Reference case

Gap Analysis & Action Plan (NIS2 & ISO 27001)

For a mid-sized chemicals company, Kristensson began with a gap analysis against the requirements of NIS2 (the Swedish Cybersecurity Act) and ISO 27001.

NIS2ISO 27001Gap analysis

For a mid-sized chemicals company, Kristensson began with a gap analysis against the requirements of NIS2 (the Swedish Cybersecurity Act) and ISO 27001. We mapped the client’s current practices, controls and governance against the regulatory requirements and identified the gaps and findings that needed to be addressed. Based on the analysis, we produced a concrete action plan in which measures were prioritised using a risk-based approach – the most critical shortcomings first. We now work closely with the client’s organisation and continuously assist them in managing and remediating the findings step by step, from policies and processes to technical controls. Through structure, clear prioritisation and hands-on support, we ensure steady progress towards compliance. The result is that the chemicals company is strengthening its information security and moving towards the requirements of both NIS2 and ISO 27001 in a controlled and sustainable way.

In brief

Challenge
The requirements of NIS2 (the Cybersecurity Act) and ISO 27001 had to be met without a clear picture of where the gaps were.
What we did
Gap analysis of practices, controls and governance against the regulations, a risk-based prioritised action plan and ongoing support to close the findings step by step, from policies to technical controls.
Result
Steady progress towards compliance. The chemical company strengthens its information security and approaches the requirements of both NIS2 and ISO 27001 in a controlled way.

Reviewed by Kristensson i Skåne AB. .

Want to know what a similar engagement would look like for you?

Contact us