All cases & insights

NIS2: what it actually changes for security hiring

NIS2 moved security from a technical concern to a documented management responsibility. That shift changed which people organisations need, not just how much security work there is.

Start a conversation
Insight · 18 June 2026
01

Two demands, one budget

The directive requires demonstrable governance: risk management, supplier oversight, incident reporting within tight deadlines. That is GRC work. But reporting an incident within 24 hours assumes you can detect it, which is detection engineering. Organisations that hire only for the first requirement discover the gap during their first real incident.

02

Where the scarcity actually sits

GRC specialists who can write a policy exist. GRC specialists who can translate a technical control into an auditable statement and back are rare. On the technical side, the shortage is not in tooling knowledge but in people who can tune detection so an on-call team is not drowning in false positives.

  • Governance specialists with technical literacy
  • Detection and response engineers
  • OT security profiles in industry and energy
  • Supplier and third-party risk
03

Practical advice

Split the role before you post it. Decide whether you need evidence for the auditor or capability against an attacker, then hire deliberately for each. And check availability early: in this niche, a good candidate is usually in a conversation with two other organisations already.

More reading

Talk to the specialist who knows this market.