Cybervize

The questionnaire nobody needs and nobody benefits from

Alexander Busse·October 8, 2026

New articles by email

We send you an email whenever a new article is published. Only the new article, no advertising. You can unsubscribe at any time via the link in every email.

You will first receive a confirmation email. How we process your address is described in our privacy policy.

Clipboard with a ticked checklist on top of a building whose foundation has deep cracks

A company falls under NIS-2 and introduces a GRC tool. Once it is set up, the tool holds a catalogue of questions, at least one for every requirement. Is there patch management? Are access rights reviewed regularly? Has the backup been tested?

The questions go to IT. The team answers them between two tickets, the tool turns the answers into a compliance score, and management sees a bar that gets greener month after month.

We consider this the wrong path. A GRC tool that measures compliance through questionnaires alone does not help a company with NIS-2. It creates an assumption of compliance and security that the tool itself never checked. It takes no work off IT and adds one more task to its list. In the end, the company carries more load and is no more secure. The reason is written in the law.

What NIS-2 requires

In Germany, the BSI Act (BSIG) transposes the NIS-2 Directive. Section 30(1) BSIG obliges essential and important entities to take appropriate, proportionate and effective technical and organisational measures. The law asks for measures, and for whether they work.

Subsection 2 lists what the measures must include at a minimum. Item 6 covers policies and procedures to assess the effectiveness of cybersecurity risk-management measures. Assessing effectiveness is therefore an obligation in its own right.

Section 38(1) BSIG addresses management. It is obliged to implement the risk-management measures and to monitor their implementation. Only someone who can see what has been implemented can monitor it.

A questionnaire measures statements

Asked about patch management, IT answers yes. That is a statement about its own operations, made on one particular day. It does not say which systems are meant, when they were last updated, or which server has been skipped for months. The tool does not know the systems. It only knows the answer.

The compliance score is therefore built on answers the tool cannot check against operations. Whether a measure works enters this number only as far as the answer claims it. Assessing that effectiveness is exactly what section 30(2) item 6 requires. A tool that only collects answers cannot deliver it itself, because it lacks the object of assessment.

Care helps only so far. A thorough team checks patch reports and test logs before answering. Then IT has done the check next to the tool, and the tool has only filed the result. A team answering from memory can be wrong, because nobody knows the entire estate. In both cases, the tool itself has checked nothing.

The assumption becomes a risk

The questionnaire becomes dangerous once its result is read as a state. A high compliance score sounds like a company that is nearly done. Management reports it to the shareholders, and the security budget follows it.

The gap then shows during an incident or an audit. The server the questionnaire listed as patched was not. Until then, the company relied on an assumption and took it for evidence.

We consider that more dangerous than not knowing your state at all. A company that knows it does not know looks for gaps. A company with a green bar stops looking.

One more task for IT

NIS-2 asks a lot of IT: implementing measures, hardening systems, reporting incidents on time. A questionnaire tool helps with none of it. It asks for the status, but implements nothing and does not show where things are stuck.

Yet most answers already exist. The vulnerability scanner knows the open findings for each system. The ticketing system shows how incidents were handled. Policies, operating manuals and contingency plans exist as documents in the company. The questionnaire has all of this typed in a second time, in a form nobody reads outside the tool.

Every round of questions costs IT time that is missing from implementation. The company creates burden and gains no additional security in return. For NIS-2, no company should therefore choose a pure GRC tool.

What a tool for NIS-2 has to do

From the law, we draw two requirements. A tool must show from operations whether measures are implemented and whether they work. And it must work with what already exists in the company, instead of asking for it again.

Questions keep their place where judgement is needed: whether a risk is acceptable, whether a measure is adequate. A person makes that decision. It needs data as its basis, not a self-report.

How Cybervize does it

That is why we built OdySecure differently. The platform measures what happens in operations. In the release shipped on 30 September 2026, twenty-three connectors are registered, including vulnerability scanners, cloud checks, inventory systems and ticketing systems. Through them, results from the systems the company already runs flow into the platform.

And OdySecure reads in what already exists. You do not fill in an ISMS, you put your documents in. From documents and organisational structure, the platform derives the chain from business process to security process. Every step is a suggestion that a person accepts.

Where an assessment is needed, work does not start from zero either. The assessment module checks against any standard and suggests matching passages from your own documents for each question, with the source. A person sets the answer.

IT keeps working in its systems, and their results, together with the existing documents, form the starting point. Management thus gets a basis for monitoring implementation as section 38 BSIG requires. In a vCISO mandate, we run this path together with your team.

Product details as of the release shipped on 30 September 2026. This describes what the platform can do, not a commitment about the scope of any individual installation.

Get new articles by email. Only the new article, no advertising.

New articles by email

We send you an email whenever a new article is published. Only the new article, no advertising. You can unsubscribe at any time via the link in every email.

You will first receive a confirmation email. How we process your address is described in our privacy policy.