ISO 27001 and NIS2: What Lawmakers Really Want – and What They Don't

Portrait Burkhard Wolkewitz

From

Burkhard Wolkewitz

Posted on

28.7.2026

Many companies still approach information security with a certain skepticism. ISO 27001 and NIS2 are familiar terms to most, but there's a common assumption that the topic is "already being handled somewhere" in the organization. IT, a consultant, or a dedicated officer has it covered. The result: a folder full of documents, a certificate on the wall, and the deceptive feeling that the box has been checked. And that's precisely where the problem starts.

Clear Language in the Law

Let's start with what lawmakers explicitly don't want: a passed audit paired with page after page of documents nobody reads and an officer whose job is just to manage paperwork. In short: compliance theater.

The EU's NIS2 Directive has been anchored in German law since December 2025 as the "NIS2UmsuCG," and it speaks plainly. The German federal government states its goal without ambiguity: to protect critical entities and the European single market and strengthen their resilience. The European Commission adds that the EU is working on multiple fronts to build cyber resilience, protect communications and data, and safeguard the online society and economy. The stated aim is effective protection against attacks on digital infrastructure and documentation alone won't get companies there.

Why Is the Situation So Serious?

The numbers speak for themselves. According to Bitkom's 2025 economic security study, total annual damage from cyberattacks, data theft, and industrial espionage in Germany has reached over €289 billion, anew record. 87 percent of German companies were victims of an attack in the past twelve months. Germany's Federal Office for Information Security (BSI) describes a persistently tense threat situation in its 2025 status report.

BSI President Claudia Plattner puts it bluntly: every institution or person reachable from the internet is, in principle, a target. Attackers specifically look for the most vulnerable points of entry.

Is this alarmism? No, it's a sober description of reality.

Severe Consequences When Companies Don't Act

Germany now has a growing list of companies that didn't survive a cyberattack. Not because of strategic missteps or a market downturn, but because their information security wasn't sufficient.

  • Fasana GmbH, Euskirchen (2025)
    A paper napkin manufacturer founded in 1919 fell victim to a massive ransomware attack. Every computer was locked, leaving the company unable to issue invoices or process orders. The production standstill caused losses in the millions within two weeks, leading to an insolvency filing in June 2025. The cause was a digital attack, not a management failure or drop in demand. (Source: WDR report)
  • EU-REC, Rheinland-Pfalz (2025)
    This recycling and waste-management company discovered a serious cyberattack in April 2025 that also exposed customer data. With its digital infrastructure lastingly damaged and operations collapsing, the company had to file for insolvency. (Source: It-Daily)

These cases aren't outliers. They're examples of a reality playing out across Germany. Mid-sized businesses are hit more and more often, since their defenses tend to be weaker than those of large corporations.

ISO 9001: History Repeating Itself

It's worth looking back at a management system many companies already know: ISO 9001 for quality management. At its core, it's a guide to running a company well, asking: how does a company steer its processes to consistently deliver good results?

In practice, that strategic question has too often become something else: a certification project. ISO 9001 gets handed to a dedicated officer or consultant, produces handbooks and procedures, and then gathers dust on a shelf, pulled out only when an audit is due, then put away again.

The real goal - a company that systematically manages and improves itself - goes unmet. What's left is exactly the compliance theater that was supposed to be avoided. ISO 27001 and ISMS now risk the same fate: companies respond to regulatory pressure by launching a project, producing documents, and pursuing a certificate, but afterward, everything goes back to business as usual, with no real change.

Getting the ISMS Mindset Right From the Start

At its core, an information security management system is a control system for managing business risk in the digital space. Organizations shouldn't simply pile up documents needed to keep a certificate. Instead, the real question is: which information is critical to our business, and how do we protect it?

The answer is rooted deep in business processes. Whether it's sales, development, or purchasing, everyone needs to ask: What data do we handle? What must stay confidential? And what would come back to bite us in the event of a cyberattack?

Only once those questions are answered is it beneficial to talk about systems, permissions, backups, and firewalls. That's the real core of ISO 27001: not regulating technology, but protecting the business. Once you understand that, the ISMS reveals itself as a genuinely strategic business tool.

Plain and Simple: What Lawmakers Expect

Legal texts are complicated, so it's often not obvious what they actually require. Here's what NIS2UmsuCG actually calls for, in plain language:

Risk analysis & security concepts
Companies must systematically identify the risks to their information and processes. Lawmakers aren't after a checklist. They want companies to genuinely know their own vulnerabilities.
Technical & organizational safeguards
NIS2 requires "appropriate" measures, meaning proportional to the risk, not at any cost. The principle: protection with common sense, not more bureaucracy.
Business continuity & crisis management
NIS2 requires clear plans for worst-case scenarios. How well can a company keep functioning after an attack? Lawmakers want companies to both protect themselves and stay resilient in a crisis.
Training & security awareness
People are the most common point of attack for cybercrime. Since technology alone can't protect an organization, NIS2 makes employee training mandatory.
Reporting obligations
Security incidents must be reported within 24 hours, with a detailed report following within 72 hours at the latest. What sounds like control at first actually serves collective defense. Reporting an attack helps protect others too, since attackers often exploit the same gaps across multiple companies.

Welcome to the 21st Century

Behind all this regulatory effort is a simple truth: we live in a digital age. Customer data, calculations, design plans, contracts, and know-how—value creation in business has long since gone digital.

It lives in systems, moves across networks, and sits in the cloud. That's a good thing. It makes companies faster, more efficient, and more competitive. But this digital value is also vulnerable. Failing to protect it doesn't just risk data loss. It risks orders, delivery capability, customer reputation, and, in the worst case, the company's very existence.

Lawmakers have recognized this and responded with NIS2, NIS2UmsuCG, and ISO 27001 as a recognized framework. Not to burden companies with more red tape, but because the threat landscape simply demands it. The protection a functioning ISMS provides isn't a regulatory side project. It's fundamental protection for jobs, for customers, and for market position.

Bottom Line: What Does This Mean for Your Company?

Once you recognize information security as the business governance tool it actually is, the question of where to start looks entirely different. The starting point is your business processes and the critical information flowing through them. You'll also need to ask the uncomfortable question: how long could we afford to be down?

The good news: these questions can be answered by connecting them to your process landscape and to what's already documented as part of quality management. That's how you build an ISMS that's genuinely understood, lived, and developed within your company. And that, ultimately, is the real difference between a certificate on the wall and actual security.

No items found.

Your question to Carsten

Sign in to get in touch with Carsten directly.

Don't miss any more new posts!

Always stay up to date: In our newsletter, we provide you with a fresh update on the Modell Aachen Insights every month.

Desktop and mobile illustration

Similar posts

See all posts