Site navigation

The EU’s NIS 2 Directive | What You Need To Know

Graham Turner

,

NIS 2 Directive guide

The NIS 2 Directive, set to take effect in October 2024, is a significant update to the EU’s cybersecurity regulations, building on the original NIS Directive of 2016. It aims to address the evolving digital landscape and growing cybersecurity threats by setting stricter requirements for a wider range of organisations, reinforcing Europe’s digital resilience.

What is the NIS 2 Directive?

The NIS 2 Directive is a legislative measure by the EU to strengthen cybersecurity across member states, ensuring that operators of essential services and key digital infrastructure maintain high standards. The directive requires more comprehensive risk management, imposes stricter supervisory requirements, and introduces tougher enforcement measures with substantial penalties for non-compliance.

Key Changes from NIS 1 to NIS 2

  1. Expanded Scope: NIS 2 covers a broader set of sectors compared to NIS 1. This includes not just critical infrastructure such as energy, healthcare, and transport, but also newer areas like digital services, social networks, and even manufacturing. The definition of essential services has been widened, impacting around 160,000 organisations across the EU.
  2. Management Accountability: Leadership teams are now directly accountable for ensuring cybersecurity compliance. This means board members and senior management could face consequences for cybersecurity failings.
  3. Enhanced Incident Reporting: The directive introduces stricter requirements for reporting cybersecurity incidents. Organisations must notify relevant authorities within 24 hours of detecting a significant incident and provide a detailed report within 72 hours.
  4. Stronger Risk Management Requirements: The directive mandates regular risk assessments, multi-layered defenses, and active management of supply chain risks. This includes robust measures for identifying and addressing vulnerabilities.
  5. Harmonisation Across the EU: Although the directive allows for some national discretion, it aims to create more consistency in cybersecurity standards across member states. This should streamline compliance for organisations operating in multiple countries.

Compliance Requirements

To comply with NIS 2, organisations must:

  • Implement comprehensive cybersecurity policies, including incident response plans and risk management procedures.
  • Conduct regular security training for staff and ensure cyber hygiene practices are observed.
  • Establish an incident response team equipped to handle significant security breaches.
  • Work closely with service providers to manage cybersecurity risks throughout their supply chain.

Recommended reading


Enforcement and Penalties

The NIS 2 Directive establishes stricter penalties and enforcement measures for non-compliance with cybersecurity requirements.

Each EU member state will designate one or more “Competent Authorities” responsible for overseeing the implementation and enforcement of NIS 2. These authorities will monitor compliance, handle incident reporting, and impose sanctions for non-adherence.

The penalties under NIS 2 can be substantial, often based on a percentage of an organisation’s global annual turnover.

Senior management can also face accountability, including liability or temporary bans from management positions if found responsible for serious breaches.

The directive specifies prompt incident notification obligations: within 24 hours of detection for a significant event and a full report within 72 hours.

Implementation Timeline

EU member states must transpose NIS 2 into national legislation by October 2024. Given the different cybersecurity environments across member states, organisations should stay updated on country-specific adaptations of the directive.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data