Skip to content
pioneerdesk.

NIS2

NIS2 asset management: you can only protect what you know

Every NIS2 obligation — risk treatment, patch management, incident response — presupposes that you know your assets completely. A complete, up-to-date inventory is therefore not busywork but the foundation of verifiability.

The inventory is the starting point, not an afterthought

NIS2 is often discussed in terms of individual measures — patches, backups, reporting channels. What gets overlooked is the shared prerequisite: each of these measures relates to specific systems. Anyone who does not know their assets completely can neither assess risks nor close vulnerabilities nor determine the affected scope in an emergency.

The principle is simple: you can only protect what you know. A blind spot in the inventory is a blind spot in the entire security architecture.

What NIS2 expects from asset management

NIS2 (Art. 21) requires risk-based technical and organisational measures — and verifiability. For asset management, this results in concrete requirements:

  • Completeness. All relevant systems captured, including rarely used or decentralised devices.
  • Currency. The inventory reflects the actual state, not the state at the last stocktake.
  • Depth. Not merely “device exists”, but OS version, installed software, patch level, responsible persons and criticality.
  • Linkage. Asset data must converge with risk and patch status, otherwise compliance work remains piecemeal.

A maintained spreadsheet meets none of these requirements on a lasting basis. It goes stale between two maintenance dates and captures nothing that nobody actively enters.

The blind spot: shadow IT

The biggest risk in the inventory is the systems nobody knows about: privately connected devices, forgotten test servers, software installed without authorisation, unmanaged cloud services. Precisely this shadow IT appears in no manual list — and becomes the point of entry when damage occurs.

NIS2-grade asset management must therefore actively search for the unknown, not merely manage the known. More on this under Shadow IT detection.

How OneLog makes the inventory dependable

OneLog treats the asset inventory as a living data foundation, not a document:

  • Automatic collection via the RMM agent and complementary network discovery — new and changed systems are detected without anyone having to enter them.
  • Continuous currency. Hardware, software and patch status are reconciled continuously, so the inventory reflects the real state.
  • Direct NIS2 linkage. Asset data is coupled with patch and risk status, which is what makes the evidence for patch management and risk treatment robust in the first place.
  • Sovereign operation. Collection and storage take place EU-sovereignly in the STACKIT Sovereign Cloud, with no US cloud exposure — the inventory data of your entire estate remains under EU jurisdiction.

A fair assessment

An automated inventory does not replace organisational responsibility — criticality and ownership must still be defined by your team. OneLog provides the robust, up-to-date data foundation for this and takes over the busywork of collection. That is the difference between an inventory that holds up at the next audit and a spreadsheet that is already out of date at the moment of the audit.

Frequently asked questions

Does NIS2 explicitly require an asset inventory?
NIS2 does not name an inventory as an end in itself, but it presupposes one implicitly: risk analysis, patch and vulnerability management and incident handling cannot be evidenced without complete knowledge of your assets. An up-to-date inventory is thus the de facto foundation for meeting the requirements.
What must a NIS2-grade asset inventory contain?
At minimum: hardware and software per system, operating system and patch status, responsible persons, network assignment and criticality. What matters is that the data is collected automatically and kept continuously up to date, rather than going stale in a manually maintained spreadsheet.
Why is a manual inventory list not enough?
Manual lists are usually out of date by the time of an audit and do not capture shadow IT. NIS2 demands verifiability over time — that is only achievable with continuous, automated collection directly from the infrastructure.
How does OneLog cover the asset requirements?
OneLog collects assets automatically via the RMM agent and via network discovery, keeps the inventory continuously up to date and links it directly to patch and risk status. Operation is EU-sovereign in the STACKIT Sovereign Cloud.

See OneLog in your environment

Monitors and maintains your IT remotely and fixes many incidents automatically — hosted in the EU, with no dependency on US cloud providers. NIS2 requirements are built in from the start.