A control-by-control mapping of Syneto Hybrid Cloud Ecosystem capabilities against the technical security requirements of EU Directive 2022/2555 (NIS2).
NIS2 (Directive (EU) 2022/2555) entered force October 2024. It expands the scope of NIS1 to ~10× more EU entities, raises minimum cybersecurity controls, and introduces personal liability for executives.
| Article 21 requirement | Syneto control | Evidence |
|---|---|---|
| (a) Risk analysis & policy | CENTRAL audit log; ISO/IEC 27001 ISMS | ISMS export |
| (b) Incident handling | RP timeline; Rapid Data Revival™; forensic clones | Incident PDF |
| (c) Business continuity & DR | Smart Replicator; declared failover; per-VM RPO/RTO | DR-test signed report |
| (d) Supply chain security | Signed firmware; verified-boot HYPER; SBOM available | SBOM CycloneDX |
| (e) System acquisition / maintenance | SynetoOS LTS; signed update channel; staged-rollout | Patch policy doc |
| (f) Effectiveness assessment | Quarterly DR-test workflow | Drill report PDF |
| (g) Cyber hygiene & training | Syneto Academy partner curriculum; certified admins | Cert roster |
| (h) Cryptography | AES-256 at-rest + in-transit; HSM key custody | KMS export |
| (j) Multi-factor authentication | NIS2 Package add-on: TOTP MFA; SSO-integrated | Login audit |
NIS2 imposes a strict notification cadence after a significant incident. Syneto CENTRAL's incident timeline view is designed to produce these reports automatically.
Initial notification: nature of incident, suspected cause, current impact. CENTRAL exports as a PDF, no manual writing.
Updated assessment: scope, impact, indicators of compromise. RP timeline + affected-VM list attached.
Root cause, remediation, lessons learned. Full audit-log dump + DR-test evidence + RPH-pinned recovery point list.
{"event": "recovery_point.hold.placed","ts": "2026-04-12T14:33:08.114Z","actor": { "user": "[email protected]", "mfa": "totp", "session": "s-21a..." },"object": { "rp": "vm-erp-01@2026-04-12T14:18:08Z", "txg": 4218892 },"params": { "duration_days": 90, "reason": "incident:INC-2026-04-12-001" },"approver": { "user": "[email protected]", "mfa": "totp" },"sig": "ed25519:5Hb4...J7tA","prev": "ed25519:9Vp2...Q3xC" // chain hash}
The NIS2 Package is an add-on so customers without NIS2 obligations don't pay for it. For in-scope entities, it turns compliance from a paperwork project into a config setting.
Syneto designs and manufactures the complete Hybrid Cloud Ecosystem — hypervisor, data management, data protection and disaster recovery in a single plug & play platform. Founded in 2008, headquartered in Brescia and Timișoara, serving 5,000+ European businesses.
Designed, built and supported in Europe. ISO 9001 and ISO/IEC 27001 certified operations.
Production-ready in under 30 minutes. No multi-vendor integration, no professional services required.
One contract, one phone number, one SLA — for the entire stack. Local language support.
Across 18+ years of customer deployments, no Syneto customer has ever paid ransom following a cyber incident.
Single-vendor support — one contract, one phone number, one SLA for the entire stack. Three response tiers, all delivered by Syneto engineers in your language.
| Plan | Response | Coverage | Who it's for |
|---|---|---|---|
| Essential | NBD — 8×5 | Software + hardware | Branch offices, test & dev |
| Business | 4 h — 24×7 | Software + hardware | Production workloads |
| Mission-Critical | 1 h — 24×7 | Software + hardware + TAM | Business-critical sites, DR |
support.syneto.eu
help.syneto.eu
academy.syneto.eu
partners.syneto.eu
Join 5,000+ European companies that trust Syneto.
© 2026 Syneto SpA. All rights reserved. "Syneto", the Syneto logo, "SynetoOS", "Syneto CENTRAL", "Hyperion", "HYPER Core", "HYPER Edge", and "HYPER Echo" are trademarks of Syneto SpA. All other trademarks are the property of their respective owners.