LK Goslar's NIS-2 Journey | SITS

Initial Situation & Client Profile

How can a municipal enterprise implement NIS-2 requirements in a structured way when several critical responsibilities have to be managed simultaneously?

Landkreis Goslar is a public corporation and operates a local government administration with around 1,400 employees. A central part of the district is the KreisWirtschaftsBetriebe Goslar (KWB).

KWB combines the business areas of waste management, emergency medical services and a training center for emergency medicine and is managed as a separate organizational, administrative and financial entity without its own legal personality. In this role, KWB acts as a public waste management authority under the Circular Economy Act and is responsible for emergency medical services on behalf of Landkreis Goslar in accordance with the Lower Saxony Emergency Services Act.

The regulatory requirements of the NIS-2 Directive primarily affect KWB's waste management operations. This created the need to further develop existing security structures and adapt them to new requirements.

Our success story demonstrates how Landkreis Goslar and its municipal enterprise, together with SITS, are laying the foundation for a structured and sustainable NIS-2 implementation.

Landkreis Goslar SITS

Client: Landkreis Goslar

Industry: Public Administration

Our Services: Consulting and project management for NIS-2 implementation, expert support from the eISB team, structuring of security processes, project planning

The Project in Numbers
A project with structural impact:
1
structured project plan for NIS-2 implementation
1400
employees across the district administration
6
locations
40000
properties served through waste management operations

The Challenge

Complex requirements, limited structures
The requirements of the NIS-2 Directive affect a highly operational municipal enterprise that covers a wide range of responsibilities.

The KreisWirtschaftsBetriebe Goslar needed and continues to ensure that its waste management services falling under NIS-2 comply with the relevant regulatory requirements.

At the same time, dedicated structures were lacking to implement these requirements systematically and efficiently.

The central question was: How can a complex regulatory requirement be implemented in a structured, transparent and sustainable manner within a heterogeneous and operationally focused environment?

Approach & Strategy

 
 
 
 
1
2
3
4
 
Requirements Analysis
Definition of regulatory requirements and identification of concrete action areas together with the management team
 
Project Planning
Joint development of a high-level project plan for the systematic implementation of NIS-2 requirements
 
Stakeholder Engagement
Involvement of all relevant stakeholders, from the District Administrator and the district's service units to operational management and department heads, to ensure broad organizational adoption
 
Assessment & Roadmap
Execution of a NIS-2 assessment to evaluate the current situation, identify and prioritize required measures, and establish a detailed implementation roadmap

Implementation

Creating structure, providing guidance
The project is carried out in close collaboration between Landkreis Goslar, KWB, and the SITS eISB team. The focus lies not only on expert consulting, but above all on the targeted management of the overall project.

For around 2.5 years, Landkreis Goslar has been working on implementing security standards based on the German BSI IT-Grundschutz framework. This existing experience, together with available documentation and established security mechanisms, provides the foundation for the current NIS-2 initiative within KWB.

Several key milestones have already been achieved throughout the project:

  • Kick-off with operational management to define requirements and establish a roadmap for 2026
  • Extended kick-off with department heads to refine the next steps
  • Completion of an assessment to evaluate the current security maturity level
  • Creation of a structured project plan for achieving NIS-2 compliance

SITS acts as a strategic sparring partner, providing methodological guidance and ensuring that regulatory requirements are translated into concrete actions.

„The collaboration is respectful, straightforward, and takes place on equal footing. There is a genuine sense of mutual trust, which makes working together easy. We feel well supported by SITS and benefit from its broad portfolio of services.“

- Tim Schneider, Information Security Coordinator, LK Goslar

The Result

Early impact and long-term perspectives:
Although the project is still in its early stages, the first positive effects on organizational structures and processes are already visible.

Within KWB's management team and the involved departments, awareness of security-related topics has increased significantly.

At the same time, structures are being established that enable a sustainable and long-term implementation of NIS-2 requirements.

Particularly noteworthy is the close and trust-based collaboration between Landkreis Goslar and SITS, which forms a solid foundation for future initiatives.

Protect your organization, too

Are you facing the challenge of implementing regulatory requirements such as NIS-2 in a structured way and embedding them sustainably within your organization?

Our experts support you every step of the way, from assessment through implementation.

Get in touch now
Find out how we can protect your company too

You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

More Information