The CTO’s Infrastructure Debt: When Technical Decisions Become Regulatory Exposure

Part 3 of the NIS2 Compliance Series by Garzon Cyber Solutions. Part 1 looked at the board. Part 2 was the CISO. This one is for the person whose architecture the regulator is about to scrutinise.
Part 1 dealt with governance exposure at the board level. Part 2 covered the CISO’s operational burden. But when an auditor walks in and starts pulling at threads, the threads lead to infrastructure. And infrastructure is the CTO’s domain.
“CTO” does not appear anywhere in the NIS2 directive. It does not need to. Every technical requirement, from monitoring through to cryptography, traces back to architecture choices somebody made, or chose not to make, years ago. The budget got allocated elsewhere. The migration slipped another quarter. The workaround became permanent. These are familiar stories in every technology function across Europe.
What has changed is that a regulator now prices that backlog in euros.
The Monitoring Question Nobody Wants to Answer
There is one question that separates CTOs who are ready from those who are not. If a breach happens at 2 am on a Saturday, does your tooling detect it before your customers do?
We asked a CTO at a listed German industrial group earlier this year. Roughly 3,000 employees, a hybrid estate, two on-premise data centres alongside a growing Azure footprint. He could not give a confident yes. His cloud workloads were well instrumented. His legacy estate was not. The SIEM rollout had stalled eighteen months prior. Alert fatigue had driven his security team to ignore most of what the tooling did produce.
That pattern repeats everywhere. IBM’s 2024 Cost of a Data Breach Report found that the average time to identify a breach globally remains 194 days. Organisations with mature security monitoring cut that figure nearly in half. The directive expects continuous monitoring, centralised tamper-proof logging, and automated detection. Over the past 15 years, CTO budget requests have asked for exactly the same things. The difference is that the CFO can no longer say no. The regulator has removed the optionality.
The Shared Responsibility Blind Spot
One misconception persists in boardrooms regardless of sector or geography: “We moved to the cloud, so we are covered.”
Cloud providers are responsible for their platform. Configuration, identity management, access policy, data classification, encryption standards: all of that remains with the customer. Gartner projects that through 2027, 99% of cloud security failures will be the customer’s fault. NIS2 is explicit. MFA across the board. No standing wildcard permissions. Credentials removed from code repositories and compute layers. Segmentation that would actually contain an attacker, not just satisfy a diagram.
In one assessment this year, we found an IAM configuration error that had been live since January. A security group left open from a developer test eight months earlier. An unencrypted storage bucket from a decommissioned proof-of-concept that nobody recalled existed. The Cloud Security Alliance’s 2024 State of Cloud Security report identifies misconfiguration as the leading cause of cloud breaches for the fourth consecutive year. None of these was unusual findings. What has changed is the regulatory weight. Each now constitutes a citable compliance failure, and the citation is issued against the customer organisation, not the cloud vendor.
Access Control: The Consistent Worst Performer
Every CTO assessment we conduct surfaces the same weakness. Access governance is, without exception, the most neglected area in enterprise infrastructure.
Verizon’s 2024 Data Breach Investigations Report attributed 31% of all breaches over the past decade to stolen credentials. The Ponemon Institute’s 2024 Cost of Insider Threats study puts the average annual cost of credential misuse at $4.1 million per organisation. These are not obscure findings. They are the most-cited statistics in the industry, yet the controls remain absent.
A typical finding: service accounts carrying domain administrator privileges that have not been reviewed since 2021. The person who provisioned them left the company two years ago. Role-based access control is thoroughly documented in SharePoint, but technically enforced nowhere. Joiner provisioning is functioning correctly. Mover-and-leaver processes were abandoned, and the last update to the tracking spreadsheet was over a year ago.
Article 21 expects documented policies, technical enforcement, exception logging, and evidence of regular review. That is four layers of rigour applied to the single area where most organisations have the least. When the regulator asks, and they do ask in exactly that sequence, most cannot answer past the second question. CTOs have been aware of this for years. The budget conversation changes when the consequence is €10 million in fines and personal liability for directors.

What Changed: The Regulator Priced the Backlog
Technical debt has always existed. Deferred patching cycles, identity sprawl across acquisitions, and network documentation that stopped being current years ago. Engineering teams have pitched remediation annually, framed it as risk reduction, and presented heat maps. And annually, it lost to whatever carried a revenue figure.
Essential entities now face fines of up to €10 million or 2% of global annual turnover. Important entities face €7 million or 1.4%. Individual managers can be held personally liable for governance negligence. ENISA’s 2025 NIS Investments Report found that 42% of in-scope organisations had not increased their cybersecurity budgets since the directive was adopted in 2022. That figure alone tells you how many are about to receive a difficult audit finding.
The remediation roadmap already exists in most technology functions. It has sat in a slide deck or a deprioritised Jira backlog, waiting for the authority to proceed. NIS2 is that authority. “We would like to modernise” competes with every other budget line. “The regulator requires this, and the board carries personal exposure” does not compete. It closes the discussion.
What Regulators Are Asking Right Now
A compliance officer we spoke with in the Netherlands described her regulatory engagement as “polite but unforgiving.” The auditors arrived with a structured checklist. They asked about monitoring coverage. They tested log centralisation and tamper resistance. They walked through access control from policy to technical enforcement to audit trail. They checked the asset register against the risk framework. They stress-tested incident response against the 24-hour and 72-hour notification windows.
Germany and France are conducting comparable exercises. The Commission’s Implementing Regulation (EU) 2024/2690 sets out the specific technical and methodological requirements that competent authorities are now auditing against. The standard is documentation, not intention. If you cannot produce the paperwork, the finding is non-compliance.
Closing the Gap
Garzon Cyber Solutions works alongside CTOs and technology leaders to close the distance between current infrastructure and regulatory expectations.
Cybersecurity Advisory. Architecture review, monitoring strategy, and incident readiness. We establish what is in place, measure it against NIS2, and build a remediation programme that the board will fund.
Compliance and Regulatory Readiness. Translating regulatory obligations into infrastructure specifications that engineers can build to. NIS2, DORA, the EU AI Act, ISO 27001, SOC 2.
Security and Technology Talent. Security architects, cloud engineers, DevSecOps leads, and IAM specialists. We place the people the programme needs. We understand the brief because we advise the organisations doing the work.
Technical debt was always a risk. NIS2 made it a regulated one. The CTOs who move now will pass the audit. The rest will spend time explaining to the board why the regulator found what the engineering team had been raising for years.
Sources: NIS2 Directive (EU) 2022/2555, Article 21. Commission Implementing Regulation (EU) 2024/2690. IBM, Cost of a Data Breach Report, 2024. Verizon, Data Breach Investigations Report, 2024. Ponemon Institute, Cost of Insider Threats Global Report, 2024. Cloud Security Alliance, State of Cloud Security Report, 2024. Gartner, Cloud Security Forecast, 2024. ENISA, NIS Investments Report, 2025.
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →