Security & compliance

Built for a stricter security bar, and a stricter regulator.

Network monitoring tools see everything: every device, every credential, every conversation on your network. Here's how Zynty protects that visibility, and how it helps you evidence NIS2 compliance rather than just claim it.

General security

Security isn't a checkbox in settings.

01

Encrypted everywhere

TLS 1.3 between every collector and Zynty Cloud, and AES-256 encryption at rest for telemetry, credentials and audit logs.

02

Access control & MFA by default

Role-based access control, SAML/SSO, and mandatory multi-factor authentication on every account, not gated behind an enterprise tier.

03

Anomaly & threat detection

Unauthorized device joins, port-scan patterns, unusual flow volumes and off-hours config changes are flagged automatically, not just downtime.

04

Credentials never leave your network

Device credentials (SSH, SNMP community strings, API keys) are stored encrypted on the local collector and are never transmitted to Zynty Cloud.

05

Data residency & retention controls

Choose an EU hosting region, and set log and audit-trail retention per your internal policy or regulatory requirement.

NIS2 directive

What NIS2 actually requires, and where Zynty fits.

The NIS2 Directive is the EU's revised cybersecurity law, expanding on the original NIS Directive to cover more sectors and impose stricter, more specific security and reporting obligations.

Essential entities

Higher-criticality sectors

Energy, transport, banking, health, drinking water, digital infrastructure and more. Generally organizations with 250+ staff or €50M+ turnover. Subject to proactive supervision and audits.

Important entities

Broader coverage

Postal services, waste management, chemicals, food, and manufacturing, among others. Generally 50+ staff or €10M+ turnover. Subject to reactive supervision, triggered by incidents.

Article 21 risk-management measures, and how Zynty helps

01

Risk analysis & asset inventory

Know what's on your network before you can assess risk to it.

How Zynty helpsContinuous device discovery keeps an always-current inventory, not a spreadsheet from last quarter.
02

Incident handling & detection

Detect and respond to incidents within the directive's reporting windows.

How Zynty helpsCorrelated alerting surfaces anomalies in minutes, with timestamps ready to feed a 24-hour early warning.
03

Business continuity

Maintain visibility and operations through an incident, not just after one.

How Zynty helpsMulti-region cloud infrastructure and local collector caching keep monitoring running if a link degrades.
04

Supply chain security

Understand and monitor risk introduced by vendors and third-party connections.

How Zynty helpsFlags new or unexpected external peering, VPN endpoints and third-party device connections.
05

Cryptography & access control

Protect data with encryption, and restrict who can access or change what.

How Zynty helpsTLS 1.3, encryption at rest, RBAC and mandatory MFA are on by default across every plan.
06

Effectiveness assessment

Prove your controls work, with evidence, not assertions.

How Zynty helpsExportable audit logs, uptime reports and config-change history give auditors a paper trail on demand.

Incident reporting timeline

24h
Early warning

Initial notification to your national CSIRT or competent authority of a suspected significant incident.

72h
Incident notification

Fuller assessment: severity, impact, and indicators of compromise where available.

1mo
Final report

Root cause, mitigation taken, and cross-border impact if applicable.

Why it matters: penalties for non-compliance

Essential entities
€10M or 2% of global turnover

Whichever is higher. These are minimum thresholds set by the directive; national law may go further.

Important entities
€7M or 1.4% of global turnover

Whichever is higher. First enforcement actions under national laws are expected through 2026.

This page is a general summary, not legal advice. NIS2 obligations, deadlines and the competent authority vary by EU member state and by how your organization is classified. Talk to your DPO or legal counsel to confirm what applies to you.