Network monitoring tools see everything: every device, every credential, every conversation on your network. Here's how Zynty protects that visibility, and how it helps you evidence NIS2 compliance rather than just claim it.
TLS 1.3 between every collector and Zynty Cloud, and AES-256 encryption at rest for telemetry, credentials and audit logs.
Role-based access control, SAML/SSO, and mandatory multi-factor authentication on every account, not gated behind an enterprise tier.
Unauthorized device joins, port-scan patterns, unusual flow volumes and off-hours config changes are flagged automatically, not just downtime.
Device credentials (SSH, SNMP community strings, API keys) are stored encrypted on the local collector and are never transmitted to Zynty Cloud.
Choose an EU hosting region, and set log and audit-trail retention per your internal policy or regulatory requirement.
The NIS2 Directive is the EU's revised cybersecurity law, expanding on the original NIS Directive to cover more sectors and impose stricter, more specific security and reporting obligations.
Energy, transport, banking, health, drinking water, digital infrastructure and more. Generally organizations with 250+ staff or €50M+ turnover. Subject to proactive supervision and audits.
Postal services, waste management, chemicals, food, and manufacturing, among others. Generally 50+ staff or €10M+ turnover. Subject to reactive supervision, triggered by incidents.
Know what's on your network before you can assess risk to it.
Detect and respond to incidents within the directive's reporting windows.
Maintain visibility and operations through an incident, not just after one.
Understand and monitor risk introduced by vendors and third-party connections.
Protect data with encryption, and restrict who can access or change what.
Prove your controls work, with evidence, not assertions.
Initial notification to your national CSIRT or competent authority of a suspected significant incident.
Fuller assessment: severity, impact, and indicators of compromise where available.
Root cause, mitigation taken, and cross-border impact if applicable.
Whichever is higher. These are minimum thresholds set by the directive; national law may go further.
Whichever is higher. First enforcement actions under national laws are expected through 2026.