NIS2 guide · 8 min
How a breach happens in 2026: your external surface and your supply chain
In 2026 the way you get breached has shifted, and the shift is about speed. The fastest-growing route is not a clever trick but tempo: attackers, increasingly aided by AI, weaponise a vulnerability in an internet-facing edge device before a patch exists (the average time-to-exploit has turned negative) and harvest valid credentials at scale. It reaches you two ways: your own external surface is hit directly, or a weaker supplier is breached and the attacker pivots into you (NIS2 Article 21(2)(d)). This guide walks the 2026 attack chain step by step, names the concrete gap that opens each door, and is honest about where an external monitor like norppa.io helps and where it cannot.
Key takeaways
- • In 2026 the dominant initial-access routes are exposed edge devices (VPNs, firewalls, gateways) exploited fast, often before a patch exists, and stolen credentials at scale, both accelerated by AI.
- • You are exposed on two surfaces: your own external posture and every supplier's (NIS2 Article 21(2)(d)); norppa.io monitors both continuously.
- • No external scanner detects a true zero-day. norppa.io's job is to shrink the exposed surface, name the concrete gaps, flag known-exploited issues the moment they are catalogued, and catch the credential and ransomware signals around a compromise.
Two doors, and in 2026 they open fast
You are breached one of two ways, and both begin on the outside. Either your own external surface is compromised directly (an exposed service, a leaked credential, a spoofable domain), or a weaker supplier is breached and the attacker pivots into you, which is the risk NIS2 Article 21(2)(d) makes you responsible for. The attacker uses the same steps for both doors. norppa.io monitors both: every supplier you add and your own domain get the same 100+ continuous external checks. Your own domain can additionally enable a monthly full external assessment (an add-on) that runs only on your own domain, never on your suppliers.
Official source: NIS2 Directive on EUR-Lex — Articles 20 (management responsibility), 21(2)(d) (supply-chain security) and 23 (incident reporting).
The 2026 attack chain, step by step
Each step below is real and documented in 2026 incident data. What has changed is tempo: AI compresses reconnaissance and exploit development, and known vulnerabilities are now often weaponised before a fix ships. At each step, norppa.io names the specific gap that opens the door, not just a score, on your own surface and your suppliers'.
Exposed edge devices: the fastest door
What happens in 2026
The dominant 2026 initial-access route is an internet-facing edge device: a VPN, firewall or gateway (Citrix, Ivanti, Fortinet, Palo Alto). These sit on the perimeter, lack endpoint detection, and are now frequently exploited as zero-days or within hours of disclosure; across 2026 the average time-to-exploit has turned negative, meaning exploitation before a patch exists. AI accelerates both the discovery and the weaponisation.
The gap norppa.io names
No external scanner detects an unknown zero-day, and norppa.io does not claim to. What it does: inventory exactly which edge, VPN and admin surfaces you and your suppliers expose, name each known-exploited (CISA KEV) and high-EPSS vulnerability the moment it is catalogued, and detect origin IPs reachable behind a CDN. The smaller and better-known your exposed surface, the less a zero-day has to hit.
Stolen credentials at scale
What happens in 2026
Just as common as an exploit is a valid login. Infostealer malware and initial-access brokers trade fresh credentials daily. In June 2026 the FortiBleed campaign showed the scale: administrator credentials were harvested from tens of thousands of internet-facing Fortinet firewalls across 194 countries, not through a single CVE but by cracking weakly-hashed configs and reused passwords. There was nothing to patch.
The gap norppa.io names
norppa.io names leaked credentials tied to your domain and your suppliers from dark-web and infostealer sources, and flags the exposed edge and admin services that make a FortiBleed-style harvest possible, so you can rotate and restrict before the login is used.
Email spoofing and CEO fraud (BEC)
What happens in 2026
With a foothold, or just a spoofable domain, the next move is fraud by email. Weak DMARC lets an attacker send mail that appears to come from a supplier straight to you, and AI now writes the lure fluently, in any language and at volume.
The gap norppa.io names
norppa.io names the exact email-authentication gap, no DMARC or DMARC at p=none, missing SPF or DKIM, on your domain and your suppliers', and raises a business-email-compromise verdict when a domain can be impersonated.
The two paths converge
What happens in 2026
From here the attacker either moves inside your own environment or pivots from a breached supplier into you, the exact supply-chain risk NIS2 Article 21(2)(d) makes you responsible for. A single shared hosting provider or one leaked admin credential can chain several of these steps together.
The gap norppa.io names
norppa.io names the chained attack path when findings combine (for example exposed authentication plus leaked credentials plus a spoofable domain equals account-takeover-ready), and maps concentration risk where many suppliers, or you, depend on the same provider.
Compromise and your NIS2 clock
What happens in 2026
The end state is ransomware or data theft. Under NIS2 a significant incident, including one that reaches you through a supplier, starts a 24-hour early warning and a 72-hour notification duty, and your management body is personally accountable (Article 20).
The gap norppa.io names
norppa.io re-checks ransomware-victim and dark-web sources every few hours and alerts the moment a supplier or your own domain appears, and keeps a tamper-evident duty-of-care record for the reporting that follows.
Where norppa.io fits: name the gaps, on both surfaces
norppa.io does not promise to stop a zero-day; no external tool can. What it does is make the chain visible early enough to break. It runs the same continuous external monitoring on your own domain and on every supplier, and instead of a single score it names the specific, actionable gaps: this exposed service, this known-exploited CVE, this leaked credential, this DMARC misconfiguration, each mapped to the NIS2 article it answers to. In a year when exploitation often precedes the patch, seeing and closing the concrete gap early, on both surfaces, is the defence that scales.
See how you and your suppliers actually score
7-day free trial · no credit card · cancel anytime
Common mistakes
- ✕Hardening your own perimeter while never checking what your suppliers expose to the same attackers.
- ✕Waiting for a patch, when 2026's edge-device vulnerabilities are routinely exploited before one exists, so exposure reduction and speed matter more.
- ✕Leaving DMARC at p=none, so your domain, or a supplier's, can be spoofed straight into your inbox.
- ✕Learning of a supplier's ransomware incident from the news, after your NIS2 reporting clock has already started.
FAQ
Is this only about my suppliers, or my own security too?
Both. NIS2 Article 21(2)(d) makes you responsible for supplier risk, but the same external signals decide whether your own organisation is breached directly. norppa.io monitors your own domain with the same 100+ continuous checks as your suppliers; your own domain can additionally enable a monthly full external assessment (an add-on that runs only on your own domain).
Are these 2026 attack patterns real?
Yes. Mandiant's M-Trends 2026 and VulnCheck report that a large share of initial-access vulnerabilities are now exploited as zero-days, with the average time-to-exploit turning negative (exploitation before patch), and Google's threat-intelligence group observed the first AI-developed zero-day exploit. The FortiBleed credential campaign (June 2026) and edge-device CVEs such as Citrix Bleed (CVE-2023-4966) and MOVEit (CVE-2023-34362) are documented, catalogued cases. We reference public sources, not invented statistics.
If norppa.io cannot detect a zero-day, how does it help?
By making the surface small and known, and the response fast. It names exactly which edge, VPN and admin services you and your suppliers expose (the target class), flags every known-exploited vulnerability the moment it is catalogued, catches the leaked credentials and ransomware signals around a compromise, and maps each gap to NIS2. It is exposure reduction, early warning and evidence across both surfaces, not a promise to stop an unknown exploit.
See the gaps on your own and your suppliers' external surface
Run a free external check on your own domain and see the same monitoring norppa.io runs on every supplier: the concrete gaps, mapped to NIS2.
7-day free trial · no credit card · cancel anytime
Related guides
How to comply with NIS2: a step-by-step roadmap
The steps to NIS2 compliance in order: confirm scope, register, management accountability (Art. 20), the Article 21(2) measures, supply-chain security, incident reporting (Art. 23) and continuous, evidenced assurance.
Who is in scope for NIS2? Essential vs important entities, sectors and size thresholds
Determine whether NIS2 applies to you: the two tiers, the Annex I/II sectors, the size thresholds, size-independent exceptions, and how the supply chain pulls you in even if you're not designated.
NIS2 for suppliers: you're not designated, but your customers are
Most companies are never designated under NIS2, yet many must comply anyway. How a covered customer's Article 21(2)(d) supply-chain duty flows down to you, what they'll ask for, and how to respond credibly.
NIS2 and the supply chain requirement: what it means in practice
NIS2 requires essential and important entities to assess their supply chain cyber risks. Supplier tiering, 4th-party risk, Art. 23 notification, and what auditors look for.
Supplier cyber risk assessment: what automated NIS2 monitoring checks
All check categories explained: ransomware, dark web leaks, TLS/DNSSEC, cookie security, CVE/EPSS, sanctions, MX blacklists and SAQ. Finding lifecycle and NIS2 article mapping.
NIS2 Art. 21(2): supplier security checklist
Checklist for procurement and security teams: what to ask, what evidence to collect, and how to respond when a supplier falls short. Includes suggested evidence documents.
NIS2 supplier questionnaire (SAQ): what to ask, how to score it, and a free template
What to ask suppliers under Art. 21(2)(d), how to score answers and respond to gaps, why self-attestation needs verification, and a free copy-paste questionnaire template.
NIS2 incident reporting: the 24- and 72-hour deadlines explained
What counts as a significant incident, the Article 23 timeline (24-hour early warning, 72-hour notification, one-month final report), and when a supplier's incident becomes your obligation.
NIS2 and management responsibility: what boards and leadership must know
What NIS2 expects of the management body: approval and oversight duties, personal liability (Art. 20), training, board reporting KPIs, and the penalties under Art. 34.
ISO 27001 and NIS2: what your ISMS already covers, and the gaps it doesn't
If you hold ISO 27001, what carries over to NIS2 and what does not: statutory incident reporting, management liability, registration, and continuous supply-chain assurance: plus how to close the gap.
NIS2 fines and penalties: how much, who is liable, and how to avoid them
What NIS2 penalties are: the Article 34 caps (€10M / 2% for essential, €7M / 1.4% for important entities), the management body's personal liability (Art. 20, Art. 32), non-monetary enforcement, and how to avoid them with continuous, evidenced diligence.
NIS2 vs DORA: how they differ, where they overlap, and which one applies to you
How the two EU regimes differ and overlap, why DORA is lex specialis for financial entities, which applies to you, and what both mean for third-party and supply-chain risk.
GDPR vs NIS2: how they overlap, where they differ, and when one incident triggers both
How GDPR and NIS2 differ and overlap, when one incident triggers both (GDPR Art. 33 72h to the DPA vs NIS2 Art. 23 24h/72h/1-month to the CSIRT), the Art. 35 cooperation and no-double-fine rule, and what both mean for supplier due diligence.
The EU Cyber Resilience Act (CRA): scope, timeline and what it means for your supply chain
What the CRA requires, its phased dates (in force 2024, reporting Sept 2026, full compliance Dec 2027), who is in scope and why pure SaaS often isn't, how it complements NIS2, and what it means for procurement and supplier due diligence.
The EU AI Act: risk tiers, the timeline, and what deployers must do (Article 26)
What the EU AI Act requires: the risk tiers, the phased dates (in force 2024, prohibited Feb 2025, GPAI Aug 2025, high-risk Aug 2026), the Article 26 deployer obligations, how it stacks with NIS2 and the GDPR, and what it means for AI procurement.
NIS2 transposition status: which EU countries have it in force
Which of the 27 EU Member States have written NIS2 into national law and which are still finalising it, and why the gaps reach your supply chain regardless.
NIS2 supplier contract clauses: what to require from your suppliers
The contract clauses that turn NIS2's supply-chain duty into something enforceable: security baseline, incident-notification window, evidence and audit rights, subcontractor flow-down, and how to verify them continuously.
Your external security posture under NIS2: what suppliers and customers can see
The publicly visible signals customers assess under NIS2 Art. 21(2)(d): email spoofability (SPF/DMARC), certificate hygiene, internet-exposed systems and leaked credentials, why each matters and how to check and fix them.
Do your suppliers use AI? NIS2 supplier risk meets the EU AI Act
Suppliers increasingly embed AI in the services you depend on, and so do their suppliers. Where supplier and nth-party AI creates risk under NIS2 Art. 21(2)(d) and the EU AI Act, what to assess, and how to keep visibility.
Vendor impersonation and CEO-fraud (BEC): email spoofing, DMARC and NIS2
One of the most common supply-chain attacks needs no breach: spoofed email that redirects a payment or steals data. How BEC and vendor impersonation work, the SPF, DKIM and DMARC settings that stop them, and how it fits NIS2 Art. 21(2)(d).
Last reviewed: 19 June 2026
This guide is general information about EU law, not legal advice. NIS2 takes effect through each EU Member State's national transposition law, which can differ in detail. Verify the obligations that apply to you with your competent authority or legal counsel.