Guide · NIS2 · Architecture

A NIS2-compliant security ecosystem: how we integrate SIEM, XDR/EDR, firewalls, switches and servers

How ALAconnect connects individual security tools into a single system that protects, detects, responds and documents, following the measures required by NIS2.

ALAconnect · Published on 9 October 2026 · 7-minute read

At a glance

  • NIS2 does not ask you to buy a product but to manage risk: prevent, detect, respond and prove it with evidence.
  • Firewalls, switches, servers and workstations are not enough on their own: they must send their events to a single point of analysis, the SIEM.
  • EDR/XDR protects workstations and servers and can isolate a compromised device within seconds.
  • Centralised monitoring makes the 24-hour early warning to CSIRT Italia required by NIS2 achievable.

Why you need integrated tools, not just tools

Many SMEs already have a firewall, antivirus and backup, but each works on its own: the firewall blocks, the antivirus alerts, the backup copies, and nobody puts the information together. A modern attack, however, crosses several layers: a phishing email leads to a stolen password, the password opens a VPN, and from the VPN the attacker moves towards the servers. Each tool sees only one piece.

NIS2 (Italian Legislative Decree 138/2024) and the basic security measures defined by the Italian National Cybersecurity Agency (ACN) require this risk to be managed as a whole: knowing the assets, protecting them, detecting incidents, handling them and notifying them within precise deadlines. To do this, systems must talk to each other. This is what we mean by a protected ecosystem.

Security ecosystem architectureEdge devices (firewalls, switches, physical and virtual servers, workstations with EDR) send events to the SIEM and to monitoring; the SIEM correlates events and triggers the response; evidence flows into the compliance portal.NIS2 governance and evidencePrivacy & Compliance Portal: ACN controls, incident register, deadlinesSIEM / XDRevent collection and correlation,vulnerabilities, file integrity, alertsInfrastructure monitoringavailability, performance, capacity,backup and service statusFirewallNGFW, IPS, VPNSwitchesVLANs, segmentationServersphysical and virtualWorkstationsEDR, MFA, patchingIncident responseendpoint isolation, IP blocking on the firewall, restore from backup, notification to CSIRT Italia
Ecosystem diagram: edge devices feed the SIEM and monitoring; the response goes back to the devices; evidence flows into NIS2 governance.

The layers of the ecosystem

1. Perimeter: next-generation firewall

The firewall is the control point between the company network and the Internet, and between sites. Besides filtering traffic, it inspects content with IPS and web filtering, manages VPNs with multi-factor authentication and, above all, sends its logs to the SIEM: access attempts, blocked connections, detected threats. On its own it protects; integrated, it tells you what is happening.

2. Internal network: switches and segmentation

Managed switches divide the network into separate segments (VLANs): offices, servers, telephony, guests, production machinery, video surveillance. If a device is compromised, segmentation prevents the attacker from reaching everything else. Switches also send events to the SIEM, for example a new device being connected or a port changing state.

3. Physical and virtual servers

Physical servers, virtualisation hosts and virtual machines are securely configured, regularly updated and equipped with agents that send system logs, logins and changes to critical files to the SIEM. The same agents detect known vulnerabilities and deviations from secure configurations, so update priorities are based on real data.

4. Workstations and servers: EDR/XDR

EDR (Endpoint Detection and Response) protects PCs and servers by analysing process behaviour, not just known virus signatures: it recognises ransomware starting to encrypt files even if it is new. XDR extends the same logic by correlating what happens on endpoints with network, email and cloud events. When it detects a threat, the device can be isolated from the network within seconds.

5. SIEM: where everything comes together

The SIEM collects events from firewalls, switches, servers, endpoints and cloud services such as Microsoft 365, stores them and correlates them with rules that recognise attack patterns: many failed logins followed by a successful one, a login from an unusual country, a suspicious process on a server. It is the layer that turns thousands of logs into a few meaningful alerts, with the context needed to decide.

6. Infrastructure monitoring

Alongside security there is availability: monitoring checks the status and performance of servers, network, storage, services and backups. A filling disk, a failed backup job or a stopped service are signals to handle before they turn into downtime, and business continuity is itself a measure required by NIS2.

How the ecosystem meets NIS2

NIS2 requirement / ACN measuresHow the ecosystem covers it
Asset inventoryAgents on servers and endpoints and network monitoring keep the device list up to date.
Vulnerability managementThe SIEM detects vulnerable software on servers and workstations and indicates update priorities.
Access control and MFAThe firewall enforces MFA on VPNs; the SIEM flags anomalous logins and repeated attempts.
Network segmentation and protectionFirewalls and switches separate segments and block unnecessary traffic between them.
Incident detectionEDR/XDR and SIEM correlate events and raise real-time alerts.
Notification within 24 hoursCentralised logs and event timelines make it possible to prepare the early warning to CSIRT Italia on time.
Business continuity and backupMonitoring checks backup jobs and services; restore tests are documented.
Evidence for inspectionsReports and controls flow into the Privacy & Compliance Portal with date and status.

From detection to response

An ecosystem matters most when something goes wrong. A typical example: the EDR detects a process on a workstation that starts encrypting files. Within seconds the workstation is isolated from the network; the SIEM reconstructs where the attack came from, for example an email attachment, and if an external address is involved it is blocked on the firewall. The technician checks the other devices, restores files from backup and records the incident with the event timeline, ready for notification to CSIRT Italia and, if personal data is involved, to the Data Protection Authority.

Where to start

  1. Inventory: list devices, servers, cloud services and network flows.
  2. Log collection: connect firewalls, servers and Microsoft 365 to the SIEM first.
  3. Endpoint protection: extend EDR to all workstations and servers.
  4. Segmentation: separate at least servers, offices, guests and unmanaged devices.
  5. Incident procedure: define who does what and link it to SIEM alerts.
  6. Evidence: document controls and tests to demonstrate compliance.

How ALAconnect works

ALAconnect designs and manages the entire ecosystem: firewalls and switches, endpoint protection, SIEM and monitoring, backup and incident response, with a single point of contact and NIS2 documentation. Read more in NIS2 compliance and Cybersecurity, or request a gap analysis. Many of these measures can be funded: see Grants and funding.

Need support?