The business landscape has experienced a surge in digital transformation initiatives, driven by the need to optimize operational functions. However, this reliance on digital technologies makes organizations vulnerable to cyber-attacks. With cyber threats on the rise, the European Union (EU) has proposed NIS2 for the Security of Networks and Information Systems (NIS), a comprehensive cybersecurity directive aimed at elevating cybersecurity standards across the EU.
NIS2 applies to critical infrastructure operators classified within 15 sectors including banks, energy, health, manufacturing, etc. and to digital service providers in the EU. More than 150,000 large and medium-sized companies are estimated to be affected by the directive. NIS2 expands on the previous NIS directive released in 2016, by defining clear cybersecurity requirements and incident reporting obligations while imposing sanctions for non-compliance.
The directive categorizes entities as "essential" or "important" based on the potential ramifications of service disruption. Both categories must adhere to the same security measures, but "essential" entities face proactive supervision. Organizations must implement specific cybersecurity measures, including risk analysis, incident handling, business continuity systems, supply chain security and more. It also establishes incident reporting obligations, requiring organizations to issue early warnings, conduct assessments, and submit comprehensive incident reports within defined timeframes.
Non-compliance with NIS2 exposes organizations to cyber threats and regulatory sanctions. Essential companies may face fines of up to €10 million or 2% of its worldwide annual turnover, while important companies could face fines of up to €7 million or 1.4% of worldwide annual turnover. Management would be held liable for risk management and are exposed to penalties and temporary bans from management roles.
NIS2 not only mandates public and private organizations to enhance their cybersecurity but also requires national governments to establish collaboration and vulnerability-sharing initiatives. The directive establishes the European Cyber Crisis Liaison Organisation Network (EU CyCLONe) to manage cybersecurity incidents at the EU level, fostering information exchange and cooperation.
Organizations must achieve NIS2 compliance by October 2024. Early adherence to the directive can enhance competitiveness, reputation and customer trust. Seizing the opportunity for proactive compliance with NIS2 is crucial for organizations aiming to establish robust cybersecurity measures and ensure long-term growth and profitability.
ISG offers comprehensive services to assist organizations in understanding NIS2 requirements and achieving compliance, including quick self-assessment, in-depth maturity evaluation, AI and ML based policy alignment, management training, incident response planning and cybersecurity strategy development.
NIS2 will establish a benchmark for cybersecurity risk management in the following sectors:
Additionally, the directive extends its applicability to companies operating outside the EU but offering services within the EU such as companies offering cloud services, social media networks and search engines. Such companies are required to designate a representative in the EU.
Organizations are required to implement suitable technical and organizational measures to manage the risks that may affect the security of their network and information systems. The following measures will be addressed as part of the directive:
NIS2 defines mandatory post-incident activities that are to be performed in a multiple-stage approach. Upon becoming aware of an incident, organizations are obligated to issue a warning to the relevant national authority within a 24-hour timeframe. They are then required to conduct an initial assessment of the incident within 72 hours. All incidents necessitate the submission of a comprehensive incident report within one month from the initial report.
All organizations falling under the purview of the directive are required to achieve NIS2 compliance by October 17, 2024. This timeline allows for the necessary preparations and adjustments to be made to ensure adherence to the requirements outlined in NIS2. Organizations must assess their cybersecurity posture in all aspects of security controls, covering people, process and technology to identify potential gaps and bridge these gaps.
ISG provides comprehensive services tailored to assist organizations in gaining a deep understanding of how NIS2 applies to their unique circumstances. We guide organizations through the necessary steps to enhance their security measures and ensure robust compliance with the directive. We offer the following key services:
ISG is ready to help you to seize the opportunity for proactive compliance with NIS2. Contact us now to find out how to get started.