NIS2 deadlines
Directive in force, real fines, but policies and remediation still to be defined.
NIS2, security and AI governance for SMEs.
Companies of 10 to 250 employees, with a focus on the Italian market, that need to comply with NIS2, GDPR and the EU AI Act without an in-house SOC. noze offers affordable platforms and ongoing support.
Directive in force, real fines, but policies and remediation still to be defined.
Incomplete IT inventory, vulnerabilities discovered only after an incident.
Departments using cloud LLMs without policies or traceability.
No in-house CISO, no dedicated DPO, no red team.
Vulnerability assessment and automated pentest, monthly subscription.
NIS2 / GDPR / AI Act in one on-premise platform.
Open AI governance with Admina Enterprise: NIS2 and AI Act without lock-in.
SolutionCISO-as-a-service consulting to define posture and roadmap.
SolutionAI strategy, governance and responsible adoption for SMEs.
SolutionCloud-native architectures, web apps and scalable microservices.
From 11 September 2026 Article 14 of Regulation (EU) 2024/2847 applies: early warning within 24 hours, notification within 72 hours, final report within 14 days of the fix being made available. The clock does not start from a CVE or a CVSS score but from reliable evidence that somebody is exploiting the vulnerability. Reports go through the ENISA single reporting platform, which opens on the same day the obligation becomes enforceable, and you need to have registered beforehand.
On 30 July Anthropic called the incidents in its own cyber evaluations closer to an operational failure than an alignment failure. It now retracts that: they were biased reasoning and recklessness. The evidence sits in one comparison, 79% against 1%, and in a monitor that flagged 1% of actions while reading the chain of thought and about 50% with it stripped out. There is also a PyPI attack chain that infected 15 hosts in 90 minutes.
A native plugin in Zig exposes x64dbg over MCP with 80 tools, from disassembly to conditional breakpoints through OEP detection and module dumping. These are the operations that make up sample triage, now reachable by an agent. The project declares MCP revision 2024-11-05, listens on 0.0.0.0 and enforces a bearer token generated on first run.
noze pairs CyberAgent's vulnerability assessment and automated pentest, on a monthly subscription, with DataGovern to handle NIS2, GDPR and the AI Act in one on-premise platform. CISO-as-a-service consulting sets posture and roadmap without hiring an internal security team.
CyberAgent is built for an SME budget: vulnerability assessment and pentest are delivered as a monthly subscription, with no need to build an internal red team. noze's platforms are affordable and come with ongoing support, so spending stays predictable and security does not depend on a single incident.
With Admina Enterprise, SMEs adopt open AI governance that covers NIS2 and the AI Act without lock-in, bringing policies and traceability to how departments use LLMs. noze's AI strategy guides responsible adoption without giving up generative tools.