NIS2Art. 21(2)(b)voice-validated
NIS2 Art21b: Art. 21(2)(b)
Network and Information Security Directive 2 (EU 2022/2555)
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Essential and important entities must implement incident handling measures, covering detection, analysis, containment, eradication, recovery, and post-incident review of network and information system security events. Incident handling procedures must be tested and validated.
ATT&CK techniques this article tests · 15
| Technique | Why it maps | Confidence |
|---|---|---|
| T1078 | 1. Incident handling measures, including detection and analysis, directly address the compromise of valid accounts. NIS2 Art. 21(2)(b) mandates these measures for security events involving network and information systems. | 90% |
| T1133 | 1. Detection and containment of unauthorized external remote service access are core components of incident handling. NIS2 Art. 21(2)(b) requires entities to implement measures for such security events. | 80% |
| T1059 | 1. Malicious command and scripting interpreter use necessitates robust detection, analysis, and eradication capabilities. NIS2 Art. 21(2)(b) explicitly covers these incident handling phases for security events. | 90% |
| T1053 | 1. Unauthorized scheduled tasks represent a persistence mechanism requiring detection, analysis, and eradication. NIS2 Art. 21(2)(b) mandates incident handling for such security events. | 80% |
| T1055 | 1. Process injection, a privilege escalation technique, demands immediate detection and containment. NIS2 Art. 21(2)(b) requires incident handling measures for security events. | 80% |
| T1027 | 1. Detection and analysis of obfuscated files are critical for identifying defense evasion. NIS2 Art. 21(2)(b) requires incident handling to cover detection and analysis of security events. | 70% |
| T1036 | 1. Identifying masquerading techniques requires thorough analysis during incident handling. NIS2 Art. 21(2)(b) mandates analysis as part of incident handling measures for security events. | 70% |
| T1003 | 1. OS credential dumping is a critical security event requiring detection, containment, and eradication. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events. | 90% |
| T1087 | 1. Account discovery by adversaries is a precursor to further compromise, requiring detection and analysis. NIS2 Art. 21(2)(b) includes detection and analysis in incident handling measures. | 80% |
| T1046 | 1. Network service scanning, if malicious, must be detected and analyzed as a security event. NIS2 Art. 21(2)(b) requires incident handling to cover detection and analysis. | 70% |
| T1021 | 1. Unauthorized use of remote services for lateral movement requires detection, containment, and eradication. NIS2 Art. 21(2)(b) mandates these incident handling phases for security events. | 80% |
| T1005 | 1. Unauthorized data collection from local systems is a clear security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling. | 90% |
| T1071 | 1. Command and control communications using application layer protocols must be detected and contained. NIS2 Art. 21(2)(b) requires incident handling measures for such security events. | 80% |
| T1041 | 1. Exfiltration over C2 channels is a critical security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events. | 90% |
| T1047 | 1. Malicious use of Windows Management Instrumentation for impact or control requires detection, analysis, and eradication. NIS2 Art. 21(2)(b) mandates incident handling for security events. | 80% |
Defending mitigations · 7
| Mitigation | What it does | Confidence |
|---|---|---|
| M1013 | 1. Effective event log management is fundamental for detection, analysis, and post-incident review. NIS2 Art. 21(2)(b) explicitly mandates these phases of incident handling. | 100% |
| M1015 | 1. Secure software configuration reduces attack surfaces, aiding in containment and eradication. NIS2 Art. 21(2)(b) requires measures for containment and eradication of security events. | 90% |
| M1031 | 1. Network segmentation is a primary control for containing incidents and limiting lateral movement. NIS2 Art. 21(2)(b) mandates containment as a key incident handling measure. | 100% |
| M1047 | 1. Robust auditing mechanisms are essential for detection, analysis, and post-incident review. NIS2 Art. 21(2)(b) explicitly requires these elements within incident handling. | 100% |
| M1035 | 1. Limiting network access to resources helps prevent and contain security incidents. NIS2 Art. 21(2)(b) mandates containment as part of incident handling measures. | 90% |
| M1040 | 1. Antivirus/antimalware solutions are crucial for detecting and eradicating malicious software. NIS2 Art. 21(2)(b) requires detection and eradication capabilities in incident handling. | 90% |
| M1051 | 1. Regular software updates reduce vulnerabilities, aiding recovery and preventing future incidents. NIS2 Art. 21(2)(b) includes recovery and post-incident review in its incident handling requirements. | 80% |
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-798 | 1. Hard-coded credentials are a common root cause for initial access, requiring robust incident handling for detection and eradication. NIS2 Art. 21(2)(b) addresses security events stemming from such weaknesses. | 90% |
| CWE-287 | 1. Improper authentication leads to unauthorized access, necessitating incident detection, analysis, and containment. NIS2 Art. 21(2)(b) mandates incident handling for security events. | 90% |
| CWE-78 | 1. OS command injection vulnerabilities enable execution of arbitrary commands, requiring incident handling for detection and eradication. NIS2 Art. 21(2)(b) covers such security events. | 80% |
| CWE-200 | 1. Exposure of sensitive information is a critical security event requiring detection, containment, and recovery. NIS2 Art. 21(2)(b) mandates comprehensive incident handling for such events. | 90% |
| CWE-269 | 1. Improper privilege management allows privilege escalation, necessitating incident detection, analysis, and eradication. NIS2 Art. 21(2)(b) requires incident handling for security events. | 80% |
| CWE-502 | 1. Deserialization of untrusted data can lead to remote code execution, requiring incident detection and eradication. NIS2 Art. 21(2)(b) mandates incident handling for security events. | 70% |
| CWE-434 | 1. Unrestricted file uploads can lead to initial access and execution, requiring incident detection and eradication. NIS2 Art. 21(2)(b) covers security events stemming from such vulnerabilities. | 70% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0196 compute · voice-rubric self-validated