NIS2 and recoverability: what must be demonstrable?

NIS2 is not just about preventing cyber incidents. Organizations must also be able to demonstrate that they are prepared for disruptions and that critical systems and data remain recoverable.

This makes recoverability a vital part of NIS2 compliance. You shouldn’t just have backups. You must also be able to show that backups are protected, recovery processes are in place, and recovery is possible within acceptable limits.

For IT teams, this means that backup, recovery, ransomware protection, air gap, immutability, RTO, and RPO must be made concrete and demonstrable.

Why recoverability is important within NIS2

NIS2 focuses on cyber resilience. This means organizations must manage risks, be able to absorb incidents, and protect continuity.

In the event of a cyber incident, the question is not only whether the attack could have been prevented. The question is also how quickly critical services can be restored.

That is why recoverability plays a major role. When systems, files, or backups are hit, it must be clear which data is available, how recovery proceeds, and how long that recovery takes.

Having a backup is not the same as demonstrating recoverability

Many organizations have backups. However, that does not automatically mean that recovery is well-organized.

A backup is only useful if it:

  • is available when you need it
  • is protected against ransomware
  • cannot be modified or deleted unintentionally
  • can be restored within the desired timeframe
  • is regularly tested
  • aligns with the organization’s recovery goals

For NIS2, demonstrability is particularly important. You must be able to show that policy, technology, and the recovery process are aligned.

What must you be able to demonstrate regarding recoverability?

Demonstrating recoverability starts with clear answers to practical questions.

Which data and systems are critical?

Not all systems have the same priority. Determine which data, applications, and processes are essential for continuity.

Think of customer data, healthcare data, production environments, financial systems, identity systems, document management, email, ERP, backup environments, and archives.

How quickly must recovery take place?

Establish how quickly critical systems must be available again. This is often expressed as RTO, Recovery Time Objective.

An RTO of 4 hours requires a different setup than an RTO of 48 hours.

How much data loss is acceptable?

Establish the maximum amount of data loss that is acceptable. This is often expressed as RPO, Recovery Point Objective.

A short RPO requires frequent backups, sufficient capacity, and good protection of recovery points.

Are backups protected against ransomware?

Attackers often target backup environments as well. Therefore, you must be able to demonstrate that backups are not continuously exposed to the same risks as production environments.

Air gap backup, immutable backup, and separate backup storage play an important role here.

Is recovery being tested?

A recovery plan that has never been tested provides little certainty. Recovery tests show whether data can be restored, how long recovery takes, and where bottlenecks lie.

The role of RTO and RPO in NIS2

RTO and RPO make recoverability concrete.

  • RTO indicates how quickly a system or dataset must be restored after an incident.
  • RPO indicates how much data loss is acceptable.

Together, they determine how your backup and recovery strategy should be designed. They also determine which storage, retention, air gap, and recovery processes are needed.

Without RTO and RPO, recoverability remains vague. With RTO and RPO, you can demonstrate which choices were made and why.

Ransomware recovery under NIS2

Ransomware is a key scenario in recoverability. Not because NIS2 is only about ransomware, but because ransomware directly affects availability, integrity, and continuity.

In ransomware recovery, you must be able to demonstrate that a reliable recovery copy is still available when production environments or regular backups are hit.

Therefore, these measures are important:

The goal is not just that data is stored somewhere. The goal is that data can be restored in a controlled and timely manner.

Air gap and immutable backup as a provable measure

Air gap backup and immutable backup help to strengthen recoverability.

Air gap backup ensures that a backup copy is not continuously accessible from the network. This makes it harder for ransomware to hit this copy as well.

Immutable backup ensures that backup data cannot be modified or deleted for a certain period.

Together, these measures help to demonstrate that recovery points are better protected against modification, deletion, and ransomware.

Which documentation helps with NIS2 demonstrability?

Demonstrability requires documentation. Not as a paper exercise, but as proof that risks, choices, and processes have been recorded.

Think of:

  • overview of critical systems and data
  • backup policy
  • retention policy
  • RTO and RPO per system
  • recovery procedures
  • results of recovery tests
  • roles and responsibilities
  • logging and monitoring
  • incident response plan
  • vendor agreements
  • proof of air gap or immutability

This documentation helps to maintain internal control and makes audits or inspections better substantiated.

The role of storage in NIS2 recoverability

Storage plays a larger role than is often thought. Backup software makes copies, but the storage determines where those copies are located, how they are protected, and how quickly recovery is possible.

For NIS2 recoverability, storage must help with:

  • availability of recovery data
  • protection against modification or deletion
  • ransomware-proof backup
  • scalability with growing data
  • control over access
  • recovery within RTO and RPO
  • demonstrability for audits

Therefore, storage should not be chosen only at the end of the backup strategy. It is a component of cyber resilience.

How Silent Bricks help with recoverable backups

Silent Bricks help organizations store backups securely and keep them recoverable. The solution is suitable for backup, recovery, VTL, air gap storage, and Veeam environments.

For organizations subject to NIS2, Silent Bricks can help to better substantiate backup and recovery. Think of secure storage, air gap, protection against ransomware, and faster recovery processes.

This makes Silent Bricks suitable for organizations that want to not only set up recoverability but also make it demonstrable.

Compliance requires more than recoverable backups

Recoverability is a vital part of NIS2, but not the only one. Organizations must also maintain control over archive data, sensitive business data, and AI applications.

For data that must be kept for a long time, compliant archiving can help to store information securely, verifiably, and demonstrably unalterably. Silent Cubes supports this with hardware WORM storage for digital archives, records, and other critical data with a long retention period.

Also, local AI can contribute to a better compliance approach. When employees use AI with sensitive business data, you want to know where data is processed, who has access, and how rights management is enforced. Silent AI helps organizations to use generative AI locally, without sending sensitive information to public AI services.

This creates a broader approach to compliance: recoverable backups with Silent Bricks, compliant archiving with Silent Cubes, and local AI with Silent AI.

Frequently asked questions about NIS2 and recoverability

What does recoverability mean within NIS2?

Recoverability means that an organization can restore critical data, systems, and processes after an incident. Within NIS2, it is about recovery not only being technically possible but also being demonstrably set up and tested.

No. A backup alone is not enough. You must also be able to demonstrate that backups are protected, recovery is tested, and recovery processes align with RTO, RPO, and continuity requirements.

RTO and RPO make recoverability measurable. RTO determines how quickly systems must be restored. RPO determines how much data loss is acceptable. Without these agreements, it is difficult to demonstrate recoverability.

Air gap backup helps to keep a recovery copy out of reach of ransomware. This increases the chance that a reliable backup will still be available after an incident.

Immutable backup prevents backup data from being modified or deleted for a certain period. This helps to better protect recovery points against ransomware, human error, and unwanted changes.

Silent Bricks supports secure backup storage, recovery, VTL, and air gap storage. This helps organizations keep backups better protected and recoverable.

Want to know more about NIS2, backup, and recovery?

NIS2 requires demonstrable cyber resilience. Backup and recovery play an important role in this, especially when ransomware, data loss, or downtime impact critical processes.

Read more about NIS2 compliance, backup and disaster recovery, or air gap backup against ransomware. Want to test your recoverability? Schedule a meeting with one of our experts.

Subscribe for tips and info

We regularly write blogs on current topics from the world of digital storage technology. Sign up here to be notified about new blogs.