Network Bridge Solutions
← All insightsThinking · 5 min read

Why Default Microsoft 365 Settings Fail a NIS2 Audit

The demand will come from your biggest customer before it comes from any regulator. Here is what their questionnaire will find.

A factory machine still wrapped in protective shipping film, standing on a working production floor.

The letter that makes NIS2 real for most manufacturers does not come from a regulator. It comes from a customer. Usually the biggest one. Their procurement team sends a security questionnaire, thirty or sixty questions long, and somewhere in the middle it asks how your Microsoft 365 is configured, who checks it, and where that is written down.

That is the moment NIS2 stops being an article you skimmed and becomes a deadline with an order book attached.

If you have read anything about NIS2, you have probably read the same three things everyone writes. It is the EU's updated cybersecurity directive. It covers essential and important entities. The fines are large. All true, and none of it tells you what to actually fix first. So the reading produces a vague intention to take security more seriously, and the vague intention produces nothing.

Here is the specific thing the reading never says. For most manufacturing businesses of the size NIS2 actually touches, the biggest single gap is not on the factory floor and it is not some exotic system you have never heard of. It is Microsoft 365, the system you already pay for and use every day, running on settings nobody ever decided.

First, the honest scoping question

NIS2 is not everyone's law, and anyone who tells you it is should worry you.

In Poland, where our EU operation is based, it is now in force. The amended KSC Act took effect on 3 April 2026. Businesses in scope must assess themselves and register in the national system by 3 October 2026, and get twelve months to meet the technical and organisational requirements. The incident reporting duties do not wait.

Manufacturing is named directly. Annex II of the directive lists the makers of medical devices, electronics, electrical equipment, machinery, vehicles and other transport equipment. In those sectors, a business with fifty or more people, or more than ten million euros in turnover, is an important entity under the directive.

If that is not you, the law can still reach you, and this is the part most coverage misses. Article 21 requires covered entities to manage the security of their supply chains. So the obligations flow downhill. Your customer is designated, therefore your customer must vet you, therefore you get the questionnaire. NIS2 applies to you directly, or through a customer's supply-chain requirements. For most smaller suppliers it arrives the second way, and it arrives with commercial weight rather than legal weight, which in practice is heavier.

Why the gap is in Microsoft 365

Microsoft runs the platform and runs it well. The data centres, the patching, the uptime. That is their side of the deal.

The configuration is your side. Who can sign in and from what. Whether a stolen password is enough to get in. What a personal laptop can reach. What happens when a file full of drawings leaves the building in an attachment. Whether anyone is told when a setting changes. Microsoft gives you the controls. It does not know your business, so it cannot set them for you.

A new tenant is configured for convenience, because a system that blocks things out of the box would never sell. Convenience is the right default for getting started. It is the wrong permanent state for a business whose biggest customer is about to ask hard questions.

And NIS2 asks for something very specific. Article 21 wants security measures that are documented, managed and monitored. Look at those three words against a default tenant. Nothing is documented, because nobody made decisions worth writing down. Nothing is managed, because the settings sit wherever they landed on day one. Nothing is monitored, because monitoring is off or ignored. A default Microsoft 365 tenant fails all three tests at once, before an auditor looks at a single technical detail.

None of this is anyone's fault, and this matters. Nobody in the business was ever asked to make these decisions, so nobody made them. That is a systems gap, not a people gap. But it is still the first thing a questionnaire finds.

The nine questions the questionnaire is really asking

Strip the jargon out of a NIS2 security questionnaire and it is asking nine things about your Microsoft 365.

  1. Is there a written record of how it is set up, and why? Not the invoice. The decisions, and the reasons.
  2. If a setting changes, does anyone find out? Settings drift. Someone fixes a login problem by loosening a rule and the loosened rule stays for years.
  3. Does every sign-in ask for a second check beyond the password? Every account. Including the directors, and including the shared tablet in dispatch.
  4. When did anyone last look at the security score Microsoft already gives you? It sits in every tenant, free, and in most businesses unread.
  5. Can a personal laptop reach your drawings, your prices and your customer files?
  6. Is anything marking your sensitive files and watching what leaves in attachments?
  7. Would you notice an administrator account signing in at three in the morning from a country you do not trade with?
  8. If your Microsoft 365 data were deleted or encrypted, do you hold a copy that does not live inside Microsoft 365?
  9. Can you point at each NIS2 requirement and name the setting that answers it?

Ask these of whoever runs your IT, in-house or a provider. For most businesses the honest answer to several is "I would have to check". That is a finding, not a shame. It is also exactly what an audit is for, and far better discovered by you than by your customer.

The clock that makes this urgent

One part of NIS2 has no twelve-month runway. A designated entity must give an early warning of a significant incident within twenty-four hours, a fuller notification within seventy-two, and a final report within a month.

You cannot report what you cannot see. A tenant nobody watches cannot meet a twenty-four hour clock, because in a tenant nobody watches, day one of an incident is whenever someone happens to notice, and that is routinely weeks in. The reporting deadlines quietly assume the monitoring already exists. That assumption is the whole game.

Where to start

Not with new software, and not with a panic purchase. The order that works is boring, which is a good sign in security.

First, know what you have. Get the current state of the tenant written down, setting by setting, decision by decision. Second, close the open doors, and the two that matter most are sign-ins without a second check and personal devices reaching company data. Third, start watching. Drift, admin sign-ins, the score Microsoft already calculates. Fourth, map what you now have to what NIS2 asks, so the questionnaire answer is a document you already hold rather than a week of scrambling.

A business does not get made compliant by a purchase. It becomes compliant when its everyday systems run on decisions someone actually made, written down, and checked. Microsoft 365 is where that either is true or is not, because it is where your identities, your files and your email already live.

The gap was never exotic. It is the system you already own, running on decisions nobody made. Make the decisions, write them down, watch them, and the questionnaire stops being a threat. It becomes the easiest paperwork of your month, and your biggest customer notices that too.