NIS 2: New Measures To Strengthen Corporate Cybersecurity

(Photo © Moritz Kindler / Unsplash)

The European NIS 2 directive, which addresses corporate cybersecurity, now targets a broader range of companies and sectors, and holds company management accountable for cybersecurity. Here is an overview of the new requirements and the steps to take.

In response to the growing cyber threat and the ongoing digitalisation of services, the European NIS 2 directive (Network and Information Security) aims to harmonise and strengthen cybersecurity requirements, in order to better protect businesses and, through them, the citizens affected.

“NIS 2 was adopted in 2022 but will be implemented this year following its transposition into national law. It follows the 2016 NIS 1 directive, expanding its scope and objectives to provide even greater protection,” explains Sheila Becker, Head of Network and Information Systems Security (NISS) at the Luxembourg Institute of Regulation (ILR).

Expansion of the sectors covered

More specific and more ambitious, this new directive introduces a number of key changes.

The first? A significantly broader range of companies are now affected. All entities are by default classified under two new categories: essential entities — mainly businesses operating in highly critical sectors — employing at least 250 people, or generating an annual turnover exceeding €50 million, or with an annual balance sheet total over €43 million; and important entities, employing at least 50 people or with a turnover or balance sheet total of at least €10 million.

This new classification comes with a significant expansion of the sectors covered: “The space sector, manufacturing, online marketplaces, and food production, among others, are now included. The full list is available on our website ilr.lu, where you’ll also find a detailed FAQ. Companies are welcome to send their questions via our dedicated email address: [email protected],” notes Sheila Becker

Registration and Incident reporting to the ILR

All affected companies must take the in￾itiative to register themselves with their competent authority, namely the Luxembourg Institute of Regulation (ILR) or the Commission de Surveillance du Secteur Financier (CSSF) for companies in the financial sector.

Once registered, they are required to re￾port any incident that could significantly impact cybersecurity within 24 hours.

“This could be an attack, a mishandling, human error, a malicious act, a small explosion in the server room, or even a truck hitting an electronic communications distribution cabinet… In short, anything that could compromise IT systems and the data processed by the company,” explains the Head of Network and Information Systems’ Security.

Responsibility of management bodies

Another key change under NIS 2 is the accountability of company management. Cybersecurity is no longer solely the responsibility of the IT department. Executives are now expected to stay informed, undergo training, and ensure their staff are also trained on cybersecurity matters. They must understand the stakes and implement a risk analysis and IT system security policy.

It’s important to note that failure to comply with the directive may result in penalties ranging from a formal warning to fines of up to €10 million or 2% of the company’s total global turnover.


This article was published in Silicon Luxembourg magazine.

Total
0
Shares
Related Posts
Total
0
Share