Logo webu

NIS2 in Practice: Why Compliance Is Not Enough and How to Manage Cyber Risks

 ​

September 17, 2026 | 5 minute read

 ​

The number of cyber incidents in the Czech Republic is growing, and attacks are becoming increasingly sophisticated. While companies are trying to determine whether new legislation applies to them, what obligations it will bring and how to avoid potential penalties, attackers are not concerned with audits or regulatory checklists. This is precisely why organisations should not view NIS2, the new Czech Cybersecurity Act (ZoKB) or the DORA Regulation as just another compliance obligation. Their real purpose is to help companies manage cyber risks more effectively and strengthen their resilience to real-world threats.

NIS2 Is Not Just About Legislation

NIS2 is a European directive aimed at increasing the level of cybersecurity across EU Member States. In the Czech Republic, it is implemented through the ​new Cybersecurity Act (ZoKB), which will affect thousands of organisations across the energy, healthcare, manufacturing, transport, digital services and public administration sectors. In the financial sector, a similar role is played by the European DORA Regulation (Digital Operational Resilience Act), which focuses on digital operational resilience.

Although the individual regulations differ, they share the same objective. They are not primarily about technology or creating more documentation. Instead, they place ​cyber risk management, security governance and management accountability ​at the centre of attention. For many organisations, this represents a significant change. Cybersecurity is no longer solely the responsibility of the IT department but is becoming an integral part of strategic business management.

NIS2 compliance a řízení kybernetických rizik v organizaci
For organisations that have not yet addressed NIS2, it often represents the first opportunity to take a systematic approach to cyber risks and establish fundamental cybersecurity principles. ​NIS2 is not an end goal in itself. It is the beginning of systematic cybersecurity and security risk management within an organisation.

Meeting NIS2 Requirements Does Not Mean You Can Handle a Cyberattack

One of the most common misconceptions is that meeting NIS2 requirements automatically means better security. ​In reality, it is only the foundation.

“An audit can confirm that an organisation has the necessary documentation and processes in place. However, it cannot ensure that the company will be able to handle a real security incident. Our experience shows that the extent of the damage often depends not on the mere existence of security measures, but on the ​speed of detection and response,” ​explains Tomáš Volný, Senior Consultant at axelum.

Attackers do not follow regulatory requirements. They exploit situations where organisations respond slowly, lack clearly defined responsibilities or are unable to distinguish a genuine threat from hundreds of security alerts. ​That is why NIS2 compliance is only the beginning. ​Equally important is the ability to detect an incident in time, escalate it correctly and minimise its impact on the organisation’s operations.

 ​

Risk Management Instead of Blind Regulatory Compliance

Cybersecurity cannot be treated merely as a checklist of requirements; it needs to be ​managed according to real business risks. ​Modern cybersecurity is based on the principle of Information Risk Management – systematically assessing what matters to the company, which threats could affect it and what impact an attack could have on its operations, customers and business. Only with this understanding can organisations determine which security measures genuinely make sense.

This is precisely the approach introduced by NIS2, ZoKB and DORA. Instead of looking at technology in isolation, they ​connect cybersecurity with the way the organisation operates as a whole.

 ​

Management Accountability Is More Than a Formality

The new regulations also significantly strengthen the role of organisational leadership. ​Cybersecurity is no longer an issue that can be fully delegated to the IT department or external providers.

Management needs to understand the key risks, have access to regular and structured reporting on cyber risks, security incidents and the status of security measures, and ​actively participate in decisions regarding security measures. ​This is why governance is increasingly discussed in connection with NIS2 – the way an organisation defines responsibilities, oversight and decision-making processes in the area of security.

Companies with well-established governance generally respond to incidents more quickly and are better able to assess their impact across the organisation. ​

NIS2 as an Opportunity to Build Greater Resilience

Companies that view NIS2 solely as a regulatory obligation are likely to successfully pass an audit. Organisations that use it as an opportunity to strengthen their cyber resilience and improve security risk management, however, stand to gain much more. They will be ​better prepared for incidents, respond faster to emerging threats and protect their critical processes and data more effectively. ​And that is ultimately what matters most.

“At axelum, we help organisations ​move from regulatory compliance to real resilience. ​We support them in preparing for NIS2, ZoKB and DORA, establishing governance, managing cyber risks, conducting security audits and building incident detection and response capabilities. Because the real goal is to protect the organisation in an environment where cyber threats are an everyday reality,” ​says Tomáš Mertl, Senior Consultant at axelum.

 ​

FAQ

Find out who NIS2, ZoKB and DORA apply to and how to move from compliance to genuine cyber resilience.

What is NIS2?
NIS2 is a European directive aimed at increasing the level of cybersecurity across EU Member States. In the Czech Republic, it is implemented through the new Cybersecurity Act (ZoKB).
What is ZoKB?
ZoKB is the new Czech Cybersecurity Act, which transposes the requirements of the NIS2 Directive into Czech law.
What is DORA?
DORA (Digital Operational Resilience Act) is a European regulation focused on the digital operational resilience of the financial sector and its IT service providers.
Who does NIS2 apply to?
NIS2 may apply to organisations operating in selected regulated sectors, such as energy, healthcare, manufacturing, transport, digital services or public administration. The specific scope of obligations depends on the type and size of the organisation and the services it provides.
Is meeting NIS2 requirements enough to ensure cybersecurity?
No. Meeting regulatory requirements is only the foundation. Effective cybersecurity requires continuous cyber risk management, robust governance, regular reporting and the ability to respond effectively to incidents.

Are You Ready for NIS2 and a Real Security Incident?

Find out where your organisation’s vulnerabilities lie and how to move from compliance to genuine cyber resilience.
Schedule a Consultation
All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.