Critical infrastructure cybersecurity: someone signs for this now
Under NIS2 the obligation has a name on it, and the reporting clock is measured in hours rather than weeks. That changes what a security platform has to produce: not only protection, but a record that a named person can stand behind at short notice.
The evidence has to exist before the clock starts, not after.
The duty moved upstairs
Critical infrastructure has always been regulated. What NIS2 changed is who answers. Management bodies approve the risk measures, can be held liable, and are expected to have been trained. The question stopped being whether the network team is competent and became whether a director can demonstrate the organisation did what it said.
Alongside that sits a timetable. An early warning goes to the authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72, and a final report within a month. None of that is time for collecting screenshots.
And underneath the governance, the same old physical reality: assets with thirty year lives, directories that never leave the site, and control networks that were never designed to be reachable.
Accountability is personal
Named individuals carry it, which changes the questions asked internally. People start wanting the underlying record rather than the summary of the record.
Reporting is timed
When the clock is in hours, the only usable evidence is evidence that already existed. Anything assembled during the incident competes with handling the incident.
Isolation is a design, not a wish
Many of these networks are meant to have no path to the public internet at all, which rules out any tool whose management plane lives somewhere else.
A record that exists before you need it
QS-WAN runs a private network from one console, and QNova Client puts it on the devices that can take it. For an operator under NIS2, three things matter most.
Separation you can point at
Each segment sits behind its own gateway, and a permitted path is an edge in the Network Map you can switch off. That picture is the same one the board sees and the one the engineers work from.
The management layer can stay inside
Licensed on your own infrastructure, the console lives inside the boundary, so an isolated network stays isolated and there is no exception to explain to an assessor.
Evidence produced continuously
Assessments return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators, and the detection history is kept rather than summarised, so the 72 hour notification is a reading exercise.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design. Assets with thirty year lives deserve key establishment with the same horizon.
Runs where you decide
License it onto your own infrastructure, take a gateway we ship configured, or let us host it. The choice usually follows whether the network may touch the public internet at all.
Four questions a director should be able to answer
These are the questions that follow an incident, and the ones a supervisory visit opens with. The console holds each answer without a collection exercise.
What is connected to what?
Gateways, VLANs and the edges between them in the Network Map, each one way, two way, disabled or zero trust.
Who had access at the time?
User profiles, their devices and one certificate per gateway membership, with a CSV export for the file.
What did the endpoints see?
Detection history kept and paginated by the service, counted by category, with the engine, the machine and the decision recorded.
Were the measures checked?
Assessment results per gateway, with the risk score and the indicators that moved it.
The honest caveat, before it matters. A green confirmation means the intention was recorded. A gateway that was offline applies it on reconnect, so a record is only current when the gateways are online.
What a platform cannot do for you
Critical infrastructure attracts confident promises. These are the places where this one stops.
It does not make you compliant
NIS2 duties sit with your organisation. The platform produces evidence that helps you meet and show them; nobody here signs anything on your behalf.
It is not a SOC
No analyst of ours watches your network. The score and the evidence are produced for your people to read.
It does not run your process
Control systems, safety systems and their engineering stay with the teams and vendors that own them.
It does not file your report
The 24 and 72 hour notifications are yours to send. What changes is how long it takes to assemble what goes in them.
Start with the report you would have to write
Take the last incident, real or tabletop, and ask where each fact in the notification would come from. A demonstration is free and that question makes a good agenda.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.