NIS2 scenario testing with simulations
The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk management and incident reporting obligations for essential and important entities across the EU.
iluminr simulations let teams rehearse the decisions NIS2 cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.
Simulations mapped to NIS2
Mapping is indicative. Confirm scope against your own obligations.
Frequently asked questions
What is NIS2?
The NIS2 Directive (EU) 2022/2555 sets cybersecurity risk management and incident reporting obligations for essential and important entities across the EU.
How do simulations help with NIS2?
Simulations let teams rehearse the decisions NIS2 cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.
Which iluminr simulations map to NIS2?
Simulations mapped to NIS2 include Bracing for Impact: Communications Test, Data Breach: Major Leak, Extortion: Ransomware Invasion, Inside Job: Data Breach, Trading Halt: Ransomware Chaos and Double Tap: Cyber Attack, among others.
Who should take part?
These simulations are most often run with Technology & Security, Risk, Compliance and Legal.
Can I build a 12-month NIS2 testing program?
Yes. The iluminr program builder suggests a 12-month plan of simulations for NIS2. You can add or remove scenarios and export the plan as a PDF for your board.
Can we customize these simulations?
Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.
Is this mapping legal or compliance advice?
No. The mapping between simulations and NIS2 is indicative. Confirm scope against your own obligations.

