System monitoring
Wazuh collects logs from servers, workstations and the cloud, detecting events and configuration issues.
Wazuh + OpenProject at a fixed monthly subscription, hosted on our servers in Poland.
Wazuh collects logs from servers, workstations and the cloud, detecting events and configuration issues.
Every alert becomes an OpenProject task with an owner and a deadline.
See who is responsible and what is overdue. The legislation requires management to exercise this oversight.
A record of actions and decisions ready for audits and CSIRT notifications.
A policy on paper is not enough. Inspectors ask for evidence that systems and incident handling work. Security management system implementation: by 3 April 2027. Entry in the register of entities: by 3 October 2026.
Monitoring, incident response, accountable people, deadlines, reports and a record of what happened, who acted and when.
Fines of up to EUR 10 million or 2% of turnover for essential entities, up to EUR 7 million or 1.4% for important entities, and personal accountability for management.
We collect alerts, assign tasks and maintain an audit trail of actions.
NIS2 covers 18 economic sectors. As a general rule, thresholds start at approximately 50 employees and EUR 10 million in turnover; IT and security service providers may be covered from approximately 10 employees.
Saying “we have procedures” is not enough. Inspectors ask what was done and when.
The system detects an event.
24 hours — early warningA task gets an owner and a deadline.
72 hours — incident notificationActions and decisions are recorded.
1 month — final reportWazuh + OpenProject tracks these three deadlines and records what was done.
From detecting an event to a record that stands up to an audit.
Wazuh collects logs and detects issues.
OpenProject creates a task, an owner and a deadline.
The team responds and decisions are recorded.
A report ready for audits and CSIRT notifications.
Wazuh (GPLv2) and OpenProject (GPLv3) have no licence fees. Billing is fixed monthly, regardless of log volume.
Measure letters refer to Directive (EU) 2022/2555.
| 01 | Incident handling — (b) | Wazuh: log analysis + Active Response |
| 02 | Vulnerabilities — (e) | Wazuh: Vulnerability Detector (CVE) |
| 03 | Risk and cryptography — (a), (h) | Wazuh: SCA — configuration and TLS auditing |
| 04 | Access control — (i) | Wazuh: FIM who-data — who changed what |
| 05 | Deadlines, tasks and evidence | OpenProject: task owners and history |
Together, 8 of the 10 Article 21 measures. Supply chain management and training remain the client’s processes; we provide the technical data to support them.
One report that management, IT and inspectors can understand.
| 01 | What happened? | alert, time, system |
| 02 | Who was responsible? | task owner |
| 03 | What was done? | record of actions and decisions |
| 04 | What is the status? | open, in progress, closed |
| 05 | How do we prevent a recurrence? | remediation, checks, lessons learned |
These five answers are often missing during an audit. Our report is built from task histories, without collecting data manually.
First we deploy the core on a few systems, then add more sources.
A few systems, basic alerts and the first report.
Alert thresholds, responsibilities, deadlines and reports.
More data sources and complete NIS2 documentation.
The pilot shows real progress, without committing to a full rollout or investing in hardware on your side.
The solution runs on NIS2SOFT servers in Poland. Logs stay in the country. We take care of maintenance, updates and rule tuning.
The next step is a free assessment of your entity and a pilot plan.
Book a call with NIS2SOFT