CASE STUDY
Romanian manufacturing company, NIS2-compliant in 12 weeks
The situation
The CEO found out from the company’s lawyer that the firm fell under NIS2, the EU’s cybersecurity directive. The first reflex was the one we see in almost every leadership team: “we still have time, we’ll deal with it next year.” The second, after reading what management liability and the level of the fines actually mean: who handles this at our company? The answer was nobody. The 2-person IT team kept the company running day to day, but had neither the time nor the specialization for a compliance project. Hiring a security specialist meant a market-rate salary of over EUR 40,000/year in their region, for a role they needed intensively for a few months and then only periodically.
What we did
1. Assessment (2 weeks): we confirmed the company fell under NIS2, inventoried the systems, and measured the gap between the actual situation and the requirements. Deliverable: the exact list of measures to implement, prioritized by risk.
2. Implementation (9 weeks): the technical measures (MFA, tested backups, segmentation, logging, an incident response plan, etc.) and the organizational ones (policies, procedures, responsibilities). We worked with the existing IT team, not over it.
3. Registration and training: we registered the company through the DNSC platform and appointed the NIS2 compliance officer.
4. Audit preparation: complete documentation, evidence for every measure, and a plan for maintaining compliance.
Results
- NIS2-compliant in 12 weeks, with daily operations uninterrupted
- 24 technical and organizational measures implemented and documented
- Total cost: 30% of the annual salary of a dedicated hire - for a result a single employee could not have delivered in that timeframe
- A bonus that was not in the plan: 10 critical vulnerabilities closed
What this means for your company
If your company has operations or a subsidiary in the EU with at least 50 employees or EUR 10 million in revenue, and it works in one of the 18 sectors the directive covers - including manufacturing, distribution, and transport - there is a real probability it falls under NIS2, and the liability is not IT’s, it is leadership’s. In Romania, where this client operates, the registration deadline expired in September 2025; postponing does not make the requirement disappear, it only makes the company’s position harder to defend. The same pattern holds on the US side - CMMC if you sell to the Department of Defense, HIPAA in healthcare, SOC 2 when enterprise customers demand it: the accountability lands on leadership, and as this case shows, the work does not require a full-time hire. Checking where you stand takes a 30-minute conversation and it is free.
“We kept putting off the NIS2 subject for almost a year. The HIFENCE team told us from the start what we needed and what we did not, without trying to sell us more than necessary. In about 3 months everything was done, including the DNSC registration. They respond fast, communication is very good. I recommend them.” — CEO
Schedule a compliance conversation
In 30 minutes you will know where you stand, in black and white.
More case studies
Studiu de caz
200 hours
recovered every day
A WiFi network that had grown organically was costing over 100 operators at a manufacturing company a combined 200+ hours per day. After an audit and redesign, that time was recovered in full - the equivalent of ~25 employees’ work, without a single new hire.
Studiu de caz
6 weeks
for a complete IT takeover
The only person who had managed a distribution company’s IT for 8 years left with 30 days’ notice, without leaving any documentation. We took over everything without a single day of interruption, and today any system can be managed from documentation, not from one person’s memory.
Studiu de caz
EUR 70k
annual savings
A security audit showed a media company was paying ~EUR 6,000 per month for protection that no longer matched reality. The money was redirected to measures with real impact: a stronger security posture, on a smaller budget.