Securing network and information systems.
And proving that you do.
The NIS2 Directive establishes a unified legal framework to uphold cybersecurity across 18 critical sectors in the EU. It requires you to manage the risk to your network and information systems — and, months later, to show an auditor that you did. TotulDigital collects the traces your systems already produce, checks them daily against the numbered requirements of the Directive's implementing regulation, and writes the record you hand over.
How TotulDigital turns activity into immutable evidence.
Everything digital leaves a trace. We collect the traces, place them on a unified cryptographic timeline, cross-reference them against live threat intelligence, and deliver two definitive outcomes: immediate warning if something is wrong, and verifiable proof that it is not.
Strict read-only ingestion. Connectors with write scopes are instantly rejected.
Article 23 compliant incident warning clock initiates upon awareness.
Cryptographic append-only ledger sealed daily against tampering.
Zero CLOUD Act liability. All nodes held in audited EU member states.
The Six Stages of Evidence Conversion
From unorganized operational exhaust to deterministic, courtroom-grade compliance proof under CIR (EU) 2024/2690.
Collection
Your systems already write down what they do: who signed in and from where, which file was opened, what the firewall let through, what changed on a server. Those records are logs. We ingest the logs—the traces of the activity—using strict read-only connectors. Any credential returned with write permission is rejected at connection time rather than retained.
Correlation
One record on its own means very little. The same account signing in from two countries twenty minutes apart means a great deal. Records from every source merge onto a single timeline, so what they mean together becomes visible—which no single system can see, because each one only holds its own half of the story.
Enrichment
What is happening in your environment is then compared against what is known to be happening everywhere else: addresses being used in attacks this week, domains registered days ago, file signatures from live campaigns. An EU-hosted or on-premises language model explains findings in human operational terms with zero data egress.
Triage
Not everything unusual is wrong. A backup job reads thousands of files at night; an administrator signs in from a hotel abroad. Every signal is weighed for what it would actually cost you, the ones with an ordinary explanation are set aside, and what remains reaches a person in the order it deserves without fatigue.
Detection
A break-in already under way, an account taken over, malicious software running, data leaving where it should not. You are told immediately and not in tomorrow's report, because Article 23 counts from the moment you become aware and gives you twenty-four hours to issue an initial warning notification.
Measurement
The same material, read a second way. Every signal is attached to a numbered control of CIR (EU) 2024/2690 and becomes evidence: what you can prove, what you cannot, what was found and whether it was fixed. One report every morning, and a record that does not depend on anyone remembering to write it.
The Whole Loop, End to End
Where the evidence comes from, how the pipeline processes it, and who takes action. The boundary on the right is the product definition: we measure, your people change things.
Read-only ingestion from SaaS (M365, Google Workspace), Cloud platforms (AWS, Azure), on-premises infrastructure, firewalls, and host endpoints. Zero internal data egress.
Automated correlation across disparate timelines, localized AI enrichment, impact triage, CIR (EU) 2024/2690 control mapping, and append-only ledger sealing.
Remediation is carried out exclusively by your team or designated managed provider. TotulDigital holds zero write access; the subsequent collection cycle independently verifies the fix.
We collect the traces, never the content.
This distinction is the cornerstone of our architecture. A log records that a document was opened, by whom, from where, and at what timestamp. It never contains the document itself. We never read your email, inspect your files, or store customer records. What we preserve is the auditable trace of activity—which is precisely what a National Competent Authority auditor requests.
What TotulDigital does not do.
We do not remediate, and deliberately cannot. No connector holds write access. No firewall rules are modified, no accounts are disabled, and no files are moved by our platform. All operational remediations are executed by your administrators or managed IT partners. The subsequent collection sweep verifies whether the remediation resolved the finding.
If you would rather it were done for you.
TotulDigital tells you what is wrong and proves it was fixed. When organizations lack internal capacity, our certified sovereign IT operations partners execute end-to-end remediation under strict approval control.
What it takes on
Whole operations rather than isolated tasks: tickets, incidents, patch deployment, and change management on the IT side; triage and escalation on the security side. A finding TotulDigital raises becomes an accountable case with an owner, a clear plan, and a verifiable closure date.
Who signs
Nothing with consequence runs unsigned. Anything touching a production system escalates to an authorized person on your side. No credential or access policy changes without explicit authorization, leaving an unalterable log for your auditor.
Where it runs
Single-tenant by default. On TotulDigital sovereign bare-metal infrastructure, within your private sovereign cloud, or on your isolated air-gapped hardware with zero internet egress. Compute, models, and ledgers remain entirely under your territorial jurisdiction.
What It Reads
Sources are added one at a time, and each connector explicitly states which numbered CIR (EU) 2024/2690 controls it advances. A source that advances none is not offered.
| Source & Scope | CIR (EU) 2024/2690 Control | Status |
|---|---|---|
|
cloud
Microsoft 365 & Entra ID
Sign-ins, MFA states, administrative privilege changes, external file sharing
|
Pt 11.2, Pt 11.7 | Available |
|
domain
Google Workspace
Sign-ins, account activity, Drive DLP events, and organizational sharing
|
Pt 11.2, Pt 11.3 | Available |
|
dns
Linux, Windows & macOS Hosts
File integrity monitoring (FIM), system configuration audit, CVE vulnerability scans
|
Pt 6.9, Pt 6.10, Pt 12.4 | Available |
|
laptop_mac
Workstations & Laptops
Disk encryption status, local administrator escalation, patch compliance
|
Pt 11.3, Pt 11.7 | Available |
|
router
Firewalls & Network Infrastructure
Fortinet, Palo Alto, Cisco, Sophos, SonicWall, pfSense, MikroTik, OPNsense
|
Pt 6.7, Pt 6.8 | Available |
|
cloud_queue
Public Cloud Platforms
Amazon Web Services (CloudTrail), Microsoft Azure Monitor, Google Cloud Audit
|
Pt 3.2, Pt 3.4 | Available |
|
badge
Identity & Access Providers
Authentik, Keycloak, Okta, Ping Identity, FreeIPA
|
Pt 11.3, Pt 11.6, Pt 11.7 | Available |
|
backup
Virtualization & Backup Systems
Proxmox PBS, VMware vCenter, Veeam with air-gap verification checks
|
Pt 10.1 | Available |
|
developer_board
Container Platforms & Orchestration
Kubernetes audit logs, Docker socket events, Podman systemd services
|
Pt 12.4 | Available |
|
sync_alt
Aggregated SIEM & Plain Syslog
Splunk, Elastic, Graylog, or generic RFC 3164/5424 collectors
|
Pt 3.2 | Available |
Which of these you actually need depends on what you run.
Describe your environment and you will receive a written sovereign attestation statement detailing the controls it would evidence, and the ones it would not.
The 18 Sectors in Scope
The obligations do not change by sector; the systems that evidence them do. Size and operational tier together determine whether an entity is Essential or Important under Directive (EU) 2022/2555.
Sectors of High Criticality (11)
Other Critical Sectors (7)
Being secure and proving it are two different jobs.
Think of the fire extinguishers in your building. Having them is not enough. Someone signs a sheet every month to say they were checked, and that sheet is what an inspector asks for. Security now works the same way. The law does not only ask whether you are watching — it asks you to produce the record. Most organisations are doing far more than they can show.
- check_circle Generated every single morning
- check_circle Tied line-by-line to CIR 2024/2690
- check_circle Records open, closed, & recurring findings
100% Read-Only Access
TotulDigital connectors request read scopes exclusively. A credential returned with write permission is rejected at connection time rather than retained. We inspect without the power to alter.
Self-Hosted or EU Managed
Identical software, deployed directly into your own enterprise network or operated in our sovereign European Datacenters (planned EU regions). Zero US CLOUD Act exposure.
Remediation Verification
Each finding includes a structured remediation plan executed by your administrators. Subsequent automated collections record the outcome as verified closed, unresolved, or recurring.
This is what arrives each morning.
One page. The number on the left is the legal control each line answers; your team does not need to memorize it, but the NIS2 national auditor (e.g., DNSC, the German federal cyber authority, ANSSI) will verify against it.
| Annex Point | CIR 2024/2690 Requirement | Cryptographic Observation | Telemetry Status |
|---|---|---|---|
| Point 11.2 | Management of access rights | A sharing link created in March remains active on a document restricted on 28 August. Retrievable by any holder without authentication. | Recurring (closed 2 Sep) |
| Point 6.7 | Network security | A firewall rule permits inbound connections from any external IP address directly to the internal finance database server. | Open |
| Point 3.4 | Event assessment and classification | A workstation sent 4.2 GB of data to an unrecognized autonomous system between 01:00 and 04:00 UTC. | Open |
| Point 11.7 | Multi-factor authentication | Four accounts with domain administrative privileges authenticate with single-factor password only. | Open (rec 14 Sep) |
| Point 11.3 | Privileged accounts | The superuser administrator credential for the core HR ERP platform is concurrent and shared by 2 operators. | Open |
| Point 6.8 | Network segmentation | General workstation VLAN has direct IP route to hypervisor management cluster without micro-segmentation. | Open |
| Point 12.4 | Asset inventory | Three rogue Linux servers discovered transmitting telemetry on secondary subnet; absent from approved CMDB. | Open |
| Point 11.5 | Identification | Shared finance mailbox signs in via generic service account with non-attributable authorization. | Open |
| Point 3.2 | Monitoring and logging | Application server stopped syslog stream at 02:14 UTC. Resumed 14 hours later following agent restart. | Verified closed |
| Point 6.9 | Malicious software | Quarantined ransomware dropper signature on accounting endpoint; hash revoked across cluster fleet. | Verified closed |
| Point 10.3 | Termination procedures | HR termination date was recorded as 18 August; credentials stayed active for 31 days. Session revoked 19 Sep. | Verified closed |
| Point 6.10 | Vulnerability handling | Three critical CVEs on perimeter reverse proxy patched; verification scan confirmed complete mitigation. | Verified closed |
Who outside your organisation can open your files.
Every file and folder reachable from outside, sorted by how far it reaches. The worst kind is a link that needs no sign-in at all: anyone who has the address can open the file, nobody is recorded as having done so, and it keeps working even after you think you have locked the file down.
- folder Finance & Auditing
- folder HR & Personnel Records
- folder Board Minutes & Governance
- folder Project Engineering Archive
- folder Shared Corporate Storage
And everywhere else your enterprise stores unstructured data.
Which controls a real environment evidenced.
One page out of the same report. Approximately one-third of the numbered controls in CIR (EU) 2024/2690 are evidenced by telemetry. The remainder are reported as open documentary items. Coverage claims that exceed what a monitoring system can observe do not survive an audit.
| Legal Ref | CIR 2024/2690 Control Name | Automated Detections | Evidenced in Audit Record |
|---|---|---|---|
| 11.6 | Authentication | 302 | check_circle Yes |
| 3.2 | Monitoring and logging | 167 | check_circle Yes |
| 6.9 | Protection against malicious and unauthorised software | 155 | check_circle Yes |
| 11.2 | Management of access rights | 140 | check_circle Yes |
| 3.4 | Event assessment and classification | 135 | check_circle Yes |
| 6.7 | Network security | 70 | check_circle Yes |
| 11.3 | Privileged accounts and system administration accounts | 30 | info Partial |
| 11.7 | Multi-factor authentication | 2 | Requires an identity source |
Find out where you stand.
Tell us what your organisation runs — five lines is enough — and we will tell you which parts of the law you could prove today and which you could not. Written, transparent, and no sales call required.
Legal Texts
Every figure, deadline, and title is quoted verbatim from official EU texts:
- Directive (EU) 2022/2555 (NIS2) arrow_forward
- CIR (EU) 2024/2690 Technical Annex arrow_forward
- ENISA Implementation Guidance arrow_forward