NIS2

Background
The Network and Information Systems 2 Directive is a European directive aimed at strengthening cybersecurity in the European Union (EU) proposed by the European Commission.
The NIS2 Directive aims to enhance the security of network and information systems within the EU by requiring operators of essential and important entities to implement appropriate security measures and report any incidents to the relevant authorities. It aims at further improving the resilience and incident response capacities of both the public and private sectors and focuses on cybercrime and European and national cybersecurity management. The Directive comes into force on 17 October 2024.
‘essential entities’ and ‘important entities’
The NIS2 directive distinguishes between ‘essential entities’ and ‘important entities’. The main difference between the two is that important entities will face lower financial penalties and will be subject to reactive supervision by authorities as opposed to proactive supervision reserved for essential entities. This means that unless there is a reason for it, such as a cyber incident or reports from external organisations such as auditors or other parties in the supply chain, a key entity will not face direct supervision from regulators and authorities. There is a defined list of these entities, which include Transportation, Digital infrastructure and IT services and Health amongst others.
The key highlights of the NIS 2 Directive
- Increasing the accountability of the C-level (by imposing direct obligations on the management in respect of compliance obligations, in particular to approve the cybersecurity risk-assessment);
- Increasing the level of cyber resilience in a comprehensive way for entities operating in the EU across all relevant sectors (the NIS 2 Directive contains a list of mandatory measures to be taken, such as business continuity measures, cybersecurity training, policies on risk analysis and information system security, etc.);
- The obligation to notify the competent authority (in case of any incident having a significant impact of the provision of the services) and the recipients of the services (if such an incident is likely to adversely affect the provision of those services) within very strict timeframes;
- The creation of GDPR-like fines (up to 10,000,000 EUR or 2% of the total annual worldwide turnover – whichever is higher);
- The establishment of a framework for a better cooperation and information sharing between Member States and competent authorities (to improve the awareness and the collective capability to prepare and respond to the cyber threats).
How can you prepare for NIS2?
- Extended focus on organisation management & governance: Organisation’s top level management are obliged to approve the cybersecurity risk management measures taken by your organisation. To that, organisations must ensure cyber security training for management bodies
- Cybersecurity risk-management measures: Organisations have to perform risk management and implement mitigating measures including policies on risk analysis and preventive capabilities such as incident handling, supply chain security, cryptography, HR security etc
- Business Continuity: If incidents occur organisations must ensure continuous performance. Business continuity can be reached with backup management, disaster recovery and crisis management
- Reporting obligations: If cybersecurity incidents occur, the organisation is entitled to notify competent authorities within 24 hours of becoming aware of the significant incident followed by an in depth incident notification within 72 hours
Author: Neil Redmond, Director of Cyber Security, NIS2, DORA and AI Act Lead, PWC and graduate of the Executive MBA (2004)
Why global supply chains are so fragile 