On September 15, 2026, ADEX sponsored the 6th Cyber Security Conference at the Hilton Nicosia. The event ran under the auspices of Cyprus’ Digital Security Authority and was organized by IMH together with the ISACA Cyprus Chapter. ADEX was among the sponsors, alongside Mastercard, Thales and Kyndryl. That line-up is worth a second look: a payment network, two enterprise security vendors, and an adtech anti-fraud platform, all funding the same conversation. Ad fraud has moved out of the marketing agenda and into the security one.
NIS2 came up all day. On the panel “NIS2: From Directive to Executive Accountability,” Farukh Rakhimov, Head of Financial and Compliance Group at AdTech Holding, talked about turning the directive into owners, processes, and evidence. The full panel recap is on the AdTech Holding blog.
This post covers one part of that discussion, the part that matters most for adtech: suppliers.
This is an account of a conference discussion and of one practitioner’s approach, not compliance or legal advice. Organizations should confirm their own obligations under NIS2 and its national transpositions.
What NIS2 Asks About Suppliers
In short, NIS2 expects companies to know who their suppliers are, what those suppliers touch, and what happens if one of them fails. Supply chain security is listed among the required risk-management measures in Article 21. Article 23 then sets the reporting clock for significant incidents: an early warning within 24 hours, a full notification within 72 hours, and a final report within a month of that notification.
At the panel, Farukh summed it up in one line:
“You can outsource a service, but you cannot outsource accountability.”
Whether a given adtech company falls under NIS2 depends on its sector, size, and the national rules that implement it. Even outside direct scope, clients that are covered may ask for supplier-security terms in their contracts. So the question still comes up, just through a different route.
Who Counts as a Supplier in Adtech
In most industries, the supplier list is a spreadsheet: a hosting provider, a payment processor, a few SaaS tools. In adtech, it looks more like this:
- publishers and every domain they send traffic from;
- advertisers and every landing page they point to;
- trackers, redirect hops and intermediary domains between the click and the landing;
- partner platforms on both the supply and the demand side.
That adds up to thousands of counterparties, and the list changes every day. You can’t keep it up to date by hand. Even if you could, a list only tells you who someone was on the day you checked.
Why a One-Time Check Doesn’t Hold
ADEX specialists documented a case that shows the problem well. A college domain with years of clean history got hacked. The attackers planted a page on it and used Google search inside the redirect chain, so the planted page showed up as an ordinary search result. A user who clicked the ad went through the trusted domain and ended up on a page that had nothing to do with the college.
A standard onboarding check would most likely have passed that domain. Its reputation was good, its certificate was valid, and it had a real history. The compromise happened afterwards.
This is the core issue. A certificate, a clean landing page, or a filled-in onboarding form proves what was visible at one moment. Nothing more.
The Supplier Clock Is Your Clock
Farukh gave an example at the panel that fits adtech almost too well. Say a partner spots an incident late on a Friday, and their contract gives them a few days to tell you. By the time you hear about it, the 24-hour window NIS2 gives you for an early warning may already be gone. So the deadlines in your supplier contracts have to match the deadlines you answer to yourself.
In adtech, a lot of incidents never get reported by the supplier at all. A hijacked landing domain doesn’t send a notice. You find out from a user complaint, a partner’s alert, or your own monitoring. If that happens three days later, the compromised page has already been live in your chain for three days, and the first question you get is why nobody noticed sooner.
What Continuous Checking Looks Like
Farukh’s framework from the panel was simple: every requirement needs an owner, a process, and evidence. For adtech suppliers, that becomes three habits.
- Monitor counterparties continuously. You can’t know what is happening to a partner’s domains unless you check them regularly, including redirects that only show up for certain GEOs, devices, or referrers.
- Classify counterparties by criticality. Some domains carry more risk than others, and some partners touch user data or payment flows. A good reputation shouldn’t mean automatic approval.
- Keep the evidence. Monitoring logs, redirect histories, review records, alerts and enforcement decisions. When a client, partner, or regulator asks what you did, that record is your answer.
ADEX checks partner domains on an ongoing basis and keeps a record of what it finds. If you don’t want to set all of this up yourself, have a look at ADEX threat intelligence.
Measuring It
Once you keep those records, brand safety stops being a promise and becomes something you can measure. Useful metrics include:
- Mean time to detection: how long a compromised domain stays in the chain before someone flags it.
- Time to takedown: how long it takes from detection to blocking.
- Enforcement success rate: how many flagged cases end in a confirmed action.
- Channel coverage: what share of traffic sources and landing domains are actually being monitored.
These are the numbers that show whether supplier oversight actually works, which is the kind of evidence the panel kept coming back to.

