BORNHACK 2026 · THU 16 JUL · 15:00–16:00 · SPEAKERS TENT
[ TALK: COMPLIANCE / NIS2 ]
Asking why
until it hurts.
// how I learned the hard part of compliance
Gorm Reventlow
bornhack.dk
[ INTRO ]
ASKING WHY UNTIL IT HURTS
whoami
$ history | grep compliance
2023started dabbling — collecting data for a DPO
2025new job, one brief: "NIS2. It's stuck. Fresh eyes."
2026this talk — what happened in between
// expecting a hardcore veteran? wrong tent. but you'll recognize the terrain.
01
The Easy Part
// rules, standards, and a lot of studying
[ 01 / THE EASY PART ]
ASKING WHY UNTIL IT HURTS
The Assignment
$ cat brief.txt
>a company that had been wrestling with NIS2 for a while
>the brief: fresh eyes on a stuck problem
>my track record at that point: collecting data for a DPO
so: fresh eyes. very fresh.
[ 01 / THE EASY PART ]
ASKING WHY UNTIL IT HURTS
The Reading List
$ ls ~/reading/
nis2-directive/who is covered, what is required
iso-27001/the management system
iso-27002/the controls
iso-27005/risk management
iso-27035/incident management, parts 1–4
network/people who had done it before — the real find
study. study. study.
[ 01 / THE EASY PART ]
ASKING WHY UNTIL IT HURTS
The Mindset Behind the Rules
$ man nis2
>it looked daunting — and for a while it became my whole focus
>understanding it all matters, including the intent behind it
>the intent: not paperwork for auditors — resilience you can prove
[ 01 / THE EASY PART ]
ASKING WHY UNTIL IT HURTS
Status Check
$ compliance --status
reading the directive[ done ]
understanding the mindset[ done ]
feeling pretty good about it[ done ]
implementation[ pending ]
All of the above turned out to be the easy part.
02
The Hard Part
// in which a plan meets reality
[ 02 / THE HARD PART ]
ASKING WHY UNTIL IT HURTS
The Plan
$ ./implement.sh --dry-run
[ ok ]workshops with department heads and middle management
[ ok ]procedures drafted together, in their own words
[ ok ]documented, approved, filed
textbook execution. what could possibly go wrong.
$ ./implement.sh --production
The plan only ever lived in plan mode.
written together. approved together. followed by no one.
[ 02 / THE HARD PART ]
ASKING WHY UNTIL IT HURTS
The Logic Problem
$ ./convince.sh --method=logic
>my move: show the logic — requirement, risk, procedure
>it made almost no headway
>what it met instead: opposition
People don't change how they work because a diagram is correct.
[ 02 / THE HARD PART ]
ASKING WHY UNTIL IT HURTS
The Fear Problem
$ ./convince.sh --method=fear
>the other classic: "the web is dark and full of terrors"
>it works once. twice, maybe. then people grow numb
>every scare story after that costs credibility you'll need later
You can't scare people into caring. Nudge common sense — and sell the benefit.
[ 02 / THE HARD PART ]
ASKING WHY UNTIL IT HURTS
Mental Barriers of Change
$ dmesg | grep -i warn
W01foggy vision
W02lack of planning
W03impatience
W04plan vs. reality
W05circular dependency
W06fear of telling the truth
W07digitalization of clutter
W08lack of followership
// every one of them answers to a why
[ 02 / THE HARD PART ]
ASKING WHY UNTIL IT HURTS
The Two Jobs of Implementation
$ jobs -l
01
Document reality
how each department actually works, day to day — not how the org chart says it works
02
Build resilience
contingencies for the things that must keep working — written so anyone can follow them
03
Asking Why
// the part that finally worked
[ IN MY "LIMITED" EXPERIENCE ]
Compliance like NIS2 is less a legal task — and more a change-management obstacle.
the directive tells you what. it never tells you how to move people.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
The Reframe
$ diff pitch.old pitch.new
--- pitch.old
"NIS2 requires us to document this."
+++ pitch.new
"Why is it important that this keeps working?"
same procedure underneath. completely different conversation.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
Find What Hurts
$ nmap --top-ports 5 organisation
T01money
T02reputation
T03human safety
T04position among competitors
T05legal ramifications
find them. prioritize them. every why gets measured against this list.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
Four Questions
$ cat ~/toolkit/questions.txt
01Why is it important that this keeps working?
02Why is there no contingency plan for it?
03Why do we muddle through each day instead of writing the procedure down?
04What do we gain by muddling through — and if nothing, why do we keep doing it?
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
Until It Hurts
$ why --recursive
why is there no contingency plan?
└─ "we manage. we know the drill."
└─ why is the drill not written down?
└─ "no time. we're busy."
└─ what does muddling through gain us?
└─ "…"
It hurts when the honest answer is nothing.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
Upper Management Resistance
$ tail -f meetings/upper-management.log
UPPER MANAGER
"You make this sound like the most important thing in the world. We have operations and goals. Why should I sacrifice them for yours?"
ME
"Your decision. If you see no value in resilience in your domain, don't build it. I won't chase you down — I expect you'll be chasing me, because you need it."
// don't tackle the resistance. let them tackle themselves.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
The Goal of the Journey
$ update-alternatives --config ambition
0
do nothing
ignore the responsibility — and hope it goes ok.
1
avoid sanctions
weak implementation. compliance for compliance's sake.
2
create value
run on risk: resilient systems, strong contingency plans.
3
risk-based leadership
the continuation: data-driven decisions, steered by data and risk.
// choose out loud — every choice here comes with a price
maturity & value →
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
What Changed
$ git log --oneline
a41f2c9the answers to "why" became the business case
7be03d1stronger than any article citation I ever produced
c9d4e88people stand behind procedures they justified themselves
it has made the case stronger ever since.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
The Incentives
$ echo $WHATS_IN_IT_FOR_ME
>return on investment — not always money
>a clear view of risk, and the choice to reduce it
>breaking the silo — clarity in your department and across the organisation
the barriers push back. these pull forward.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
Know Your Role
$ id
RESPONSIBILITY
what you are expected to deliver
MANDATE
what you are empowered to change
make sure they are aligned. misaligned? start by aligning them — before anything else.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
The Decay
$ dig manager.converted +ttl
Converted managers don't stay converted.
>they lose focus
>they forget
>other events pressure the priority away
conversion has a TTL. keep re-asking why.
[ 03 / ASKING WHY ]
ASKING WHY UNTIL IT HURTS
WHAT GOOD LOOKS LIKE
Resilient— survives the bad day
Documented— exists outside someone's head
Reproducible— works when that someone is on holiday
[ THE TAKEAWAY ]
Compliance is about moving hearts and minds.
...and a lot of stubbornness.
the rules were the easy part.
gorm@bornhack:~$ why --interactive
Questions?
> slides: nis2-talk.blacklog.net
> source: github.com/Reventlow/nis2_bornhack_2026
> feedback: scan, or program page → feedback
Gorm Reventlow
BornHack 2026