NIS2 broadens the risk conversation

NIS2 encourages a more structured view of cybersecurity and risk governance for affected organizations. For companies in Spain, the practical question is not how to turn every requirement into another form, but how to demonstrate that risks are understood and appropriate measures are applied. The human factor belongs in that analysis because critical capabilities depend on internal and external people. Screening can be one of several possible controls where there is a clear link between role and exposure.

Risk also enters through access decisions

Granting access is a risk decision. An organization can protect a platform with advanced technical controls while giving broad privileges to employees, contractors or suppliers. It is therefore useful to connect access inventories with role classification. This does not mean claiming that NIS2 imposes universal background checks. It means asking whether people-related controls are sufficient where compromised access could materially affect continuity, data or essential services.

Not every role requires the same control

A proportionate approach avoids two errors: doing nothing because the regulation does not list every personnel control explicitly, or screening the entire workforce excessively. The alternative is to define categories such as standard, sensitive and critical roles. Each level can have different measures, from basic identity checks to additional role-related verification, always respecting purpose, necessity, local law and data protection.

Suppliers and third parties matter too

NIS2 also increases attention on the supply chain. In practice, a technology supplier may have access as sensitive as an internal employee. A Human Risk map should therefore include contractors and third parties when they operate inside the organization's digital perimeter. Companies can request reasonable evidence about supplier identity, hiring and personnel controls without assuming that a commercial contract alone manages human risk.

Prepare with a Human Risk map

Preparation means connecting three maps that are often separate: roles, access and controls. HR knows who occupies each position; the CISO knows what they can technically do; Compliance knows legal obligations and limits. Together they can identify gaps and document decisions. This exercise remains useful as the Spanish NIS2 framework evolves because it creates governance that can be adapted to regulatory change.

Want to integrate Human Risk Management into your risk model?

Validato helps organizations design modular, proportionate background checks for candidates and employees, with international reach and data governance in Switzerland and the EU. Contact us to discuss which screening level fits your higher-risk roles.