Preparing for NIS2: Your Roadmap to Cybersecurity Compliance
Over the past year, significant attention in the security community has been devoted to the European NIS2 Directive and its incorporation into national laws. This legislative change will affect a wide range of medium and large organisations. So whether you operate in the private or public sector, you should be interested in this topic.
What do NIS2 and related changes in national laws mean for your organisation? And how can you implement its requirements in practice? Read more.
Kateřina is a Security Consultant focusing on information security management system, risk management and business continuity. In ensuring compliance with standards and laws, she has experience in conducting maturity assessments and setting corrective measures, especially in the area of ISO 27001 and the Czech Act on Cyber Security.
What is NIS2?
The most significant change is the expansion of the scope from the seven sectors regulated initially to fifteen. Tens of thousands of entities will now have to comply with the requirements of the Directive and national laws.
The security measures required by the Directive are not significantly new compared to the NIS2 or the requirements of various information security standards such as ISO 27001. NIS2 is a natural evolution rather than a radical revolution in the understanding of expected cybersecurity measures. Nevertheless, it can still be a significant challenge for many organisations, especially those that have not yet considered implementing an information security management system.
Indicative Timetable for the New Legislation
How Does It Concern You?
NIS2 will affect medium and large organisations operating in defined sectors. NIS2 distinguishes between essential and important entities. Essential entities are defined as large organisations operating in the sectors listed in Annex I, as well as other entities identified as critical either directly by NIS2 or by a specific EU country. Important entities are medium-sized organisations from the sectors listed in Annex I, and large and medium-sized organisations from the sectors listed in Annex II.
What Can You Do?
Whether you belong to organisations under lower (important entities) or higher (essential entities) obligations, some requirements are common to both groups. You must adopt appropriate and proportionate technical, operational, and organisational measures to ensure the security of the networks and information systems used in your activities or to provide your services. You also must take steps to prevent incidents or minimise their impact on the users of your services. And set up reporting of incidents to relevant authorities if it occurs.
What are the new or more challenging topics?
Especially for organisations that have not yet been required to address information security, the biggest challenge initially will be to set up the strategy, roles and responsibilities and an overall framework for information security within the company. They must set this up, even if they must fulfil only the lower requirements level.
All organisations must have implemented functional and adequate processes for Business Continuity, Incident Management, Disaster Recovery, Backup Management, Third Party Management, Basic Cyber Hygiene and more.
There is a new obligation to educate members of the management body on cybersecurity to be able to consider and assess cybersecurity risks. The typical training methods are seldom interesting for this specific group and the specific training objective, and therefore, alternatives such as Round Table exercises should be considered. Round Table exercises utilise experienced experts to discuss selected topics (usually the actual threats and their potential impacts) with members of management.
Another option that companies appreciate is the Table-Top Exercise, where tailored scenarios of cyber incidents are addressed. Through Table-Top exercises, you can identify weaknesses in your organisation's security and incident response and management process. The Round Table and Table-Top exercises will significantly enhance cybersecurity awareness among the most important target group.
Organisations under the NIS2 Directive must implement fundamental measures to reduce risk as part of risk management and mitigation efforts. Risk analysis is the primary measure here, followed by the management of the identified risks. This involves monitoring assets, evaluating them, conducting risk assessments, and creating a plan to mitigate identified risks.
The risk analysis is crucial for properly managing the organisation's cybersecurity processes. It serves to pinpoint risks that could cause significant problems for your organisation. Incorporating risk analysis into the organisation's processes ensures that decisions about which measures to implement and at what level or which not to implement are entirely justifiable and make sense even from the standpoint of efficient financial management. By thoroughly understanding the risks, organisations can allocate their resources more effectively, avoiding unnecessary expenditures on low-impact risks and focusing on measures that yield the highest benefit in reducing vulnerability and exposure.
However, conducting a risk analysis that provides valuable outputs is not simple. It's necessary to consider the appropriate granularity of inputs to weigh up the methodology that will be feasible to carry out in a reasonable amount of time and yield meaningful results. From our experience, it happens all too often that a risk analysis carried out improperly results in hundreds of risks that do not allow for sensible strategic decisions in cybersecurity management.
Essential and critical entities must notify their competent authority without undue delay of any significant incident. Where an incident is likely to affect adversely the provisioning of their services, they must also inform the recipients of those services without undue delay.
A significant incident is an incident which has caused or is likely to cause severe disruption to the operation of the services or financial loss to the organisation or which has affected or is likely to affect other natural or legal persons by causing them significant material or non-material damage. From this vague specification, it is quite clear that almost any incident can be categorised as significant.
Notifying an incident must be made immediately but no later than 24 hours after discovery. To meet this requirement, an organisation must set up processes, responsibilities, and tools to ensure timely incident reporting.
This mechanism helps ensure that the relevant authorities have timely and sufficient information about current incidents and threats to other entities. This information should then be provided to other actors to improve readiness and response to incidents in the EU.
What Are the Specifics for the Czech Republic?
The Czech Republic is updating the Act on Cyber Security to align with the NIS2 Directive. The current draft is available for review, although it may change the legislative process. Based on the existing draft of the updated Regulation on Regulated Services, organisations can determine whether they are classified as significant or essential entities and will thus be subject to distinct regulatory requirements. The revised legislation is expected to come into effect by October 2024.
In the Czech Republic, NÚKIB (National Cyber and Information Security Agency) estimates an increase in the regulated subjects from 400 to more than 6,000 entities. However, the final number may be even higher.
How to Implement NIS2 into Your Practice?
The first step is to conduct a gap analysis. This analysis assesses the current state of information security management and the measures implemented in your organisation against the legislation. Rather than the general NIS2 regulation, it is advisable to assess compliance with its local implementation in the country in which your organisation operates.
Once you know your gaps, you can propose and implement measures to address them. Without a quality gap and risk analysis, the implementation of measures lacks the necessary order and priorities.
NIS2 brings about significant qualitative changes in cybersecurity's legislative and procedural aspects. Learn more about our collaboration, and if you are still determining how NIS2 will affect you or need help knowing where to implement mandatory measures, feel free to contact us. We would be happy to assist you with its complete implementation.
Prepare for NIS2 in Time with Us
Right in Your Inbox
Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.