Cybersecurity Solutions

Four products that produce the evidence NIS2 asks for, where it is hardest to get

Get in Touch

What NIS2 asks, and where the evidence comes from

NIS2 and its implementing regulation ask an essential or important entity to know its assets, test its systems, handle its vulnerabilities, answer for its suppliers and show that its measures work. Four products produce that evidence where it is hardest to get: Ibex on the networks the cloud cannot reach, Buteo on what your domain shows the internet, Goshawk on the code your teams and suppliers deliver, and Marmot on the AI your people use.

Article 21 lists the measures. Implementing Regulation (EU) 2024/2690 says what each one has to look like in practice. The table reads them the way a supervisor will, and names the thing of ours that produces the record.

Measure by measure

NIS2 Article 21 and its Implementing Regulation (EU) 2024/2690. The measures a technical supervisor asks about first, and what of ours answers each one.

Provision What it requires What we bring
§12.4Reg. (EU) 2024/2690, asset inventory A complete, accurate and up-to-date inventory of assets, reviewed at planned intervals. Ibex discovers the hosts on each network segment, keeps one record per device and flags what is outside your baseline. Buteo keeps the inventory of the other side: the subdomains, services and certificates your domain shows the internet, scan after scan.
§6.8Reg. (EU) 2024/2690, network segmentation Systems segmented into networks or zones according to trust level and the risks involved. Ibex shows which segments can reach each database, and touches nothing outside the agreed ranges.
§6.6Reg. (EU) 2024/2690, patch management Security patches applied within a reasonable time, tracked against the software actually in use. Ibex fingerprints product, version and CPE per service, and reads the version each database is really running.
§6.10Reg. (EU) 2024/2690, vulnerability handling Information about technical vulnerabilities obtained, the exposure to them evaluated, and the vulnerabilities managed. Findings from Ibex, each with its severity and its evidence, exported as SARIF for whatever tracks them, and from Goshawk in PDF and DOCX reports with a computed CVSS v4.0 score per finding. Findings from Buteo with a lifecycle of their own, new to accepted risk, and a diff against the previous scan.
Art. 21(2)(e), §6.2NIS2, secure development Security in acquisition, development and maintenance, with rules for secure development applied in-house and when development is outsourced. Goshawk and the Security Audit read the code to test whether those rules held.
Art. 21(2)(d)NIS2, supply chain Supply chain security, weighing the practices of each supplier and service provider, including the code they deliver. An audit of the delivered application. And for the supplier a cloud model becomes, Marmot: the gate bounds what reaches it, and its log proves what did.
Art. 21(2)(f)NIS2, effectiveness Policies and procedures to assess the effectiveness of the cybersecurity measures. An external audit is that assessment, made on the code and the network rather than on paper.

Implementing Regulation (EU) 2024/2690 binds digital infrastructure, ICT service and digital providers directly, and for every other sector it is the most detailed reading of Article 21. The Security Audit page maps the code review on its own, and the Fintech page does the same for DORA. For Portugal's transposition, the calendar and a self-check are on NIS2 in Portugal: the RJC, and DORA's on DORA in Portugal.

Where we are typically brought in

Essential and important entities establishing their position against NIS2 Article 21

Classified and other isolated estates where no cloud service can reach

SOC teams that need tooling beside the SIEM rather than another console

Beside the SIEM, when the answer is tooling

The SOC work we have done since 2019 has not gone away. Where the gap is a workflow rather than a product, we build companion tooling that sits beside QRadar, Splunk, Elastic or Microsoft Sentinel over their native APIs, and nothing gets replaced.

Attack-surface and AI visibility for the environments a cloud agent cannot reach

Source-code audits of what your teams and your suppliers deliver, with the ASVS coverage table

AI your people can use, with a gate that decides per request what may leave

Companion tooling beside your SIEM: log-source onboarding, ownership tracking and retrieval assistants over your runbooks, integrated with QRadar, Splunk, Elastic and Microsoft Sentinel over their native APIs

Dashboards and reports written for the board and the supervisor rather than for the analyst

Deployment patterns that respect your security architecture, including the ones with no route to the internet

The products behind the table

Ibex for the network and Buteo for what it shows the internet, Goshawk for the code, and Marmot for the AI. Three run inside your perimeter; Buteo never enters it.

Ibex

Ibex

Security for the networks the cloud can't reach

Air-gapped attack surface management: network, code, AI and databases assessed from one sealed appliance inside your perimeter, with findings tied to the host they run on.

Learn More about Ibex
Buteo

Buteo

External attack-surface auditing

The outside view of your domain as a service: DNS and email posture, TLS, headers, subdomains and ports, scored, tracked and compared scan to scan.

Learn More about Buteo
Goshawk

Goshawk

Only what survives refutation ships

Security audits of your repositories as an application: automated scanning with its limits stated in writing, and a full tier with senior human verification.

Learn More about Goshawk
Marmot

Marmot

Sovereign AI with a Gate

On-premises AI with a per-request gate that decides what may reach a cloud model, and what never leaves the building.

Learn More about Marmot

Which measure can you not evidence yet?

Tell us the estate and the obligation, and we will say which of these produces the record, and which does not.