Skip to content
Review Open access

Translating NIS2 Requirements into Actionable Tasks for SMEs Using STRNIS2

2026 · AHFE International · 0 citations

Abstract

Organisations must translate cybersecurity requirements into work that people can carry out and managers can check. This methods paper specifies STRNIS2, a six-stage method for assigning that work in small and medium-sized enterprises. Its Human-Centric Compliance Matrix (HCCM) records the requirement, task, responsibilities and evidence. The method develops our earlier NIS2 Compliance Starter Pack by specifying how information and effort are allocated across a handover. A purposive document analysis connects European and Latvian requirements with human-factors research and incident-response guidance. In a constructed reporting example, information may be deferred only if it is unnecessary for an immediate safe decision, a capable recipient accepts the remaining work, and recording and notification deadlines remain achievable. Comparison with an existing shared ticket examines when to change a procedure and when to retain it. A planned five-case study will assess method use through paired task-structuring sessions, Raw NASA-TLX, interviews and documentary review. The contribution is a task-design method and review procedure; effects on workload and cybersecurity remain to be tested.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.