Blog | August 13, 2026

The Cybersecurity Act will take effect on August 15, 2026. The Dutch implementation of the European NIS2 Directive requires thousands of organizations to ensure their digital resilience is up to standard and to demonstrate it. The latter is precisely what sets NIS2 apart from previous directives. It is no longer enough to simply say that you are working on cybersecurity. You must be able to prove how you are secured, what incidents have occurred, and what measures you have taken to prevent, detect, and respond to them. You must report an incident to the regulator within 24 hours of discovery. And if your organization demonstrably fails to meet the requirements, executives can be held personally liable. 

Many organizations currently do not know exactly where they stand. And that is precisely the problem. 

What NIS2 Specifically Requires of You 

NIS2 is not a mere checkbox exercise. You must detect attacks and suspicious activities in a timely manner, and every incident must be traceable: what happened, when, through which system, and which accounts were involved. As soon as you discover a significant incident, the clock starts ticking: 24 hours for an initial report to the regulator, followed by a full report within 72 hours. Regulators will then also want to see what measures you’ve taken to prevent a recurrence, supported by reports, playbooks, and evidence of action. You won’t be able to manage this with standalone security tools and manual processes. 

Why the Existing Approach Falls Short 

Over the years, many organizations have built up a patchwork of security solutions: a firewall here, endpoint security there, email security, and perhaps a SIEM system. All these tools generate alerts—hundreds a day, sometimes thousands. The problem is that they operate in isolation from one another. 

Your firewall detects an unknown IP address attempting to connect. Your endpoint solution flags an unusual script. Your identity system registers a suspicious login attempt. But if no one connects those three signals, you won’t see an attack. You’ll just see noise. 

Ignoring noise is human—understandable, even. But it’s also exactly the opening that attackers are looking for. An attacker leaves traces in dozens of places at once: a suspicious link in an email, an unusual DNS query, an account behaving differently than usual. Only when you view those traces in context can you understand what’s really going on. And only then can you intervene in time. 

What XDR Does 

Extended Detection and Response brings together signals from all layers of your environment: your network, your endpoints, your identity management, and your cloud. The system correlates that data in real time and turns disparate clues into a clear attack path. As a result, you not only see that something is going wrong, but you also see where the attack is located and how far it has progressed. 

That may sound similar to what a SIEM does, but the difference lies in the architecture. A traditional SIEM runs on a fixed virtual machine that processes log messages in batches. Each analysis cycle takes time, and during peak hours—in the middle of a workday when everyone is logged in and network traffic is heavy—that processing can quickly fall behind. XDR is cloud-native. If a large number of events come in, additional parallel processes are automatically launched to process them. Once the peak has passed, the system scales back down. Think of it like a highway where you can open extra lanes during rush hour and close them again afterward. A SIEM has a fixed capacity. XDR adapts. For NIS2, this isn’t just a technical detail—it’s the difference between a timely alert and one that arrives too late. 

Moreover, XDR doesn’t stop at detection. As soon as an incident is detected, the system automatically performs containment actions via direct integrations with your existing security tools: blocking a suspicious account, removing an infected device from the network, or blocking a malicious domain for the entire organization. Every action is logged with a timestamp. This provides exactly the documented evidence that regulators expect under NIS2. 

The added value of Avit as a managed XDR partner 

XDR is only as good as the people behind it. Avit manages XDR for you from our own Security Operations Center with teams in Lisbon and Manila, 24/7. Security analysts assess alerts in context, including up-to-date threat intelligence from the NCSC and recent security bulletins. The SLA: identification of every incident within 30 minutes; containment of Priority-1 incidents within two hours. In practice, we achieve this in 15 minutes. 

You won’t have to be woken up by a phone call in the middle of the night. You won’t have to know which buttons to press to stop an attack, and you won’t have to reach out to your network administrator, system administrator, and cloud administrator all at the same time. Avit takes the critical actions. The next morning, you’ll see what happened and what still needs to be resolved. For NIS2, this means structured incident documentation, demonstrable follow-up, and the reporting that regulators expect—all built into how the service operates. 

Are you ready for August 15? 

The Cybersecurity Act has been passed. The effective date has been set. The question is whether you can demonstrate compliance when it really matters. XDR provides the visibility, speed, and documentation required by NIS2. Avit ensures it works day and night, exactly as it should. 

Discover what Avit can do for your organization and contact our security experts.