All articles

Penetration testing and NIS2: evidence rather than promises

Pentesting and NIS2: evidence instead of promises

NIS2 penetration testing: demonstrable resilience rather than compliance alone

Many organisations are currently preparing for NIS2 and its Dutch implementation in the Cybersecurity Act (Cyberbeveiligingswet, Cbw). The focus is often on policies, processes, governance and documentation. But the core of NIS2 goes beyond compliance on paper alone.

NIS2 requires organisations not only to implement cybersecurity measures, but also to assess their effectiveness periodically. This follows from Article 21 of the NIS2 Directive, particularly Article 21(2)(f) on assessing the effectiveness of cybersecurity measures.

Cybersecurity is therefore increasingly shifting from a theoretical compliance exercise towards demonstrable digital resilience.

From policy to demonstrable effectiveness

Many organisations now have:

  • policy documentation;
  • MFA;
  • endpoint security;
  • logging;
  • network segmentation;
  • awareness training;
  • vulnerability scanning.

But having measures in place does not automatically mean they are effective against realistic attack scenarios.

This is precisely where a penetration test plays an important role.

But there is a difference between testing on paper and testing the way an attacker thinks. An attacker does not choose the highest-scoring vulnerability. An attacker chooses the route that works. Sometimes that route starts with a forgotten external system. Sometimes with an old account. Sometimes with a combination of small configuration errors that together form an attack path. A good penetration test examines exactly those routes, not only individual vulnerabilities.

A penetration test helps organisations demonstrate that security measures not only exist on paper, but are actually effective against realistic attack scenarios.

A penetration test shows how effective security measures really are in practice.

Why this is becoming increasingly important under NIS2

NIS2 emphasises:

  • risk management;
  • board responsibility;
  • incident prevention;
  • detection capability;
  • demonstrability of measures.

Regulators, auditors and directors therefore increasingly look beyond policy documentation alone towards questions such as:

  • Which systems have been tested?
  • Which attack paths have been examined?
  • Which vulnerabilities have been demonstrated?
  • How have the findings been followed up?
  • Which improvements have actually been implemented?

Technical validation such as a penetration test helps organisations provide specific evidence for these questions within audit, assurance and compliance processes.

A penetration test is more than a vulnerability scan

Automated scans are valuable, but have limitations. They often identify known vulnerabilities or configuration errors without showing the actual impact on the organisation.

A penetration test goes further.

During a penetration test, we examine how an attacker would actually try to gain entry, escalate privileges or compromise critical systems.

This includes looking at:

  • authentication and session management;
  • privilege escalation;
  • network segmentation;
  • cloud configurations;
  • Active Directory security;
  • API security;
  • business logic flaws;
  • chained vulnerabilities;
  • attack paths between systems.

This provides insight not only into individual vulnerabilities, but above all into the real impact and risks for the organisation.

Risk-based testing under NIS2

NIS2 does not prescribe an exact frequency or fixed form of penetration testing. The approach must match the organisation's risk profile.

The depth and frequency of penetration tests must match the organisation's risk profile, sector, threats and system criticality. Read more about commissioning a penetration test.

For organisations with:

  • business-critical processes;
  • sensitive personal data;
  • OT/ICS environments;
  • cloud-native infrastructure;
  • supply chain dependencies;
  • public services;

the need for in-depth technical validation increases considerably.

Many organisations therefore choose to carry out periodic:

  • external penetration tests;
  • internal penetration tests;
  • web application tests;
  • cloud assessments;
  • red teaming;
  • phishing and social engineering tests;

as part of their wider cyber resilience strategy.

Not only compliance, but demonstrable resilience

Ultimately, NIS2 is not only about meeting regulatory requirements.

It concerns whether organisations can actually prevent, detect and limit cyber incidents.

For many organisations, a penetration test provides an important foundation for demonstrating technical resilience.

Not only as a compliance activity, but as demonstrable validation of digital resilience.

Reporting with technical and board-level value

An effective penetration test consists of more than technical findings.

The report must also be useful for:

  • management;
  • the board;
  • auditors;
  • compliance officers;
  • security teams.

That is why reports need to:

  • prioritise risks clearly;
  • make impact specific;
  • provide context;
  • support follow-up;
  • be readable by both technical and board-level audiences.

A report that can serve as evidence within audit, assurance and compliance processes therefore has considerably more value than a list of isolated vulnerabilities.

From a snapshot to systematic validation

Cyber threats change continuously. Cloud environments change daily. New integrations, suppliers and applications constantly expand the attack surface.

That is why more and more organisations no longer see penetration testing as a one-off check, but as part of a systematic cyber resilience programme. This requires continuous insight into the attack surface, vulnerability management, OSINT and threat intelligence. And specialists who assess what can actually be exploited in practice.

SECWATCH Exposure Control brings these elements together, making a penetration test not just a snapshot but the starting point for continuous prioritisation.

Conclusion

Under NIS2, the focus shifts from merely implementing security measures to demonstrating their effectiveness in practice.

A penetration test gives organisations a practical way to test the technical effectiveness of cybersecurity measures, make risks visible and substantiate digital resilience to boards, auditors and regulators.

Frequently asked questions about NIS2 and penetration testing

Is a penetration test mandatory under NIS2?

NIS2 does not explicitly require organisations to carry out a penetration test. However, the Directive does require organisations to take appropriate technical and organisational measures and periodically assess their effectiveness. A penetration test is one of the most widely used forms of technical validation for this purpose.

How often should an organisation carry out a penetration test under NIS2?

NIS2 does not specify a fixed frequency. In practice, this depends on the risk profile, sector, system criticality and changes within the environment. Many organisations choose an annual penetration test or additional tests following significant changes, new applications or modified infrastructure.

What is the difference between a penetration test and an audit?

An audit mainly focuses on policies, processes, governance and compliance. A penetration test examines whether security measures are technically effective against realistic attack scenarios. The two complement each other within a mature cybersecurity strategy.

What does a penetration test contribute to an NIS2 programme?

A penetration test gives organisations technical insight into vulnerabilities, attack paths and risks. It also helps substantiate digital resilience to boards, auditors, customers and regulators.

Do you already know which vulnerabilities pose a real risk today?

Many organisations have scans, tools and reports. But which vulnerabilities actually pose a risk in your specific environment today? And which could be exploited first?

That is the question we start with. We look not only at what is visible, but at what an attacker could do with it.

SECWATCH helps organisations determine which vulnerabilities actually pose a risk, with penetration testing and Exposure Control providing ongoing validation.


Back to all articles