Insights
Notes from the coast
Short, concrete notes on NIS2, the Digital Security Act, and digital security in Norwegian maritime and coastal industry. Written for the people who run the business, not for security teams.
The 24-hour rule: what happens when a cyber incident hits
NIS2 gives you 24 hours to warn, 72 to report, and one month for the final report. Here is what the clock actually means for a maritime company, and why the prepared never start from a blank page.
Read →Why maritime companies can’t use American compliance tools
Generic, English-only, and storing data abroad. Here is why American compliance software fits Norwegian maritime companies poorly, and what data sovereignty actually means in practice.
Read →What the April 2025 dam hack should teach the maritime industry
A small Norwegian dam had a valve opened remotely for about four hours. Nobody needed to be clever. Here is why connected equipment across the maritime industry, ferry, port, or farm, is an easier target than you think, and what to check first.
Read →A plain readiness checklist for Digitalsikkerhetsloven and NIS2
No jargon, no scare tactics. A short list you can walk through this week to see roughly where your company stands, whether it is a vessel, a terminal, or a site, before a regulator, an insurer, or an opportunist does.
Read →