NIS2 sets cybersecurity risk-management obligations for in-scope organisations. Valenius doesn’t make you compliant — no product can — but it provides concrete technical building blocks for several of the measures NIS2 expects. Here’s an honest breakdown of what the product covers and what remains your responsibility as the operator.
Valenius can supply technical measures. The organisational programme around them remains the operator’s responsibility.
Technical measures
Server-enforced MFA for user VPN access: every user connection requires a verified second factor before the tunnel carries traffic. This addresses the multi-factor authentication measure NIS2 expects of in-scope entities.
Per-peer and per-group access policies for least-privilege connectivity, with per-customer interface isolation.
Audit logging of access and configuration changes, supporting incident detection and response.
WireGuard® for transport, mutual TLS between components, and configuration encryption at rest.
Managed Cloud hosted exclusively in the EU (Hetzner); self-hosting keeps everything on your own infrastructure.
Organisational obligations Valenius cannot fulfil
Risk analysis and information-security policies
Incident handling and reporting to the national authority within statutory deadlines
Business continuity and crisis management
Supply-chain security governance
Staff training and basic cyber hygiene
Overall governance and management accountability
Talk to us — as an MSP we help with the technical building blocks; the organisational programme stays yours.