January 6, 2026

CIS 18, NIS2, and cyber insurance – a complete guide to cybersecurity for businesses

Cybersecurity has become a critical part of business and is no longer just an IT issue. Today, companies face requirements from regulators (NIS2), insurance companies (cyber insurance), and customers who expect…

Cybersecurity is no longer a niche technical area.
It is a management responsibility, a compliance requirement, and an economic risk factor.

This page brings together everything you need to know about:

  • CIS 18 (practical cybersecurity)
  • NIS2 (legislation and responsibility)
  • Cyber insurance (financial risk and claims)

And most importantly: how it all fits together in practice.

Overview – how it all fits together

Most companies approach cybersecurity from three angles:

  • Authorities (NIS2)
  • Insurance companies (cyber insurance)
  • Customers and partners (requirements and documentation)

CIS 18 serves as the practical foundation that ties everything together.

What is CIS 18?

CIS 18 is an internationally recognized cybersecurity framework developed by the Center for Internet Security.
The framework consists of 18 specific security controls that reduce the risk of the most common cyber attacks.

CIS 18 is about:

  • What you need to do specifically
  • How to work in a structured way with security
  • How to document your efforts

Read the full review here:
https://securefirst.dk/nyheder/cis-18-vs-nis2

See the CIS 18 compliance solution:
https://securefirst.dk/cis18-compliance/

What is NIS2 – and why is it important for management?

NIS2 is an EU directive adopted by the European Union that sets out mandatory cybersecurity requirements for selected companies and organizations.

NIS2 differs from previous regulations in that:

  • Placing responsibility with management
  • Requiring documentation
  • Setting requirements for technology, processes, and people

Read about NIS2 in practice and management responsibility:
https://securefirst.dk/nyheder/nis2-ledelsesansvar

Overview of NIS2 compliance:
https://securefirst.dk/nis2-compliance/

CIS 18 vs. NIS2 – differences and interactions

The crucial thing to understand is this:

  • CIS 18 is a framework
  • NIS2 is legislation
  • CIS 18 shows how
  • NIS2 requires that you can prove it

That is why many companies choose CIS 18 as the operational basis for NIS2 compliance.

Comparison and explanation:
https://securefirst.dk/nyheder/cis-18-vs-nis2

Cyber insurance – the financial angle


But insurance companies now impose specific security requirements before they will provide cover.

Typical requirements:

  • Awareness training
  • Phishing tests
  • Incident response
  • Documentation

CIS 18 is often used as a reference for determining whether a company's security level is acceptable.

Read how cyber insurance relates to CIS 18:
https://securefirst.dk/nyheder/cyberforsikring-og-cis-18

The most important CIS 18 areas for most companies

For the vast majority of companies, cybersecurity starts here:

Awareness training

Human error is the greatest risk.

https://securefirst.dk/awareness-traening/

Phishing simulation

Training works best when it is tested.

https://securefirst.dk/phishing-simulation/

Data Breach Monitoring

Early detection reduces damage.

https://securefirst.dk/monitorering-af-databrud/

The role of management – it is no longer enough to "keep IT under control"

NIS2 makes it clear:

  • Cybersecurity is a management responsibility
  • Failure to act may have consequences
  • Documentation is crucial

Read how management works correctly with NIS2:
https://securefirst.dk/nyheder/nis2-ledelsesansvar

How SecureFirst brings it all together in one place

SecureFirst is designed for companies that want to:

  • Working in a structured manner with CIS 18
  • Comply with NIS2
  • Meet cyber insurance requirements
  • Maintain an overview – without complexity

The platform brings together:

  • Training
  • Phishing
  • Monitoring
  • Compliance and reporting

See the platform:
https://securefirst.dk/
Calculate level and price:
https://securefirst.dk/prisberegner/

FAQ – overview

Do all companies have to comply with CIS 18?

No, but CIS 18 is a recognized best practice and is widely used as a reference.

Does NIS2 apply to all companies?

No, but many are indirectly affected through customers, suppliers, and insurance.

Is CIS 18 sufficient for NIS2?

CIS 18 does not cover legal matters, but supports the vast majority of practical requirements.

Where do you start?

Start with overview, awareness, and documentation.

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.  

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...