NIS2Art. 21(2)(b)voice-validated

NIS2 Art21b: Art. 21(2)(b)

Network and Information Security Directive 2 (EU 2022/2555)

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Essential and important entities must implement incident handling measures, covering detection, analysis, containment, eradication, recovery, and post-incident review of network and information system security events. Incident handling procedures must be tested and validated.

ATT&CK techniques this article tests · 15

TechniqueWhy it mapsConfidence
T10781. Incident handling measures, including detection and analysis, directly address the compromise of valid accounts. NIS2 Art. 21(2)(b) mandates these measures for security events involving network and information systems.
90%
T11331. Detection and containment of unauthorized external remote service access are core components of incident handling. NIS2 Art. 21(2)(b) requires entities to implement measures for such security events.
80%
T10591. Malicious command and scripting interpreter use necessitates robust detection, analysis, and eradication capabilities. NIS2 Art. 21(2)(b) explicitly covers these incident handling phases for security events.
90%
T10531. Unauthorized scheduled tasks represent a persistence mechanism requiring detection, analysis, and eradication. NIS2 Art. 21(2)(b) mandates incident handling for such security events.
80%
T10551. Process injection, a privilege escalation technique, demands immediate detection and containment. NIS2 Art. 21(2)(b) requires incident handling measures for security events.
80%
T10271. Detection and analysis of obfuscated files are critical for identifying defense evasion. NIS2 Art. 21(2)(b) requires incident handling to cover detection and analysis of security events.
70%
T10361. Identifying masquerading techniques requires thorough analysis during incident handling. NIS2 Art. 21(2)(b) mandates analysis as part of incident handling measures for security events.
70%
T10031. OS credential dumping is a critical security event requiring detection, containment, and eradication. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events.
90%
T10871. Account discovery by adversaries is a precursor to further compromise, requiring detection and analysis. NIS2 Art. 21(2)(b) includes detection and analysis in incident handling measures.
80%
T10461. Network service scanning, if malicious, must be detected and analyzed as a security event. NIS2 Art. 21(2)(b) requires incident handling to cover detection and analysis.
70%
T10211. Unauthorized use of remote services for lateral movement requires detection, containment, and eradication. NIS2 Art. 21(2)(b) mandates these incident handling phases for security events.
80%
T10051. Unauthorized data collection from local systems is a clear security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling.
90%
T10711. Command and control communications using application layer protocols must be detected and contained. NIS2 Art. 21(2)(b) requires incident handling measures for such security events.
80%
T10411. Exfiltration over C2 channels is a critical security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events.
90%
T10471. Malicious use of Windows Management Instrumentation for impact or control requires detection, analysis, and eradication. NIS2 Art. 21(2)(b) mandates incident handling for security events.
80%

Defending mitigations · 7

MitigationWhat it doesConfidence
M10131. Effective event log management is fundamental for detection, analysis, and post-incident review. NIS2 Art. 21(2)(b) explicitly mandates these phases of incident handling.
100%
M10151. Secure software configuration reduces attack surfaces, aiding in containment and eradication. NIS2 Art. 21(2)(b) requires measures for containment and eradication of security events.
90%
M10311. Network segmentation is a primary control for containing incidents and limiting lateral movement. NIS2 Art. 21(2)(b) mandates containment as a key incident handling measure.
100%
M10471. Robust auditing mechanisms are essential for detection, analysis, and post-incident review. NIS2 Art. 21(2)(b) explicitly requires these elements within incident handling.
100%
M10351. Limiting network access to resources helps prevent and contain security incidents. NIS2 Art. 21(2)(b) mandates containment as part of incident handling measures.
90%
M10401. Antivirus/antimalware solutions are crucial for detecting and eradicating malicious software. NIS2 Art. 21(2)(b) requires detection and eradication capabilities in incident handling.
90%
M10511. Regular software updates reduce vulnerabilities, aiding recovery and preventing future incidents. NIS2 Art. 21(2)(b) includes recovery and post-incident review in its incident handling requirements.
80%

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-7981. Hard-coded credentials are a common root cause for initial access, requiring robust incident handling for detection and eradication. NIS2 Art. 21(2)(b) addresses security events stemming from such weaknesses.
90%
CWE-2871. Improper authentication leads to unauthorized access, necessitating incident detection, analysis, and containment. NIS2 Art. 21(2)(b) mandates incident handling for security events.
90%
CWE-781. OS command injection vulnerabilities enable execution of arbitrary commands, requiring incident handling for detection and eradication. NIS2 Art. 21(2)(b) covers such security events.
80%
CWE-2001. Exposure of sensitive information is a critical security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events.
90%
CWE-2691. Improper privilege management allows privilege escalation, necessitating incident detection, analysis, and eradication. NIS2 Art. 21(2)(b) requires incident handling for security events.
80%
CWE-5021. Deserialization of untrusted data can lead to remote code execution, requiring incident detection and eradication. NIS2 Art. 21(2)(b) mandates incident handling for security events.
70%
CWE-4341. Unrestricted file uploads can lead to initial access and execution, requiring incident detection and eradication. NIS2 Art. 21(2)(b) covers security events stemming from such vulnerabilities.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0196 compute · voice-rubric self-validated