Services
Three steps that build on each other: find out where you stand, close the gaps that matter, then keep it that way, with the evidence NIS2 asks for.
- Step 1 · usually 2–4 weeks
NIS2 OT Check
For plants that need to know where they stand on NIS2, and what to do first.
Price on request: scoped to what you already haveWhat you get
- An on-site walk-through of your plant with the people who run it
- An inventory of assets and connections, collected passively: nothing touches live control
- A zones-and-conduits model of your plant (IEC 62443)
- A gap list against the NIS2 measures: incident handling, backup and recovery, supply chain, access control and MFA, the 24 h / 72 h / 1 month reporting
- Risks ranked by their impact on safety and uptime, not by checklist order
- A 12-month roadmap with effort estimates, and a briefing for management
The result: You know where you stand, what to do first and what it costs. The gap list and the roadmap are yours to keep.
How we build your rules and playbooks - Step 2 · Project
Implementation
For closing the gaps from the check, without stopping the line.
Price on request, scoped after the checkWhat you get
- Network segmentation along the zones and conduits, including the firewall rules
- Secure remote access for vendors and your own engineers, with MFA
- OT monitoring rolled out and tuned to your plant, so an alert means something
- Backup and recovery for controllers, HMIs and historians, with a tested restore
- Rules and evidence for supplier access
- Planned around your maintenance windows: production keeps running
The result: The gaps closed and documented, ready for the auditor.
- Step 3 · Ongoing
Managed OT Security
For keeping it that way, every day, with proof.
Price on request: depends on your sites and sourcesWhat you get
- Klaar Lagebild run by us, on the tools you already have
- Every alarm assessed: noise kept out, real cases worked through with your team
- NIS2 reports drafted within their deadlines; you check and submit them
- Playbooks, and an audit trail that shows what was done, when and by whom
- A monthly status for management and a quarterly review of rules and risks
- Runs in a German/EU cloud or on premises, air-gapped if needed
The result: Your plant watched, NIS2 kept up, and the proof ready when the BSI or BACS, an auditor or your insurer asks.
Questions we hear
Do you need access to our controllers?
No. We read what your tools already see, read-only and at a low agreed rate. Changes to the plant happen only in agreed maintenance windows, together with your people.
Who submits the NIS2 reports?
You do: the law makes your organisation responsible. Lagebild prepares each report within its deadline; a person on your side checks it and submits it in the BSI portal, or in Switzerland in the BACS Cyber Security Hub.
Do we have to buy new tools?
No. We work with what you run, from OT monitoring to firewalls, SIEM and ticketing, and recommend more only where the check shows a real gap. We are vendor-neutral.
Can we start with the check only?
Yes. The NIS2 OT Check stands on its own: you keep the gap list and the roadmap, whether or not you work with us afterwards.
Where does our data live?
In a German or EU cloud, or on your premises, air-gapped if needed. Nothing leaves the EU.
What does it cost?
It depends on where you start. A plant that already has an asset list, network drawings or an ISO 27001 scope needs less time from us, so the Check and the rollout get shorter. After a free 30-minute call you get a clear quote, with no licence surprises.
Do you work in Switzerland?
Yes. Swiss operators of critical infrastructure report cyberattacks to BACS within 24 hours and complete the report within 14 days (ISG). Lagebild runs the Swiss workflow and drafts both reports. NIS2 still reaches Swiss companies through EU subsidiaries and EU customers, and we cover that too.
Which systems does Lagebild connect to? See the integrations →