A shared landing zone for a group with entities in three countries
- 01Situation
- Three subsidiaries run separate cloud tenants with different controls. Each national authority expects NIS2 incident reporting on its own timeline, and nobody can show the group’s security posture in one view.
- 02What we would build
- One landing zone in code with per-entity policy sets, shared logging and an incident process that classifies and routes reports per country.
- 03Where people decide
- Each entity’s security officer approves policy exceptions for their workloads; the group CISO owns the shared baseline.
- 04What we would measure
- Time from incident detection to classification, share of workloads under policy, and recovery tests passed per quarter.