Gap Analysis & Action Plan (NIS2 & ISO 27001)
For a mid-sized chemicals company, Kristensson began with a gap analysis against the requirements of NIS2 (the Swedish Cybersecurity Act) and ISO 27001.
For a mid-sized chemicals company, Kristensson began with a gap analysis against the requirements of NIS2 (the Swedish Cybersecurity Act) and ISO 27001. We mapped the client’s current practices, controls and governance against the regulatory requirements and identified the gaps and findings that needed to be addressed. Based on the analysis, we produced a concrete action plan in which measures were prioritised using a risk-based approach – the most critical shortcomings first. We now work closely with the client’s organisation and continuously assist them in managing and remediating the findings step by step, from policies and processes to technical controls. Through structure, clear prioritisation and hands-on support, we ensure steady progress towards compliance. The result is that the chemicals company is strengthening its information security and moving towards the requirements of both NIS2 and ISO 27001 in a controlled and sustainable way.
In brief
- Challenge
- The requirements of NIS2 (the Cybersecurity Act) and ISO 27001 had to be met without a clear picture of where the gaps were.
- What we did
- Gap analysis of practices, controls and governance against the regulations, a risk-based prioritised action plan and ongoing support to close the findings step by step, from policies to technical controls.
- Result
- Steady progress towards compliance. The chemical company strengthens its information security and approaches the requirements of both NIS2 and ISO 27001 in a controlled way.
Want to know what a similar engagement would look like for you?
Contact us