An audit report intended for management must translate complex technical findings into measurable operational and financial risks, while proposing a clear remediation path.
NIS2 Security and Compliance Audit Report
Recipients: Board of Directors / General Management
Prepared by: [Name of Service Provider / Security Manager]
Date: [Date]
Scope assessed: Network infrastructure, servers, workstations and governance (Reference: NIS2 Directive / CyberFundamentals)
1. Executive Summary
- Overall maturity level: [Low / Intermediate / Advanced]
- Total number of non-conformities identified: [X] (Critical: [X], Major: [X], Minor: [X])
- Key finding: The infrastructure has critical vulnerabilities that could affect business continuity and expose management to liability under the NIS2 directive.
- Objective of the action plan: To achieve a basic level of compliance within [X] months to eliminate the risks of financial and operational sanctions.
2. Summary Table of Major Risks
| Domain | Technical Observation (The Gap) | Business & Legal Risk (NIS2) | Critical |
| Access Control | Lack of MFA on some local administration accounts and remote access. | Risk of intrusion through compromised credentials (Ransomware attack). | Critical |
| Network & Perimeter | Management flow of accessible or poorly segmented servers (absence of dedicated VLAN). | Rapid lateral spread of malware in the event of a breach. | Major |
| Backups | Non-isolated local backups (lack of immutability). | Risk of total data destruction in the event of a targeted attack. | Critical |
| Subcontracting chain | IT service provider contracts without service level agreements (SLAs) or security requirements. | Direct non-compliance with Article 21 of NIS2. | Major |
3. Detailed Analysis by Domain
A. Governance and Organization
- Observation: [Example: Lack of a formalized Security Policy and mandatory employee training.]
- Impact NIS2: Violation of the obligation of governance and management accountability.
- Priority recommendation: Draft and have the information security policy validated by management, and deploy a phishing awareness plan.
B. Technical Infrastructure and Network
- Observation: [Ex: Overly permissive firewall rules, incomplete network segmentation on UniFi type equipment.]
- Impact of NIS2: Failure to protect information systems and unnecessary exposure to external attacks.
- Priority recommendation: Apply the principle of least privilege, isolate flows and strengthen the security of DNS configurations (Cloudflare/SPF/DKIM).
C. Resilience and Continuity (Backups)
- Observation: [Example: Backup strategy present but not tested under real-world restore conditions.]
- NIS2 impact: Inability to guarantee continuity of service in the event of a major incident.
- Priority recommendation: Implement a documented business continuity plan (BCP) and conduct quarterly integrity tests.
4. Prioritized Remediation Plan (Roadmap)
To optimize resources, corrective actions are ranked by order of urgency:
- Phase 1: Immediate Actions (0 to 30 days) – Critical Emergency
- Widespread deployment of multi-factor authentication (MFA/FIDO2) on all sensitive access points.
- Physical or logical isolation of backups (setting up an immutable, disconnected copy).
- Correction of critical network exposure vulnerabilities.
- Phase 2: Medium-Term Actions (30 to 90 days) – Organizational Compliance
- Implementation of network segmentation (VLAN) and hardening of hypervisors (Proxmox/Docker).
- Review of contracts and security clauses with IT service providers and subcontractors.
- Formalization of the incident notification procedure within 24/72 hours.
- Phase 3: Long-Term Actions (90 to 180 days) – Continuous Improvement
- Centralization of logs (SIEM / Syslog) and implementation of active monitoring.
- Follow-up audit and validation of overall compliance by a third party.
5. Conclusion and Next Steps
Compliance with the NIS2 directive is not just a regulatory requirement; it's the company's operational shield. Management is urged to approve this remediation plan and release the estimated budget of [Amount / Person-days] to launch Phase 1 as soon as possible.