NIS2; An Updated NIS Directive – How Does It Affect Your Business?
23 January 2024
On 18 October 2024, the NIS2 Directive will enter into force in the EU, replacing the original NIS Directive. The upgraded directive aims to improve collective cybersecurity within member states. This means that more organisations will have to meet stricter cybersecurity requirements. In this article, we will give you a summary of NIS2, find out what it is about, whether the directive affects your organisation and what you should do if so. What new security requirements are placed on these organisations and what is required to meet the new requirements? How do you get started with NIS compliance?
What are the major changes in NIS2?
- More sectors of organizations will be affected.
- Minimum requirements for actions will be introduced.
- More precise reporting requirements will be implemented.
Is your organization covered by the new NIS Directive?
The NIS Directive was created to increase the Union’s level of security within network and information systems for essential services. The NIS Directive covered the following sectors, which are unchanged in NIS2:
Essential units:
- Energy
- Transport
- Banking
- Financial Market Infrastructure
- Healthcare
- Drinking Water Supply and Distribution
- Digital Infrastructure
However, from the first directive it has been identified that even more sectors need to be included and therefore it has been expanded to also include:
Other important devices:
- Wastewater
- ICT service management
- Public administration
- Space services
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacture of certain essential products such as pharmaceuticals
- Digital providers such as social networking platforms
- Research
Organizations are also divided into essential and important entities, based on their importance to the sector they belong to, as well as their size.
What happens if the NIS2 Directive does not apply to me?
It is not entirely clear which activities actually fall into each sector and even if your organisation will not have to comply with the NIS2 Directive you may still want to consider building your security work to comply with the Directive. The organisations covered by NIS2 are many and these organisations must ensure that their suppliers are also secure. This means that many companies will ultimately have to comply with the NIS2 Directive because the companies they work with do. This makes NIS2 a directive that most of us should be aware of.
Ten basic security measures required by NIS2
According to NIS2, organizations must take appropriate and proportionate risk management measures to prevent security incidents and minimize their impact. NIS2 includes a list of 10 basic measures that all organizations must take:
- Information systems risk analysis and security guidelines
- Incident management
- Business continuity, such as backup and disaster recovery, and crisis management.
- Supply chain security, including security-related issues related to the relationship between each business and its direct suppliers or service providers.
- Security in the acquisition, development, and maintenance of networks and information systems, including vulnerability management and disclosure.
- Policies and processes for assessing the effectiveness of cybersecurity risk management measures.
- Secure cybersecurity fundamentals and cybersecurity training
- Policies and procedures for the use of cryptography and, where applicable, encryption
- Human resource security, access control policies, and asset management
- Use of multi-factor authentication or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communication systems within the organization, where applicable.