Senior cybersecurity professionals at more than a fifth of the UK’s largest businesses are “not sure” whether the EU’s NIS2 directive even applies to their organisation, new research by specialist cybersecurity consultancy Green Raven Limited has revealed.
More than two-thirds of respondents at organisations with at least 1,000 employees said that NIS2 does apply to them, but almost 10% of these admitted that their organisation was not compliant as of the October 17th deadline – with a further 3% not sure.
The research also asked respondents for their reaction to the Cyber Security and Resilience Bill, trailed by the UK Government in July 2024’s King’s Speech. This new bill is expected to build upon the foundations laid by the EU’s Network and Information Systems (NIS) directive and is commonly seen as the UK’s response to the NIS2 directive.
Asked to react based on what they had heard or read about the new Act, 37% of respondents said that they hope that the new Cyber Security and Resilience Bill won’t apply to their organisation, but almost 80% expect that it will.
Further, 46% of respondents expect the bill to make unwanted demands of UK businesses, but over 82% expected the bill to make reasonable demands of UK businesses. A similar proportion agreed that the bill would make necessary demands of UK businesses.
Finally, almost 88% of respondents agreed with the statement: “The UK Cyber Security and Resilience Bill will improve the UK’s overall cyber resilience.” Not a single respondent disagreed with the statement, despite the acknowledgement of the additional demands and overheads the new bill is likely to bring.
Conducted on its behalf by Censuswide, Green Raven surveyed 200 respondents from among the UK’s 1,930 organisations with at least 1000 employees. All respondents described their role as CISO/director/head/manager of [in] their organisation’s cybersecurity team.
The EU’s Network and Information Security Directive (NIS2) aims to improve the overall level of cybersecurity and standardise cyber resilience across the EU, by requiring operators of critical infrastructure and essential services to implement appropriate security measures and report any incidents to the relevant authorities.
EU member states were required to transpose NIS2 into their national legislation by 17th October 2024. Although the UK has left the EU, NIS2 impacts UK organisations that fall under its scope and conduct business in the EU, either as a customer or as a supplier.
Recommended reading
- 98% of Firms Eye GenAI for Cloud App Modernisation
- NCSC Issues Guidance for Securing Cloud-Hosted SCADA Systems
- Cloud Complexity and AI are Too Much for Traditional Security
Morten Mjels, CEO of Green Raven Limited, said: “NIS2 came into force in January 2023 – almost two years ago – so for senior cybersecurity professionals at the companies most likely to be impacted to not know if it even applies… wow.
“Saying yes, we’re compliant may be acceptable; admitting that no, we’re not compliant but we’re working on it may also be acceptable– assuming there may be a grace period when new regulations come into force.
“But, eventually, failure to be compliant is going to significantly impact the ability of these organisations to do business in Europe or is going to attract a significant fine for doing business in Europe without being compliant. And saying ‘we weren’t sure’ is unlikely to be much of a defence.”





