ERP System Resilience: Sovereignty and NIS2 Risk Mitigation

ERP System Resilience: Sovereignty and NIS2 Risk Mitigation

Why ERP security NIS2 compliance is now a board-level issue

For most European SMBs, the ERP system is the business. Orders, invoices, inventory, payroll, production schedules, customer records: all of it lives in one place. Yet ERP security NIS2 obligations are still treated by many Italian and EU companies as an IT department problem, something to delegate to whoever manages the servers. The NIS2 directive closes that escape route.

NIS2 (Directive EU 2022/2555, transposed in Italy through Legislative Decree 138/2024) reframes cybersecurity as a governance duty. Management bodies must approve risk-management measures, oversee their implementation, and can be held personally accountable for failures. Article 20 is explicit: directors and senior managers are required to follow cybersecurity training and ensure their staff do the same.

The practical consequence is simple. If your ERP goes down for a week and you cannot demonstrate that you assessed the risk, documented the controls, and tested recovery, the problem is no longer just lost revenue. It becomes a compliance failure with fines that can reach 10 million euros or 2% of global annual turnover for essential entities, and 7 million euros or 1.4% for important entities.

Who is actually in scope

A common misconception is that NIS2 only touches large infrastructure operators. In reality the directive covers medium and large entities (50+ employees or more than 10 million euros in turnover) across 18 sectors, including manufacturing, food production, waste management, postal services, chemicals, digital providers, and public administration.

Italy’s implementation registered well over 20,000 entities in the first notification cycle through ACN (Agenzia per la Cybersicurezza Nazionale), a figure far higher than early estimates. Many of those organisations are family-run manufacturers in Lombardy, Veneto, and Emilia-Romagna with lean IT teams and an ERP installed a decade ago.

Even companies formally out of scope feel the pressure. NIS2 requires in-scope entities to manage supply chain risk, which means their suppliers get questionnaires, contractual security clauses, and audit requests. If you sell to a manufacturer or a utility, you will be asked about your ERP controls regardless of your headcount. Our overview of NIS2 requirements and compliance steps breaks down how to determine your position.

Business continuity for ERP systems: the hardest requirement to fake

Article 21 of NIS2 lists the minimum measures entities must adopt. Among them: incident handling, business continuity including backup management and disaster recovery, crisis management, supply chain security, vulnerability handling, encryption, access control, and multi-factor authentication.

Business continuity for ERP systems is where most SMBs discover uncomfortable gaps. Backups exist, usually. Tested restores do not. According to industry research, roughly one in three organisations that attempt a restore from backup during a real incident fail on the first try, and ransomware groups now actively target backup repositories before encrypting production systems.

What a defensible continuity plan looks like

Start with two numbers the board must approve, not IT: your Recovery Time Objective (how many hours without the ERP your business can survive) and your Recovery Point Objective (how much data you can afford to lose). For a manufacturer running just-in-time production, an RTO of 48 hours may mean missed contractual penalties. Write the numbers down, because an auditor will ask.

Then build toward them. That means immutable or air-gapped backup copies that ransomware cannot encrypt, documented restore procedures that someone other than the ERP consultant can execute, and at least one full restore test per year with the results recorded. A restore test that nobody documented did not happen as far as compliance is concerned.

Finally, plan for the degraded mode. If the ERP is unavailable for 24 hours, how do you ship goods, take orders, and pay people? Paper fallback procedures sound archaic until the alternative is a complete production stop. A well-structured help desk and managed support service is often what turns a written plan into a response that actually works at 3 a.m. on a Sunday.

Patching the system nobody wants to touch

ERP platforms are notoriously hard to patch. Custom modules, legacy integrations, and the fear of breaking month-end closing lead to systems running years behind on updates. Vulnerability handling is a named NIS2 obligation, so “we cannot patch because of customisations” is not a defence.

The workable path is a documented vulnerability management cycle: an inventory of ERP components and their versions, a feed of relevant advisories, a risk-based prioritisation, a test environment, and a scheduled maintenance window. Where patching genuinely cannot happen, compensating controls (network segmentation, strict access control, enhanced monitoring) must be documented as a deliberate risk decision approved at management level.

Digital sovereignty for business data: beyond the buzzword

Most SMB ERP deployments now involve cloud components, whether a full SaaS platform, a hosted database, or a hybrid setup with cloud analytics. That raises questions NIS2 does not answer directly but auditors increasingly ask: where is the data stored, who can access it, and under which legal jurisdiction?

Digital sovereignty for business data is not nationalism dressed as IT policy. It is a concrete risk assessment. A non-EU cloud provider may be subject to extraterritorial disclosure laws such as the US CLOUD Act, which can compel access to data regardless of where the servers physically sit. For a company handling industrial designs, pricing strategies, or sensitive personal data, that is a genuine exposure to document.

Practical questions to put to your ERP vendor

Ask for the location of primary and backup data centres, in writing. Ask who holds the encryption keys: if the provider holds them, they can technically read your data. Ask about subprocessors, because your ERP vendor’s support partner in a third country is part of your supply chain whether you knew it or not.

Ask what happens at the end of the contract. Data portability and exit clauses matter enormously when a vendor is acquired, raises prices, or suffers a breach. The EU Data Act, applicable from September 2025, strengthens switching rights for cloud customers, and ERP contracts signed before it should be reviewed against the new rules.

Finally, ask for evidence rather than reassurance. ISO 27001 certificates, SOC 2 reports, penetration test summaries, and incident notification commitments with specific timelines. NIS2 imposes a 24-hour early warning for significant incidents, so a vendor that promises to notify you “promptly” is giving you a compliance problem.

NIS2 compliance for SMEs: a realistic sequence

The gap between the directive’s text and a 60-person company’s reality is wide, but it is crossable with a sequence rather than a project.

Start with scope and governance. Determine whether you are an essential entity, an important entity, or a supplier to one, and assign a named owner at management level. Register with ACN if required and document the decision either way, because showing you assessed your position is itself evidence of diligence.

Next, map the ERP estate. List modules, integrations, interfaces, data flows, and every account with administrative rights. Most companies find orphaned accounts, shared passwords, and integrations nobody remembers authorising. Fixing those costs almost nothing and removes the most commonly exploited attack paths.

Then close the three highest-impact controls: multi-factor authentication on every remote and administrative access path, least-privilege roles in the ERP itself (the finance clerk does not need master data rights), and tested immutable backups. These three measures address the majority of real ERP incidents and are explicitly named in Article 21.

After that, formalise incident response. Who declares an incident, who notifies ACN within 24 hours, who talks to customers, who calls the lawyer. Run one tabletop exercise per year with the management team in the room, not just IT. Our cybersecurity services are designed around exactly this progression, from assessment to monitoring to incident response.

Public sector bodies and their suppliers face an additional layer, since procurement rules and AgID requirements interact with NIS2 obligations. Organisations working in that space can review our solutions for public administration for the specific controls involved.

The accountability shift nobody can delegate

The deepest change NIS2 introduces is not technical. It is the end of plausible deniability at the top. Risk-management measures must be approved by the management body, which must also supervise implementation and can face liability, including temporary bans from management functions for serious repeated failures.

For an SMB owner, that means two or three hours a year of genuine attention: reading the risk assessment, approving the RTO and RPO, signing off on the gaps you are accepting and why, and asking whether the last restore test actually worked. Documented decisions are the asset here. An auditor can accept a risk you knowingly accepted and recorded; they cannot accept one you never considered.

The companies handling this well are not the ones with the biggest budgets. They are the ones that stopped treating the ERP as infrastructure and started treating it as the operational core it has always been, with governance to match.

💬

Need support on this topic?

Let’s assess your company’s situation together. The first consultation comes with no obligation.

Contact us
📩

Stay updated every week

Cybersecurity, AI and technology for SMBs. No spam, only useful content.

Subscribe to newsletter

Content on this blog is written and reviewed by the editorial team of 10punto10 s.r.l., which holds editorial responsibility for the published content.