Industry · Aquaculture
NIS2 compliance for aquaculture
Connected fish farms are full of OT and IoT that was never meant to be exposed. Havvakt maps the exposure, builds the documentation, and prepares you for the Digital Security Act and NIS2, one site at a time.
Why is aquaculture covered?
Aquaculture is affected two ways. As a food producer, processing and distribution fall under the food sector (NIS2 Annex II), and as a supplier to critical infrastructure and large customers you face compliance requirements that cascade down. On top of that, sites are technically exposed: much OT and IoT is connected to networks without being built for it.
Industry-specific risks
OT/IoT on site
Feeding, oxygen monitoring, water flow, sea-lice dosing, sensors and SCADA, much of it older equipment connected because it was convenient.
Remote access
Remote control from shore is useful, but every access point is a door. Default passwords and flat networks are the most common weakness.
Supply chain
Site vendors, integrators and operations partners often hold broad access that is rarely documented.
Missing documentation
Security may be fine in practice, but without documentation you cannot show it to regulators, insurers, or customers.
What Havvakt delivers
- OT/IoT mapping of the site, on-site and remote.
- Evidence dossier: asset inventory, exposure map, supplier-risk register, and board-ready summary.
- Gap analysis against NSM Basic Principles, what a regulator would flag.
- Prioritized remediation plan and incident readiness, sized to your team and budget.
This is what the requirements look like for your industry. Let’s talk.
Questions from aquaculture
Do we need to replace our OT systems?
No. The first engagement maps and documents what already exists. Remediation is prioritized afterward, nothing is ripped out to get started.
Is this for small operators or large producers?
Both. We start with one site and do it thoroughly. For multiple sites we turn the one-off check into continuous compliance.
What do we actually receive?
An evidence dossier: asset inventory, exposure map, supplier-risk register, an NSM Basic Principles gap analysis, a board-ready summary, and a prioritized remediation plan.
How long does it take?
The first mapping normally takes 2–3 weeks, with baseline documentation in place within the first month.