raw observations, addresses, hashes, and provider metadata stay outside its prompt.
Automated Security Monitoring
Organization-scoped probe coverage, freshness, run status, and review findings.
Active entity
Verified Targets
0 / 0
Owned monitoring inventory
Scheduled Probes
0 / 0
Enabled automated checks
Latest Success
Never
Across automated probes
Awaiting Validation
0
Unverified external signals
Probe Status
No probe status
Probe Health Coverage Last success Findings
Latest Automated Findings
Recent Probe Runs
Probe Trigger Result Completed New findings
Local Posture Checks
EPC Employee Directory & Monitoring Coverage
Employee records are separate from the 23 NIS2 login accounts. Selecting context never grants portal access.
Security managers only
EPC identities
0
Active directory records
0 / 0
Corporate-domain monitoring eligible
0
Active accounts in entity
0
Employee Department / position Monitoring coverage Last synchronized Context
No employee records loaded.
Viewing this dashboard reads sanitized portal records only. It does not call a provider, launch a scan, notify a user, or create an incident.
Agentic Risk Score
0
Open Findings
0
Provider Health Issues
0
Telemetry Errors 24h
0
API Integrations Status
Optional providers
Provider Status Targets Schedule Baseline Last Success Findings Note
Daily CISO Action Board
Managed Agents
Name Provider Risk Sensitivity
Tools and APIs
Name Type Provider Risk
Agent to Tool and Data Risk Graph
Policy Record
Active Policies
AI Security Findings
Actions are audited and require matching RBAC permissions.

A sanitized, organization-scoped management brief. Printing uses the browser only; the portal does not generate or email a PDF.

Load the brief to review monitoring coverage and evidence status.
Prompt-Injection Simulation

NIS2 SME Compliance Toolkit

Practical templates and tools for NIS2 Directive compliance. Source: paolocarner/nis2-sme-toolkit

🚀 Getting Started: 1️⃣ Read the Executive Briefing → 2️⃣ Complete the Gap Assessment → 3️⃣ Review the Incident Response Playbook → 4️⃣ Customize the Information Security Policy
NIS2 Gap Assessment & Crosswalk Tool
Excel Workbook • 7 Tabs

Interactive workbook for assessing compliance readiness and planning implementation.

  • NIS2 Requirements: All 21 Article 21(2) controls with baseline vs. enhanced implementations
  • Gap Assessment: Interactive scoring (0-3 maturity scale) with automatic severity calculation
  • GDPR Crosswalk: 11 overlap areas showing ~55% efficiency opportunity
  • ISO 27001 Crosswalk: 12 control mappings showing ~75% alignment
  • Priority & Roadmap: 12-month phased plan (213 person-days estimated)
  • Compliance Dashboard: Executive summary with roll-up metrics
Download Gap Assessment (Excel)
NIS2 Executive Briefing
RTF Document • 12 Pages

Board/management presentation covering regulatory obligations, timeline, and strategic response.

  • Executive Summary for board consideration
  • NIS2 Directive Overview & timeline
  • Applicability Assessment (size criteria, sector classification)
  • Legal & Financial Consequences (penalties, management accountability)
  • Article 21 Security Requirements (all 10 measures)
  • Implementation Roadmap & Budget Considerations
  • Regional specifics (Belgium vs. Netherlands)
Download Executive Briefing
Incident Response Playbook
RTF Document • 20+ Pages

Operational playbook for managing cyber incidents under Article 23 notification requirements.

  • 4-level severity matrix with notification thresholds
  • 7-phase process: Detection → Classification → 24h Warning → Containment → Investigation → 72h Report → Recovery
  • Critical NIS2 timelines: 24h early warning, 72h detail, 1-month final
  • Regional procedures (Belgium CCB, Netherlands NCSC-NL)
  • 6 key incident response roles with decision authority
  • Containment actions per incident type (ransomware, data breach, DDoS)
  • Evidence collection & forensic procedures
Download Incident Response Playbook
Information Security Policy Template
RTF Template • 3 Pages

Master security policy template satisfying NIS2 Article 21(2)(a) requirements.

  • Purpose & Scope with regulatory alignment (NIS2, GDPR, ISO 27001)
  • Roles & Responsibilities definitions
  • 7 policy areas: Governance, Risk, Assets, Access, Incidents, Training, Third Parties
  • Baseline vs. Enhanced maturity levels
  • Exceptions Process & Compliance Review
  • Document Control template
Download InfoSec Policy Template
Additional Policy Templates Needed (Article 21(2))
  • Risk Management Policy (21.2.a)
  • Incident Management Policy Critical (21.2.b)
  • Business Continuity & DR Policy Critical (21.2.c)
  • Third-Party Risk Management Policy (21.2.d)
  • Secure Acquisition & Development Policy (21.2.e)
  • Vulnerability Management Policy (21.2.f)
  • Cryptography & Key Management Policy (21.2.g)
  • Human Resources Security Policy (21.2.h)
  • Access Control Policy Critical (21.2.i)
  • Asset Management Policy (21.2.j)
  • Authentication Policy (21.2.k)

Use the Information Security Policy as a structural template for developing these additional policies.

NIS2 Article 21 — Procurement & SCM Guide

Reference guide for supply chain security requirements. ✅ Implemented 🟡 Partial 🔴 Planned

Задължителни клаузи във всеки договор с доставчик по NIS2:

🔴
24-часово уведомление при инцидент
Доставчикът трябва да докладва security инциденти в рамките на 24 часа. Порталът поддържа вътрешно 24h reporting — нужна е договорна клауза за доставчици.
🔴
Right to Audit
Право на одит на cybersecurity практиките на доставчика. Включете клауза за физически и/или дистанционен одит поне веднъж годишно за критични доставчици.
🔴
SBOM (Software Bill of Materials)
За софтуерни доставчици — пълен списък на всички компоненти и зависимости. Критично за vulnerability management и CRA compliance.
🔴
Data Breach Liability
Ясно дефинирана отговорност при пробив на данни — финансова компенсация, timeline за уведомяване, сътрудничество при разследване.
🔴
Termination for Security Failure
Право на незабавно прекратяване при нарушаване на security изискванията без неустойки.
🔴
Sub-processor Vetting
Изискване доставчикът да уведомява и получава одобрение преди ангажиране на под-доставчици.
🔴
Compliance Certification
Изискване за ISO 27001, IEC 62443 или еквивалентен сертификат. Документирайте и следете валидността.
🔴
Vulnerability Disclosure Policy (VDP)
Доставчикът трябва да има публична VDP. Проверете дали е достъпна и дали покрива вашите продукти.

Преди подписване на договор, извършете следните проверки:

🔴
Cyber Risk Questionnaire
Стандартизиран въпросник за оценка на cybersecurity зрелостта на доставчика.
🔴
Financial Health Check
Финансова стабилност — фалит означава прекъсване на поддръжка и security updates.
🔴
Geopolitical Risk Assessment
Оценка на държавния риск. Китай, Русия, Северна Корея = повишен риск за критична инфраструктура.
🔴
NDAA Compliance Check
Проверете дали доставчикът не е в забранения списък: Huawei, ZTE, Hikvision, Dahua и др.
🔴
Reference Checks
Проверка с други клиенти за security инциденти и качество на реакция.
🔴
On-site Security Audit
За критични доставчици — физически одит на security практиките.
Четири-степенна класификация на риска
Ниво Описание Одит
Critical Достъп до критични системи, лични данни, финансови транзакции Всяка година
High Достъп до вътрешни мрежи, чувствителни данни На 2 години
Medium Ограничен достъп, общи данни Самооценка + документация
Low Публична информация, няма системен достъп Базов въпросник

Задължителни документи (Article 21(2)(d) и 21(3)):
🔴
Supplier Security Policy
Политика за сигурност на доставчиците — минимални security изисквания за всички доставчици.
🔴
Supply Chain Risk Assessment Report
Доклад за оценка на риска във веригата на доставки. Порталът проследява NIS2-1.4 контролата за Supply Chain Security.
🔴
Supplier Directory
Пълен регистър на всички доставчици с ниво на риск (Critical/High/Medium/Low).
🔴
Security Clauses Template
Стандартен шаблон със security клаузи за включване във всички нови договори.
🔴
Confidentiality Statements
Декларации за поверителност — NDA с security клаузи за всички доставчици с достъп до данни.

Препоръчителни инструменти:
💡
VRM Platform
BitSight, SecurityScorecard, RiskRecon — за автоматизирана оценка на risk posture на доставчици.
💡
SBOM Tools
FOSSA, Snyk, Mend — за анализ на софтуерни зависимости и vulnerabilities.
💡
IPVM Camera Finder
За идентифициране на rebranded CCTV оборудване от забранени производители.

Article 21(3) изисква да се разгледат:
🔴
Specific vulnerabilities на всеки доставчик
Идентифициране и документиране на специфичните рискове за всеки критичен доставчик.
🔴
Overall quality на продуктите
Оценка на качеството и security maturity на доставяните продукти и услуги.
🔴
Cybersecurity practices
Оценка на cybersecurity практиките на доставчика — incident response, patch management, encryption.
🔴
Secure development procedures
За софтуерни доставчици — SDLC, code review, penetration testing, SAST/DAST.

Постоянен мониторинг:
🟡
Continuous Monitoring
Порталът осигурява continuous monitoring на вътрешни системи (BreachScreeningAgent). За доставчици — планирано.
🟡
Threat Intelligence Feeds
Порталът поддържа threat intelligence sharing. Следете за нови заплахи свързани с доставчици.
🔴
Quarterly Reviews
Тримесечни прегледи на рисковете при критични доставчици. Създайте calendar reminders.
🟡
Incident Tracking
Порталът проследява инциденти — маркирайте supplier-related инциденти в категорията.

⚡ При инцидент при доставчик — EU Reporting Timeline:
Срок Действие Статус в портала
2 часа Първоначално уведомление до СЕРИКС (GovCERT.bg) 🔴 Planned
24 часа Доставчикът трябва да ВИ уведоми ВАС 🟡 Via incidents
5 раб. дни Подробен доклад с impact assessment 🔴 Planned
1 месец Окончателен доклад с root cause analysis 🔴 Planned
Документация за запазване:
Incident Logs
Порталът записва пълни audit logs с всички действия.
🟡
Evidence Preservation
Audit логовете се запазват. За допълнителни доказателства — използвайте impact_assessment полето в инцидентите.
Remediation Records
Пълен workflow за mitigation actions и status tracking в модула за инциденти.

🔴 Тази седмица:
Инвентаризирайте всички Tier 1 доставчици
Създайте списък на всички доставчици с достъп до вашите системи и данни.
Идентифицирайте критичните доставчици
Маркирайте доставчиците с достъп до критични системи, лични данни или финансови транзакции.
Проверете 24-часовата клауза
Проверете дали текущите договори имат 24-часова клауза за уведомление при инцидент.

🟡 Този месец:
Изпратете Cyber Risk Questionnaire
На всички критични доставчици — стандартизиран въпросник за оценка на cybersecurity.
Проверете NDAA compliance
За IT/OT оборудване — проверка срещу забранените списъци (Huawei, ZTE, Hikvision, Dahua).
NIS2 клаузи в съществуващи договори
Започнете преговори за добавяне на NIS2 security клаузи в текущите договори.

🔵 Следващите 3 месеца:
Внедрете Supplier Risk Scoring Matrix
4-степенна класификация на риска за всички доставчици.
On-site одит на топ 3 доставчици
Физически одит на сигурността на 3-те най-критични доставчици.
Създайте Supplier Security Policy
Формална политика за сигурност на доставчиците, одобрена от management.

🚨 Red Flags — Незабавно прекратете или избегнете доставчици, които:
  • Отказват да предоставят VDP (Vulnerability Disclosure Policy)
  • Нямат ISO 27001 или еквивалентен сертификат
  • Са базирани в high-risk юрисдикции без адекватни контроли
  • Имат история на скрити инциденти
  • Отказват on-site одит
  • Нямат 24/7 incident response capability
💰 Budget: 3-5% от procurement за security vetting • €10-50K/год за VRM платформа • €5-15K/одит за критични доставчици • €25-100K за юридически преглед на договори
Често задавани въпроси (Q&A)

До €10M или 2% от глобалния годишен оборот за essential entities. До €7M или 1.4% за important entities.

Software Bill of Materials — пълен списък на всички софтуерни компоненти. Задължително за CRA (Cyber Resilience Act). Позволява бързо идентифициране на засегнати продукти при нова уязвимост (напр. Log4j).

Next-Generation Security Operations Centre — рамка за cross-border сътрудничество между SOC екипи в ЕС. Порталът поддържа threat intelligence sharing с партньорски SOC центрове (BG, RO, GR).

Доставчик е Critical ако има достъп до: критични системи, лични данни на потребители, финансови транзакции, или ако прекъсването на услугата му би причинило significant operational impact. Изисква годишен одит.

INCIDENTRON е EU платформа за автоматизирано докладване на инциденти. Порталът е интегриран с INCIDENTRON API за automated NIS2 reporting.

NIS2 CISO Assistant

AI-powered advisor with real-time portal awareness. Powered by Gemini Flash (latest).

Checking...
Welcome! I am your NIS2 CISO Assistant. I have real-time access to your portal data: incidents, compliance controls, breach screenings, threat intelligence, and more.

Ask me anything about NIS2 compliance, current risks, or what actions to prioritize.