NIS2. Response. Continuity.
Outsourced CSIRT: your contact point for incident management
The NIS2 Directive requires an operational and reachable CSIRT (Computer Security Incident Response Team) contact point for incident management and mandatory notifications to the ACN (Italian National Cybersecurity Agency). AtWorkStudio provides a dedicated outsourced CSIRT contact point, backed by ISO/IEC 27001, 27017, 27018 and ISO 9001 certified competencies, to ensure compliance and business continuity.
Is your company ready for NIS2?
Find out in 15 minutes with our assessment based on the NIST Cybersecurity Framework 2.0, the international standard for cyber risk management.
106 questions · Instant report · No commitment
A complete CSIRT contact point, ready from day one
Dedicated CSIRT contact point
Incident notification
Monitoring and triage
Coordination during incidents
Documentation and reporting
Training and simulations
Why entrust the CSIRT to a specialised partner
Certified expertise
Continuous coverage
Immediate NIS2 compliance
Frequently asked questions about outsourced CSIRT
Answers to the most common questions about the outsourced CSIRT contact point service for NIS2 compliance.
The CSIRT contact point is the person designated by the organisation to manage cybersecurity incidents and handle mandatory notifications to the ACN (Italian National Cybersecurity Agency) and CSIRT Italia. The NIS2 Directive (Directive (EU) 2022/2555) requires essential and important entities to have an operational and reachable CSIRT contact point capable of managing notifications within the timeframes set by the regulation.
NIS2 requires three notification phases: pre-notification within 24 hours of discovering the incident, formal notification with technical details within 72 hours, and a complete final report within 1 month of the incident. Failure to comply with these timeframes can result in fines of up to 10 million euros or 2% of global turnover.
Yes. The regulation allows organisations to entrust the CSIRT contact point role to a qualified external provider, provided that availability, technical competence and the ability to manage notifications within the required timeframes are guaranteed. Outsourcing is a common choice for companies that lack specialised internal incident response resources.
During an incident, our CSIRT contact point immediately activates the response protocol: classifies the incident, coordinates activities with the client's IT team, manages communications with ACN/CSIRT Italia and produces the required documentation. We operate as an extension of the client's team, ensuring response times compliant with NIS2.
All companies classified as essential or important entities under NIS2 must have a CSIRT contact point: energy, transport, healthcare, digital infrastructure, public administration, manufacturing, food and other critical sectors. SMEs in the supply chain of these sectors may also be affected.
AtWorkStudio is certified ISO/IEC 27001, 27017, 27018 and ISO 9001. We are members of Clusit (Italian Association for Information Security) and Confindustria Piacenza. Our certifications cover information security management, cloud security and process quality — essential requirements for a reliable CSIRT contact point.
NIS2 compliance without compromise: your CSIRT, managed by us
Contact us to activate the outsourced CSIRT contact point service. We guarantee NIS2 compliance from day one, with certified expertise and continuous coverage.