Skip to content

Centraleyezer: an RBVM solution for compliance with NIS2 and DORA, recommended for critical maritime infrastructure

Centraleyezer: an RBVM solution for compliance with NIS2 and DORA, recommended for critical maritime infrastructure

MARITIME SECURITY FORUM

Against the backdrop of a rise in cyber-attacks on public institutions, the Maritime Security Forum presents Centraleyezer, a Risk-Based Vulnerability Management (RBVM) platform developed to support organisations in meeting the requirements of the European NIS2 Directive (transposed in Romania via Government Emergency Ordinance 155/2024) and the DORA Regulation, which will apply to the financial sector from 2025.

Unlike traditional scanners, which generate large volumes of findings that are difficult to manage and often contradictory, Centraleyezer centralises the identified vulnerabilities, eliminates false positives and prioritises them according to their actual impact on the business. The offensive scanning component, eyezer, covers five main areas: web application and API security, domain and email exposure, public data leaks (source code, access keys, vulnerable containers), exposed network services, and continuous infrastructure monitoring. The platform requires no complex installation — simply entering a domain or a range of IP addresses is enough for the discovery and scanning process to begin automatically.

The reports generated can be used as evidence of compliance with NIS2, DORA, ISO 27001, PCI-DSS or the Cyber Resilience Act. Potential beneficiaries include organisations in the energy, transport (including the Port of Constanța ecosystem), healthcare, public administration and digital infrastructure sectors, alongside financial institutions, managed security service providers (MSSPs), defence and industrial companies, as well as large organisations with a broad attack surface. The features that set the product apart — self-hosted deployment, multi-tenant support and direct alignment with NIS2/DORA requirements — make it particularly suitable for organisations with strict data sovereignty requirements and facing regulatory pressure.

Improve your organisation’s cyber security posture with Centraleyezer – a Risk-Based Vulnerability Management (RBVM) platform – opinion piece by the Maritime Security Forum

In light of recent cyber-attacks targeting organisations in the public sector, we would like to draw your attention to the availability of a tool that supports the implementation of measures to strengthen your security posture and ensure compliance with current regulations. We present a Risk-Based Vulnerability Management (RBVM) platform designed primarily as a solution for implementing the NIS2/DORA requirements.

NIS2 (EU Directive 2022/2555 on the security of network and information systems) is the European directive that establishes a framework for harmonising digital resilience processes and standards, with the aim of strengthening cyber security across the EU. As it is a directive (not a regulation), each Member State transposes it into its own national legislation; in Romania, this has been done through Government Emergency Ordinance No. 155/2024, approved and amended by Law No. 124/2025.

DORA (Digital Operational Resilience Act) is an EU regulation designed to strengthen the resilience of digital operations in the financial sector. As a regulation, it applies directly without the need for national transposition, and is the first framework enabling financial services supervisors to monitor third-party providers of critical ICT services, including cloud providers.

NIS2 requires an assessment of the effectiveness of existing security measures, and proportionate testing supports this. Automated scanning underpins several NIS2 obligations simultaneously, supporting continuous risk assessment by detecting vulnerabilities in networks, applications and systems before attackers can exploit them, which directly feeds into risk management requirements.

Although NIS2 does not mandate penetration testing as prescriptively as DORA, it sets out a risk-based expectation: if an organisation’s infrastructure manages critical services, it must be able to demonstrate that its measures actually work under simulated attack conditions.

Each Member State transposes NIS2 differently, so the specific requirements vary, but the basis is clear: organisations must test, document and remediate.

In any organisation that regularly runs security scans, the same problem arises: volume. A single scanner can generate thousands of findings in a week, and when you use three or four different tools, the results overlap, contradict one another and end up in Excel files that nobody ever opens. The ‘critical’ severity rating assigned by the scanner tells you nothing about what that vulnerability means for the continuity of your operations and data.

This is where RBVM (Risk-Based Vulnerability Management) comes in, and Centraleyezer is a platform built specifically to address this problem.

Centraleyezer is a Risk-Based Vulnerability Management (RBVM) platform — in other words, a system that centralises the vulnerabilities detected by security scanners and prioritises them according to the actual risk to the business, not according to generic severity. It unifies the asset inventory, contextual risk scoring, compliance evidence and remediation tracking, so that the security team always knows what needs to be fixed first. eyezer is the offensive scanning console behind Centraleyezer; it enables dynamic application testing, management of external attack surfaces, OSINT scanning, scanning for secrets and containers, and network probing – all in one place – with automatic, recurring monitoring that continues to keep watch after the initial scan.

Centraleyezer scans everything visible on the internet relating to the organisation – websites, web applications, servers, domains, subdomains, email and even source code or container images accidentally exposed – and identifies the vulnerabilities that an attacker could exploit. Essentially, the platform ‘sees’ the organisation’s digital infrastructure exactly as a hacker would see it, before they have a chance to exploit it.

No complicated installations are required to use it: simply enter a domain, a website address or a range of IP addresses, and eyezer takes care of the rest – automatically scanning for subdomains, exposed servers and public resources associated with the brand.

The platform covers five main risk areas:

1. Web applications and APIs – it tests the company’s websites and applications for hundreds of known vulnerabilities, including those in modern JavaScript-based applications.

2. Domain and email exposure – checks whether the domain, security certificates and email configuration are properly protected, preventing email spoofing or the hijacking of abandoned subdomains.

3. Hidden public exposure – searches for code repositories, access keys or passwords accidentally left in public places, as well as vulnerable container images.

4. Exposed network and services – identifies ports and services open to the internet that could serve as entry points for attackers.

5. Continuous monitoring – this is not a one-off scan, but a recurring process (hourly, daily or weekly, depending on the subscription) that alerts the team as soon as a change or a new vulnerability arises.

The results are easy to interpret. Each identified vulnerability is verified to eliminate false positives, prioritised according to the actual risk to the business, and translated into a concrete action, with a designated responsible person and a resolution deadline. The reports generated can serve as proof of compliance with regulations such as NIS2, DORA, ISO 27001, PCI-DSS or the Cyber Resilience Act – exactly the type of documentation that authorities or business partners may request.

Which relevant institutions or organisations might be interested in Centraleyezer?

The answer lies in what sets the product apart: self-hosted (data sovereignty), multi-tenancy (service delivery to third parties) and NIS2/DORA compliance (regulatory pressure). Anyone meeting at least two of these criteria is a serious candidate.

1. Entities falling under NIS2 — the largest segment

The NIS2 Directive has been transposed into Romanian law via Government Emergency Ordinance 155/2024, and the sectors covered align almost perfectly with the product’s profile:

Energy and utilities — producers and distributors of electricity, gas and oil, as well as network operators. They have a mixed OT/IT infrastructure, highly diverse assets and strict incident reporting obligations. Examples include: Transelectrica, Transgaz, regional distributors, refineries, water and sewerage operators.

Transport and logistics — ports, airports, rail operators, port authorities. The local context is particularly relevant here: the Port of Constanța and its surrounding ecosystem (the Maritime Ports Authority, terminal operators, shipping companies and shipping agents) are precisely the type of entity with a large attack surface, NIS2 requirements and a reluctance to use external cloud services.

Healthcare — county and regional hospitals, private clinic networks. Sensitive data, limited IT budget, but a compliance obligation.

Public administration — ministries, agencies, county councils, city councils. Here, the case for self-hosting is often decisive, not optional.

Digital infrastructure — cloud service providers, data centres, ISPs, domain registrars.

2. The financial sector — DORA pressure

Banks, insurance companies, investment firms, payment processors and fintech firms will fall under DORA from January 2025. The requirements for testing digital operational resilience and managing ICT risk make a system with demonstrable audit trails a necessity, not a luxury. Credit unions and non-bank financial institutions are a sub-segment often overlooked by large providers — too small for Qualys or Rapid7, yet too heavily regulated to do nothing.

3. Managed Security Service Providers (MSSPs)

For an MSSP, multi-tenancy with isolated instances and white-label reporting are not merely features, but the business model itself. A provider managing 15–40 clients can deliver a vulnerability management service without having to build the platform in-house. This includes: security consultancy firms, IT integrators expanding their offering with managed services, and technical audit firms looking to move from one-off projects to recurring subscriptions.

4. Defence, industry and critical infrastructure

Companies in the defence sector, manufacturers with NATO or classified contracts, and operators of national critical infrastructure are often explicitly prohibited from sending security data outside their own perimeter. Also included are organisations in large-scale industrial manufacturing, shipyards and companies with extensive automation.

5. Large companies with mature security practices

High-volume retail, telecoms, e-commerce, gaming and betting operators — all have PCI-DSS obligations and a significant attack surface. The practical criterion here is not the sector, but a concrete indicator: the organisation is already running at least three different scanners and lacks a unified prioritisation mechanism.

Maritime Security Forum