A security team that cannot produce a list of who has access to what, and prove why each person still needs it, is no longer just exposed to attackers. Under the NIS2 Directive, that same gap now exposes the organization to regulators, and it exposes the executives who run the organization to personal liability. Auditors Read more…