Staying afloat

Raft

Continuous compliance: monitoring, governance cycles, and adaptation as everything moves.

The river keeps flowing. Threats evolve, regulations update, and the organisation changes. NIS2 compliance is not a destination reached and forgotten; it is an ongoing operational state requiring sustained attention and adaptation.

Monitoring for effectiveness

Security operations need constant vigilance: critical systems monitored around the clock where service criticality demands it, regular vulnerability scans, threat intelligence for current attack patterns, and security event analysis that separates signal from noise; ML-assisted anomaly detection reduces manual review burden when event volumes are high.

Control effectiveness needs regular testing: controls tested on defined schedules, internal audits reviewing documentation and practice, penetration testing at least annually, tabletop exercises walking through incident scenarios, and red team assessments for mature programmes that want a realistic challenge.

Performance tracking shows what is working: mean time to detect, mean time to respond, vulnerability remediation times, patch compliance rates, awareness test results, incident trends, and gaps identified where risks are not adequately addressed.

Effectiveness metrics and activity metrics are different categories. Mean time to detect and mean time to respond measure outcome performance. Phishing click rate trends and exercise decision quality measure whether training produced observable behaviour change. Patch compliance rates and training completion rates measure whether activities occurred. Both categories are useful, but only the first two confirm that controls are producing their intended effect under realistic conditions.

The annual governance cycle

Board-level reviews keep security visible: an annual review of the programme, its strategy, and effectiveness; risk assessments updated as threats and operations change; budget allocated on current needs; compliance status reported honestly with supporting evidence; management training refreshed on evolving obligations.

Policy and procedure updates prevent drift: policies reviewed annually for relevance, procedures validated against current practice to catch divergence, templates updated with lessons learned, regulatory changes incorporated as they occur.

When procedures and current practice diverge, the divergence is a model signal before it is a compliance failure. The procedure encodes an assumption about how the work gets done; divergence is evidence that the assumption no longer fits. The diagnostic question is what changed: the environment, the risk, the tools, or the team’s understanding of the task. Updating the documentation to match reality addresses the surface condition. Asking why the drift happened is what prevents it reappearing.

Training and awareness never stop: annual mandatory training on current threats, role-specific refreshers, security in onboarding from day one, regular management briefings, and awareness of emerging threats as they appear.

Adapting to change

Organisational change affects security: new systems and services introduce new risks; mergers, acquisitions, and divestitures change scope and structure; new suppliers alter supply chain risk; workforce changes affect knowledge and capability. Technology change does the same: cloud migrations shift responsibility boundaries, transformation initiatives expand the attack surface, AI, IoT, and OT introduce unfamiliar risks, decommissioning changes infrastructure. And the threat landscape moves on its own schedule: new attack techniques, new vulnerability classes, sector-specific targeting, geopolitical shifts in threat actor motivation, ransomware tactics that change faster than annual reviews.

Regulatory evolution deserves its own watch: NIS2 implementation updates across member states, supervisory guidance clarifying expectations, sector-specific requirements as they emerge, related regulations such as GDPR, DORA, and CER, and EU cybersecurity strategy developments. Sector forums, information sharing and analysis centres, supervisory consultations, and peer networks spread the load of noticing.

Improving from experience

Everything that happens teaches something, if asked: post-incident reviews after every significant event, audit findings addressed systematically, lessons from exercises captured and acted on, operational challenges analysed to root cause, near-misses studied as the discounted incidents they are.

When a corrective action from a previous review reappears as the same finding in a later cycle, the corrective action addressed the surface condition but left an assumption intact. There is a third level beyond fixing the symptom (correction) and fixing the root cause (corrective action): asking what the organisation believed about this control’s operating conditions that made the gap seem impossible. That belief, once named, can be checked against current reality and either confirmed or corrected.

Maturing the programme continues from there: practices benchmarked against sector peers, maturity models to measure progress, movement from reactive response toward proactive prevention, and a culture where security responsibility spreads rather than concentrates.

Innovation keeps it sustainable: repetitive tasks automated, control overhead reduced, false positives tuned down, friction removed, new technology making security easier rather than harder.

Audit readiness always

Evidence current and organised, documentation hygiene maintained, regular internal assessments, mock supervisory interactions, and quick-response procedures for authority requests. Sustained commitment holds it together: active executive sponsorship, adequate resourcing as needs evolve, clear accountability, recognition for security contributions, and a champions programme spreading expertise across the organisation.

Output

The output of this stage is annual compliance reviews showing continued adherence, updated risk assessments reflecting current reality, continuous monitoring reports demonstrating vigilance, improvement roadmaps showing evolution rather than stagnation, and board reporting packages keeping leadership informed and engaged.

Last updated: 4 July 2026