

Christian Giebner: Hi, I’m Christian Giebner, solutions architect here at IP Fabric, responsible for the DACH region and supporting my colleagues all over Europe.
And with that, handing over to Matthias.
Matthias Lichtenegger: Thank you. My name is Matthias Lichtenegger. I’m an account executive at IP Fabric, working in sales and project management. Network monitoring and observability are my passions. NIS 2 is one of the most important topics this year, so we’ll focus on that today. Tushar, would you like to introduce yourself?
Asif (Tushar) Imam: Sure. My name is Tushar Imam, and I’m an account executive in the UK. While this business may not seem directly applicable to the UK, it is by inference, as the legislation follows a so-called mootis mundai principle. I'm largely responsible for the analysis behind some of the stuff which is going to be displayed today, as has been brilliantly taken forward by Matthias and Christian.
Matthias L.: All right, let's kick it off. Thank you very much, ladies and gentlemen, for attending today's webinar: “The Role of Network Assurance in the Observability Stack and NIS 2 Compliance.” We would like to put NIS 2 into perspective and discuss it in the context of other important, sometimes maybe even more well-known standards. We don't want to define the organizations who are affected by this too, because we think there is enough information material available. You have your online checkers where you can see if you are affected or not.
We rather more would like to shed light on the affected areas within organizations and from that, we pick our special domain: the network, of course. We want to explore what a network assurance platform actually is and put it into the right place in the observability stack.
We will shed light on why we think that is very important, and finally, we want to align our technology, the IP Fabric platform, to direct paragraphs of the NIS 2 regulation.
So, what is it all about? Nothing more and nothing less than strengthening the resilience and security of the critical digital infrastructure in the European Union. And similar to the Digital Operational Resilience Act—DORA, which is made for the financial industry—NIS 2 is now the big difference to ISO 27001 or IEC 62443 for the industrial environments—
which are very, very known, very appreciated, and globally used standards.
But NIS 2 is different. The law, ISO, and IEC are not mandatory. NIS 2 is mandatory within the European Union. It should have been put into national law by the 17th of October 2024. Only four members of the EU have done so, which includes Croatia, Belgium, Hungary, and Latvia. Germany is very late. For example, we aim for March 2025 after the elections. Because of the delay, there will not be any grace period. That means, starting from the time when NIS 2 is the law in your country, an auditor can stand in front of your door. Now, they probably will not, but it's really time to define the processes.
Asif (Tushar) I.: Matthias, can I make a point here? This might sound really bizarre, but it is actually the case: If you are an entity which trades in Europe across several European countries, you actually have to examine the NIS 2 implementation for every single country and make sure you are compliant.
Now, you would think that wouldn't be difficult since it's all coming from one piece of legislation. But that's not the case—every country in Europe is implementing NIS 2 differently. So that's the first thing: don’t assume that just because you’re in Belgium or Germany, your liability ends there. You need to check what the French are saying, what the Belgians are saying.
The other thing I want to point out is that I keep hearing people say, "Oh, we're a bank, we’re not interested in NIS 2 because we’re governed by DORA." And while it’s true that DORA overrides NIS 2 in the areas it covers, there’s still a lot in NIS 2 that DORA doesn’t address.
Especially when it comes to network segmentation and similar areas. So, banks will have to be dual compliant with both DORA and NIS 2. I’ll step out now.
Matthias L.: Very interesting—keep it coming, Tushar.
Now, let’s assume you’re obligated to follow the NIS 2 Directive. The most affected area is the classic IT office environment because the directive focuses on networks, systems, and data. We’ll focus specifically on the network today, but in certain sectors, operational technology is also relevant.
The biggest impact, however, is that top executives of organizations affected by NIS 2 are personally, legally accountable for any negligence regarding compliance. They must oversee cybersecurity measures and policies. That means management needs to understand what has to be done and what is actually being done.
This also means the legal department must stay up to date from a technical perspective—otherwise, they won’t be able to advise management properly. Human resources are required to organize cybersecurity awareness training, which is crucial. In my view, the average user needs to reach the level of the average IT technician.
If we’re being honest, even the best of us could fall for a well-crafted phishing attempt, and with AI, these attacks are becoming more sophisticated by the hour. Raising awareness within NIS 2-affected organizations would significantly improve overall security.
Another major area, one that could fill an entire webinar, is procurement. Organizations must audit their suppliers. This means that if you’re a supplier for an NIS 2-affected organization, you may very well fall under the regulation as well.
Tushar, do you have any insights into how that’s being handled? As far as we know, ISO 27001 certification is a good starting point.
Asif (Tushar) I.: Yes, in some countries—like Belgium, for instance—having ISO 27001 certification is considered equivalent to NIS 2 compliance. But here’s something important that everyone should take note of. I keep hearing people say, "We're ISO 27001 compliant," and I ask them, "How often do you get audited?" Once a year? That’s not enough.
NIS 2 requires a continuous, rolling program of evidence gathering. You can’t just do a once-a-year audit and expect that to be sufficient. You need a mechanism in place for ongoing compliance. So, I tell people: don’t just tell me you’re ISO 27001 compliant—tell me how you're going to prove it tomorrow.
Matthias L.: Thank you. Regarding procurement, organizations are required to audit their suppliers, but that’s a topic for another webinar.
For context, IP Fabric is ISO 27001 certified. We’re also aiming for SOC 2 certification, and we may eventually fall under the Cyber Resilience Act, which is coming in 2027. Unlike NIS 2, the Cyber Resilience Act will automatically become law in all EU countries when it takes effect. It seems that regulators have learned from the delays surrounding NIS 2.
The idea is that if every organization ensures compliance from their suppliers, security will cascade down the entire chain. Let’s see how that works in practice.
Asif (Tushar) I.: One more point—regarding management’s personal legal accountability. I don’t want to spread fear, uncertainty, or doubt, but here’s the reality: right now, 40% of management teams across Europe are not engaged in cybersecurity at all.
They will be caught off guard. The thing about NIS 2 is that this isn’t like an auditor coming along once a year to check your compliance—you’re expected to be compliant at all times, without prompting.
So, for those 40% of executives who aren’t currently engaged with IT and cybersecurity, they’re the ones who will be held responsible. I’m not saying they’ll all be fined or imprisoned, but there will be a lot of people running around in a panic when they realize how much time they’ve wasted ignoring this.
Matthias L.: Time is a great point. Let’s talk about timelines. Take this real-world example—this is an internal alert from today, in German, about a major healthcare institution being hacked. This is serious.
Under NIS 2, within 24 hours of discovering a significant security breach, you are required to report it. Who do you report it to? You need to know that in Germany, for example, that’s the BSI. And you should have that contact information ready, because if your email systems are down, you may not be able to look it up.
After 72 hours, you must assess the situation and provide details on the potential impact. If you’re responsible for water supply, for example, you need to determine whether households will lose access to clean water. If your business is wastewater management, you need to assess whether you can still process waste—otherwise, there will be a serious public health issue.
And after just one month, you’re required to provide a comprehensive analysis and explain the mitigation measures you’ve taken to restore operations. From a consumer perspective, that’s fair—we all need water, electricity, public transport, and other essential services.
But from an internal perspective, anyone who has ever dealt with a cybersecurity breach knows that four weeks fly by. Just writing a proper report could take two weeks.
Noncompliance—whether failing to meet these timelines or not providing complete information—can have severe consequences.
For essential organizations, such as water utilities, fines can reach €10 million or 2% of annual global revenue—whichever is higher. If your company has €2 billion in revenue, that’s a potential €40 million fine.
For important but non-essential organizations, the minimum fine is €7 million or 1.4% of revenue.
Asif (Tushar) I.: This legislation, I think, is the first occasion where the European Union is forcing the breakdown of the artificial barrier between networks and security. Networks and security have been at odds for so long—why? I don’t understand. But they don’t cooperate. How would you actually evidence what happened in that first critical period?
If you had only access to a SIEM solution, all you have is an event stream saying, "These are the logs of what happened." Do you not need to combine that with something like configuration capture? Bringing the two together, you might be able to say:
This log says they entered the system here. They made this change here. They moved laterally here. They reached their goal and started making crucial changes.
Security alone is not going to be able to see all of that. Networks and security must now start working together.
Matthias L.: And we all agree that visibility plays a big part in both security and compliance. The documentation aspect is highly relevant. So, we’d like to start by explaining what we mean by network assurance, how it fits into best practices, and where it is positioned in the observability stack.
To ensure we’re on the same page, a network assurance platform analyzes and validates your network design, architecture, topology, and configurations. If your security or performance monitoring solution gives you an alert, network assurance complements it with a static foundation of your existing environment, enabling a thorough investigation into lower layers of the OSI model.
Key features of an assurance platform include intent-based validation. It always compares the as-is state with the intended state. It provides what we like to call an "interactive Visio"—a topology mapping tool that shows not just what you have but where you have it.
As mentioned earlier, intent checks assist in troubleshooting best practices through pre-built analytics. This is all reflected in audit-ready reports, helping organizations proactively prevent issues or quickly investigate them. We position our technology as the foundation of the observability stack—it tells you what you have, where you have it, why it exists, and how everything is connected. Many organizations aren’t even certain why their architects built things a certain way.
When a monitoring solution detects an event, our assurance platform enables users to trace:
At the top of the observability stack, AI-powered tools correlate logs and suggest actions. However, foundational knowledge of your network is crucial because you can only protect what you know and see. Network assurance plays an important role in security and compliance by providing essential reports and documentation.
However, network assurance is just one piece of the technology required for NIS 2 compliance. As Tushar mentioned, SIEM solutions are also necessary. Our role is to provide visibility into network security, verify segmentation, read firewall logs, track change management, and offer situational awareness in case of incidents. For instance, our platform helps exclude the network as an entry point for an intruder and supports risk assessments from a network perspective.
So, how does this actually work? The IP Fabric platform behaves like an exceptionally skilled colleague from the network department—one with superpowers. It connects to all network devices, physical or virtual, reads all available information via show commands, and gathers data from routing tables and MAC addresses. It then builds an end-to-end network model, incorporating cloud extensions, and transforms this infrastructure data into usable insights by comparing the as-is state against the intended state.
Our technology includes up to 160 intent checks and provides end-of-life, end-of-service, and end-of-sale information for vendor equipment. This allows organizations to align rollouts with physical presence and other maintenance tasks. Additionally, our solution enables organizations to compare their device operating systems and patch levels against the NIST CVE database without requiring an online connection, making it ideal for high-security environments.
Importantly, our platform is designed to break down silos. Instead of network engineers being the only ones with access to crucial data, our insights are made available to all teams:
Christian will later demonstrate how this applies specifically to NIS 2 compliance. This is all possible because IP Fabric integrates seamlessly into existing IT management ecosystems. As an API-first solution, all information can be extracted and tailored to fit your workflows. For example, in automation, we can write data into a source of truth or CMDB, generate templates, roll them out, and then verify implementation. The same applies to service level management, firewall management, and beyond.
Asif (Tushar) I.: You don’t need to have a handle on everything in your network to be compliant. The priority is to take a top-down approach. Organizations must first define their critical services—those essential for operational resilience. This is a consulting exercise that requires engaging with high-level strategy experts.
Once those services are identified, the next step is understanding which application services support them. From there, organizations need to pinpoint which network and cloud infrastructure elements underpin those applications.
This is why it becomes crucial to identify which network devices support multiple business-critical services. Those devices require more rigorous monitoring than others. Instead of starting from the bottom up, compliance efforts must follow a structured, top-down process.
Matthias L.: Good point. We now want to move to the technical demo and map our technology to specific paragraphs of the NIS 2 directive. We’ll start with one that is directly relevant to us—Section 6.7, on network security. 6.7.2(a): Document the architecture of the network in a comprehensive and up-to-date manner. Christian, over to you.
Christian G.: Yes, this is exactly what we do—and we do it in an automated fashion. Typically, we perform an audit of your network infrastructure, running it twice a day, before and after office hours, but it's up to you how often you want to run our solution.
We create snapshots from every discovery using SSH or API calls, depending on the technology and vendor. This ensures you have all the necessary data, including historical data.
The first item I’d like to show is our complete inventory of your network environment. This includes details down to specific part numbers inside your devices, including serial numbers. You’ll have full documentation of your infrastructure, the hardware in use, and the operating systems running on your devices.
This allows you to quickly assess your exposure when a new vulnerability is announced by a vendor—you can immediately check if any of your devices are affected and take action.
In addition, we generate diagrams automatically based on the data gathered from devices across various sites. As an example, I’ve selected a single site for clarity. Normally, you must provide full documentation of your environment for an audit, but our solution allows you to break it down by specific sites.
Since this is an interactive solution, I can, for example, highlight VLAN 118 in the diagram to see which devices are part of this virtual LAN. I can also highlight the root bridge and spanning tree blocking ports.
Furthermore, we can overlay intent checks to quickly visualize compliance issues, such as insufficient NTP-configured sources.
Now, let's shift to the accountability of company management. Executives often lack network or cybersecurity expertise, which is completely fine—they have other skill sets to focus on. At IP Fabric, we aim to support the executive level by integrating customizable dashboards into our 7.0 release.
These dashboards do not require additional licensing and are designed to be easily understood. I’ve prepared an example dashboard for this webinar, using a simple traffic light system—green indicates compliance, yellow suggests caution, and red signals an immediate issue.
This makes it easy for executives to determine whether their organization meets NIS 2 requirements.
Before we discuss segmentation and access controls, Matthias, could you provide a few relevant paragraph numbers?
Matthias L.: Sure. Let’s connect network security to network segmentation.
Christian G.: Many thanks. Now, let’s look at how we support these requirements.
For example, to check whether an asset is accessible from the internet, I specify an asset—let’s say Google DNS as my external source—and a host on my network. I check for HTTP and HTTPS connectivity, submit the request, and immediately see where traffic is being blocked.
If my asset is properly protected, that’s great. If not, I need to investigate further. I can save this path verification as an intent check, ensuring it is automatically rechecked with every new snapshot.
This also applies to network segmentation—verifying whether specific networks or zones are allowed to communicate. We provide automated path verification that updates dynamically.
With NIS 2 requiring organizations to verify internal access security, we also offer intent checks for edge port security, zone firewall rules, and ACLs. If an edge port has multiple neighbors, that’s a strong indicator something is wrong.
We also provide insights into authentication security. Some vendors support password strength checks, and I’ve created a quick check for this webinar—showing devices where no password strength policy is enforced.
You can then take action by exporting this list to a CSV file or integrating it with your network automation solution.
Similarly, our solution checks outdated authentication methods, end-of-life information, and protocol compliance. I’ve included SNMP version checks, VPN authentication and encryption status, DHCP protection, and more in this dashboard.
For those who need custom compliance checks beyond our out-of-the-box capabilities, we provide a Python script that allows for vendor-specific configuration checks, generating automated reports.
I won’t go too deep into that now, as it’s beyond the scope of this webinar.
With that, do we have any questions from our Q&A?
Matthias L.: I have a question, Christian. How does IP Fabric ensure the accuracy of its discovery? How can you guarantee that the data provided is 100% accurate?
Christian G.: Great question. As we mentioned earlier, we are an on-prem solution that connects to all your network infrastructure devices using SSH or API, depending on the vendor and technology.
We operate like a network engineer, running approximately 50 show commands to gather all necessary information from the first device we log into. This device is either specified by you or defaults to the gateway of our appliance.
From there, we map out the network by identifying its neighbors and then connecting to those neighbors to collect further data. This process continues iteratively until we’ve discovered the entire network.
Even if there are devices that should have been decommissioned years ago but were never documented, we will still detect them. We refer to these as unmanaged neighbors and provide details on how they were discovered—whether through an internal routing protocol like OSPF/IS-IS, static routes, or even LLDP/CDP.
Essentially, these are devices that are verifiably on your network. We provide information on their location, interface, and IP address, allowing you to investigate whether it’s an outdated device that was never removed or a rogue device that shouldn’t be there.
Matthias L.: So what you're saying is that the IP Fabric platform also highlights shadow IT in a highly accurate way?
Christian G.: Exactly.
Matthias L.: Thank you—that's an interesting capability. I received a private message with a follow-up question, but before that, I just want to encourage everyone to keep engaging with us.
I hope we’ve sparked some interest in our technology and helped alleviate some of the burden of NIS 2 compliance—at least from a network perspective.
With that, thank you all for attending, and we look forward to seeing you next time!
Christian G.: Many thanks! Have a great day and a wonderful rest of the week.