Back to blog

Everything You Need to Know About the NIS2 Directive

B
BlueSecure
Équipe BlueSecure
June 6, 20245 min read
Everything You Need to Know About the NIS2 Directive

NIS2 (Network and Information Security) refers to the Directive on the Security of Network and Information Systems.

Adopted in December 2022, the NIS2 Directive follows the NIS1 Directive, which was adopted six years earlier by the European Union and transposed into French law in 2018. By seeking to harmonise cybersecurity practices across Europe, this directive extends its scope to a greater number of entities, increasing from 19 sectors under NIS1 to 35 sectors under NIS2. The integration of this directive into the national laws of Member States, scheduled for October 2024, represents both a challenge and an opportunity. It calls for action to strengthen the security of Europe’s digital infrastructure and promote a robust cybersecurity culture.

It further clarifies the obligation to notify the competent authorities in the event of a security incident and replaces the OES (Operator of Essential Services) status with two new categories of organisations: essential entities (EE) and important entities (IE). Another major new feature of NIS2 is the inclusion of subcontracting companies and, in some cases, local authorities among the stakeholders concerned.

Are you affected?

The NIS2 Directive targets private and public organisations with more than 50 employees and annual revenue exceeding one million euros. In addition to the sectors covered by the NIS1 Directive (transport, finance, energy, water, aerospace, healthcare, public administration and digital infrastructure), several additional sectors have been added, particularly those that are essential to citizens’ daily lives. These include postal and courier services, waste management, manufacturing, the production and distribution of chemicals, industry, agri-food, and digital service providers. However, it may also apply to public-sector entities such as local authorities.

If you would like to find out whether you are affected, you can take the test on the following website: https://monespacenis2.cyber.gouv.fr/simulateur

How can you become compliant?

To comply with the NIS2 Directive, organisations must take various measures to strengthen their cybersecurity and manage risks effectively. First, they must conduct a risk assessment to identify potential threats and vulnerabilities, and implement security measures proportionate to the identified risks. They must then adopt technical and organisational measures, such as IT security policies, incident management procedures and access controls, to manage risks to network and information system security.

Monitoring and detecting security incidents are also crucial. Organisations must establish incident monitoring and detection capabilities using appropriate tools to identify anomalies and suspicious activity. In the event of an incident, they must develop and maintain an incident management plan, train staff to respond in a crisis, and conduct regular exercises to test response procedures.

In addition, organisations must establish procedures to promptly notify the competent authorities of significant cybersecurity incidents, while complying with the notification deadlines set out in the directive (generally between 24 and 72 hours after detecting the incident). Cooperation and information sharing with national authorities, computer security incident response teams (CSIRTs) and other entities are also essential to share information on threats and incidents, and to participate in European cooperation initiatives aimed at improving collective cybersecurity.

Training and raising staff awareness of IT security and risk management are also important. Employees must receive regular training on cybersecurity best practices and company policies. In addition, regular audits must be carried out to verify compliance with the requirements of the NIS2 Directive, document all security measures implemented, and ensure that evidence of compliance can be provided in the event of an inspection by the authorities.

Finally, managing suppliers and external partners is a crucial aspect. Organisations must assess and manage supplier-related risks and ensure that suppliers also comply with security standards and the requirements of the NIS2 Directive.

By following these steps, organisations can improve their ability to anticipate cybersecurity threats and ensure compliance with the NIS2 Directive.

What do you stand to gain?

This new directive gives organisations the opportunity to review their cybersecurity approach, shifting from a reactive strategy to proactive risk management. It also enables organisations to assess their capabilities and operations against enhanced cybersecurity requirements.

The expansion of the number of organisations covered by NIS2 allows organisations to ensure that their medium-sized partners and suppliers take the necessary steps to protect themselves against cyber threats. This is particularly important at a time when the supply chain is a prime target for cybercriminals.

For organisations that have not yet established an adequate security strategy with the appropriate tools, it is crucial to recognise the importance of assessing and managing cyber risks. Threats, whether external or internal, can seriously compromise an organisation, affecting its financial stability and reputation. Therefore, implementing appropriate controls offers significant benefits that go well beyond simple regulatory compliance.

Every medium-sized or large organisation is no longer responsible solely for its own security, but also for that of all its employees, partners and customers. NIS2 therefore represents an opportunity to adopt an optimal security posture to protect data, identities and infrastructure.

What are the risks?

Non-financial consequences

  • Strict security audit requirements
  • Compliance obligations
  • Strict directives requiring immediate implementation
  • Alerts sent to customers to warn them of risks related to the organisation

Financial consequences

  • For Essential Entities (transport, finance, energy, water, aerospace, healthcare, public administration and digital infrastructure): fines may reach up to €10 million or 2% of total annual worldwide turnover, whichever is higher.
  • For Important Entities (food production, digital services, chemicals, postal services, waste management, research, manufacturing/production): fines may reach up to €7 million or 1.4% of total annual worldwide turnover, whichever is higher.

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article