- NIS2 Directive in the EU covers cybersecurity.
- Risk management and official notification requirements.
- Critical infrastructure defined.
Many organisations in the EU have already adapted their practices to take into account the directives of NIS, introduced in 2018. The NIS2 Directive is the EU-wide legislation on security that enforces a higher level of cybersecurity in organisations operating in Europe.
While NIS implementations on the ground in organisations may have been seen – rightly or wrongly – as only affecting specific personnel and business functions, the NIS2 Directive applies not only to a wider range of organisations, but also affects everyone in the business.
This second iteration of the Directive applies to companies turning over more than €10 million and/or employing more than 50 people. In the eyes of the law, individuals can be held personally responsible for the effects of a breach, including a company’s CEO, and everyone else down the food chain.
There are details in the body of the NIS2 Directive that outline which types of company or organisation of certain sizes that are subject to the law. Among the ‘essential sectors’ are energy, transport, banking, financial markets, health, water, digital infrastructure, ICT service management, and public administration.
‘Important sectors’ are listed as postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research organisations.
It’s worth noting that even if an organisation is small or not one of the listed sectors, adopting NIS2-compliant policies will go a long way to ensuring better cybersecurity practice, and help protect the organisation from the consequences of a data breach.
With fines of up to €10 million for breaches under the Directive, there’s now a significant financial liability in play, plus for every size and type of company, potential losses to the organisation of revenues, operations, and reputation.
What are the main responsibilities?
Responsibilities for cybersecurity are mentioned in articles 21 and 23 of the NIS2 Directive. Section 21 concerns security requirements, while 23 covers incident reporting requirements.
The big change, apart from the addition of personal responsibility, is that the security of an organisation’s supply chain becomes the direct responsibility of company that uses it. That requires the establishment of special relationships between a company and all its partners, with free and open information exchange benefiting all parties.
Some companies have state-backed certification for their products and services, and so referencing these will be relatively simple to include. However, for most there is a burden of data collection and assembling to be taken on board.
Reviews of suppliers’ security should be refreshed annually to take into account the changing nature of modern businesses’ infrastructure and cybersecurity provision.
Risk assessment and response to incidents
Organisations have to detail the levels of risk they are able to identify across the business, and lay out all the potential situations that may take place, plus the measures that are proposed that will ensure the continuity of production and operation.
Risk assessment involves details of cybersecurity protections in place including update policies, the level of cryptography used, software bills of materials, data protection measures, and a number of elements that examine the people in the organisation. Use of labour that may be subject to external pressures (from other nation states, for example) has to be listed, and there is often a need to detail the background checks’ results of all employees.
Access to key systems, privilege management and access controls should be considered and evaluated in terms of risk and remediation method. There are also areas of environmental and physical security to be checked and detailed, including asset management and the levels of physical access to core systems, data centres, and premises.
Organisations have responsibilities to report any data breach incidents inside 24 hours to the state-appointed body. An initial incident report should be submitted within three days, and a full report inside a month. It’s also mandated that customers or users of the organisation be informed of incidents so they can take appropriate action if necessary.
Conclusions
The two worlds of Legal and IT tend not to occupy much space in a skill set Venn diagram: Legal and compliance officers are rarely IT experts, and technology specialists aren’t usually versed in EU law. For long-term compliance, larger organisations may find that providing training to appointed individuals will help them manage NIS2 and later generations of statute in the future.
Organisations with existing ISO 27001 accreditation or those already adhering to NIS2 will find that parts of the necessary paperwork is relatively simple to undertake. But even companies with this head start have to go a lot further to comply with the NIS2 Directive.
While many will consider the oversight of cybersecurity compliance in Europe onerous and an unwelcome cost to the organisation, the contents of the law have not been drawn up to create regulatory burden.
The fact that many companies provide critical elements of national infrastructure mean that their protection is of societal importance. The reliance of people and economies on services like water, power, and banking, and goods as basic as food, mean that protecting critical producers and service-providers is hugely important.
And given that the majority of businesses and organisations rely extensively – often exclusively – on digital means to operate, places them at special risk from incursion, data loss, and operational interruptions.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.
