NIS2: which cybersecurity profiles to hire first
NIS2: which cybersecurity profiles to hire to meet the directive's governance, risk management and incident reporting obligations, and in what order.
The NIS2 directive greatly widens the number of organisations subject to cybersecurity obligations, and many mid-sized companies are discovering they are in scope. The practical question follows quickly: who in the team will carry these obligations? This article links each major requirement of the text to the profiles able to own it, and suggests a realistic order of priority for a mid-sized company.
NIS2 in brief
Directive (EU) 2022/2555, known as NIS2, replaces the first NIS directive. It aims for a high common level of cybersecurity across the European Union. The text is available on eur-lex.europa.eu.
A few structural points:
- Two categories of entities: essential entities and important entities. Classification depends mainly on the sector (listed in the directive's annexes) and on the size of the organisation. The substantive obligations are close for both; the main difference is the supervision regime.
- A much wider scope than NIS1: many sectors are added, and a large number of mid-sized companies now fall in scope.
- A directive, not a regulation: each Member State transposes it into national law. In France, transposition goes through the national legislative process, and ANSSI is the authority supporting the entities concerned.
The precise terms (application timeline, detailed criteria, penalties) are set by national law. To check the current status of transposition and whether your organisation is concerned, refer to the information published by ANSSI on cyber.gouv.fr. This article is not a substitute for legal advice.
The three blocks of obligations
Governance
Article 20 of the directive directly involves management bodies. They must approve the cybersecurity risk-management measures, oversee their implementation and follow training. Cybersecurity becomes a board-level topic, with an accountability that can no longer be fully delegated to the technical team.
Risk management
Article 21 requires appropriate and proportionate technical, operational and organisational measures. The text lists, among others:
- policies on risk analysis and information system security;
- incident handling;
- business continuity, backup management and crisis management;
- supply chain security, including relationships with suppliers;
- security in the acquisition, development and maintenance of systems, including vulnerability handling;
- assessing the effectiveness of the measures;
- basic cyber hygiene and training;
- cryptography and, where appropriate, encryption;
- human resources security, access control and asset management;
- multi-factor authentication and secured communications, where appropriate.
Incident reporting
Article 23 requires significant incidents to be reported to the competent authority in several stages. The directive provides for an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, then a final report within one month. Meeting these deadlines means detecting quickly, qualifying the incident and documenting what happened.
From obligations to profiles
Each block of obligations calls for different skills. Here is the most common mapping.
| NIS2 obligation | Main profile | What they bring |
|---|---|---|
| Governance, management involvement | CISO, or fractional CISO | Takes the topic to the executive committee, builds the roadmap, reports on progress |
| Risk analysis, policies, effectiveness assessment | GRC consultant or analyst | Risk mapping, policies, compliance tracking, audit preparation |
| Incident handling, detection | SOC analyst, detection engineer | Monitoring, alert triage, fast escalation of incidents |
| Reporting and crisis management | Incident response specialist | Investigation, timeline, factual input for notifications |
| Access control, multi-factor authentication | IAM engineer | Identity management, permissions, MFA, access reviews |
| Supply chain | Supplier risk analyst (often within GRC) | Supplier assessment, contract clauses, follow-up |
| Vulnerability handling, secure development | Security engineer, AppSec | Patch management, configuration review, development security |
| Continuity and backups | Infrastructure teams, supported by GRC | Continuity plans, restore tests |
One profile often covers several rows, especially in a mid-sized organisation. The goal is not one hire per row, but making sure no row is left without an owner.
In-house or external: what can and cannot be delegated
Some functions are better kept in-house, others can be handed to a provider.
Keep in-house first:
- Leadership. Someone has to know the organisation, its business and its risks, and talk to management. It can be an employed CISO or a fractional CISO, but accountability must be clearly assigned.
- Day-to-day GRC. Policies, risk mapping and supplier follow-up require detailed knowledge of the company.
- IAM, once the estate reaches a certain size: permissions change every week with joiners, leavers and internal moves.
Often outsourced:
- 24/7 monitoring, through a managed SOC. Still keep someone in-house who understands the alerts and can work with the provider.
- Advanced incident response, through a retainer with a provider who can be engaged quickly. ANSSI publishes frameworks and lists of qualified providers that can guide this choice.
- Audits and penetration tests, which benefit from an outside view.
Outsourcing a function does not transfer accountability. You need people in-house who can manage providers, read their deliverables and make decisions.
Prioritising in a mid-sized company
For a company starting with a small security team, this hiring order often works:
- A security lead. An employed CISO or a fractional CISO, depending on size and budget. Without a lead, other hires lack direction. Our guide to hiring a CISO covers the possible profiles.
- A GRC profile. They structure the risk analysis, write the policies and set up compliance tracking. It is often the hire that moves compliance forward the most.
- A detection capability. Either an in-house SOC analyst, or a managed SOC overseen by someone internal. See our article on hiring a SOC analyst.
- A security or IAM engineer, to implement the technical measures: MFA, permission management, hardening, vulnerabilities.
- Incident response, in-house for more exposed organisations, otherwise through a provider retainer and regular exercises. Our incident response interview questions will help you assess this profile.
Adapt this order to your starting point. A company that already has a mature managed SOC will focus on GRC; one already equipped for compliance will invest first in detection.
Pitfalls to avoid
- Hiring "a NIS2 profile". No such job exists as such. Identify the obligations you are missing and hire the matching skills.
- Betting everything on paperwork. Policies without detection or response capability will not let you meet the reporting deadlines.
- Confusing certification with competence. A risk management or audit certification is a useful signal, but it does not prove the person can run a risk analysis in your context. See our article on cybersecurity certifications.
- Underestimating the market. GRC and incident response profiles are in high demand. A slow process or a vague offer will cost you the best candidates.
In short
NIS2 does not create new jobs, but it makes essential some functions many organisations did not have: a clearly identified lead, structured GRC, detection and response capability, and rigorous access and supplier management. Start from the obligations, find the gaps, then hire in the order that secures your organisation fastest.
Need to strengthen your team for NIS2? Cyber Recrut helps you prioritise your hires, then a recruiter and a security practitioner run each search together. Our shortlisted candidates prove their skills on hands-on labs matched to the role. See how we work or share your hiring need.