Elena Canorea
Communications Lead
Intro
In a world where digitalization is advancing by leaps and bounds, data protection and regulation compliance have never been more crucial. In this scenario, the European NIS2 Directive has emerged, which affects a large part of the organizations in the EU Member States and is mandatory as of 17 October 2024.
If you do not want to suffer sanctions or be left out of its important implementation, read on. We have compiled the key data to familiarise you with the regulation and advise you to introduce it in your company as soon as possible.
The Network and Information Security 2 Directive (NIS2) is a piece of legislation that seeks to establish a uniformly high level of cybersecurity across all member states of the European Union.
It establishes obligations to be adopted by those entities that fall within its scope and focuses on three main areas:
This regulation represents a significant advance in EU cybersecurity.
As we said at the beginning, 17 October is the deadline for the transposition of the NIS2 directive and the complexity of the new obligations imposed by the regulation and the possible penalties for non-compliance are the main concerns of companies.
Among the most important measures to be adopted are the implementation of security policies and risk analysis, incident management, business continuity, supply chain security, and incident reporting. All of these will be proportional to the risks to which the company is exposed, the size of the entity, and the seriousness of the incidents that may occur.
The main changes and obligations are as follows:
The NIS2 introduces a significant change in the way organizations that must comply with their cybersecurity obligations are classified, which we discuss in detail in the following section.
Whereas the NIS Directive differentiated between operators of essential services and digital service providers, leaving it to each EU Member State to decide which entities fall into these categories, NIS2 seeks greater uniformity and clarity. Organizations are now divided into essential and important entities, using criteria such as the sector in which they operate, their size, and their annual turnover. This classification is clearer and more uniform at the European level, reducing inconsistencies in application by individual states.
This regulation significantly broadens its scope of action compared to the previous version, mainly by identifying new sectors considered as ‘high criticality’ or ‘critical’. These sectors are fundamental to day-to-day activities and their disruption could have a severe impact on economic and social life.
This extension has resulted in many more organizations being subject to compliance with these measures.
The main objective of this directive is to raise security standards across the EU and to achieve this, specific risk assessment criteria have been introduced, as well as increased requirements for security measures and risk management.
One of the key aspects is the focus on supply chain security, as any vulnerability in the supply chain can compromise the security of the entire ecosystem.
Incident management is also strengthened, requiring stricter incident reporting procedures and the need for rapid and accurate reporting.
This encourages the development of a robust incident reporting framework and promotes greater public-private collaboration, improving responsiveness and resilience to potential cyber threats.
NIS2 imposes more severe financial penalties as a deterrent for organizations that do not comply with risk management or reporting measures.
These can range from 1.4% to 2% of total annual global turnover depending on the size of the company.
This updated directive has considerably broadened the scope of application compared to the original 2016 version. In addition, the NIS2 introduces a new classification that divides the sectors of application into two categories:
In addition to the classification by sector, this directive also introduces an additional classification of specific entities:
The category to which each entity belongs has important practical implications, as the activities of those classified as ‘essential’ will be subject to much stricter and proactive supervision, such as random raids, essential security checks, and requests for proof of compliance.
In fact, in case of non-compliance with the NIS2, critical entities may face a fine of up to EUR 10 million or 2% of their annual global turnover.
Entities classified as ‘significant’ are subject to slightly less stringent controls, but may face penalties of up to €7 million or 1.4% of turnover.
If you are one of the organizations that must comply, you need to understand your compliance and reporting obligations and find a partner to help you along the way. For example, you must notify the authorities of any significant cyber threats you identify that could result in a major incident.
In fact, the NIS2 imposes phased notification obligations for incidents that have a ‘significant impact’ on the provision of your services. These notifications must be made to the relevant competent authority or to the CSRT (Computer Security Incident Response Team).
Furthermore, to promote standardization of standards, without imposing or discriminating in favor of the use of a particular type of technology, the use of relevant European and international standards and technical specifications for network and information systems security is encouraged.
In order to comply with all of the above, here are the recommended steps to follow:
As you will have guessed after reading the article, most companies are subject to this regulation and will have to hurry to implement it to avoid penalties. So, to summarise, the first thing to do is to assess whether and to what extent the NIS2 requirements apply to your organization.
The next step is to further investigate how this Directive has been transposed into national legislation in your state and follow the recommendations of the national cybersecurity authorities. Once you have reached this point, assess and develop technical, operational, and organizational measures for network and IT systems management, security risks, etc.
But if all this is overwhelming, Plain Concepts is here to help. With many years of experience in cyber security, we can be your best partner in strengthening your commitment to security and compliance.
Our cybersecurity experts can help you reduce the likelihood and impact of a cyber incident and ensure compliance with NIS2. They will advise you on how to strengthen your security strategy through proactive defense and the implementation of tools such as Microsoft Purview, which will become an essential ally, providing robust security and compliance protections, as well as helping you adapt to and comply with NIS2 requirements.
Elena Canorea
Communications Lead
Cookie | Duration | Description |
---|---|---|
__cfduid | 1 year | The cookie is used by cdn services like CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. |
__cfduid | 29 days 23 hours 59 minutes | The cookie is used by cdn services like CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. |
__cfduid | 1 year | The cookie is used by cdn services like CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. |
__cfduid | 29 days 23 hours 59 minutes | The cookie is used by cdn services like CloudFare to identify individual clients behind a shared IP address and apply security settings on a per-client basis. It does not correspond to any user ID in the web application and does not store any personally identifiable information. |
_ga | 1 year | This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. |
_ga | 1 year | This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. |
_ga | 1 year | This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. |
_ga | 1 year | This cookie is installed by Google Analytics. The cookie is used to calculate visitor, session, campaign data and keep track of site usage for the site's analytics report. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. |
_gat_UA-326213-2 | 1 year | No description |
_gat_UA-326213-2 | 1 year | No description |
_gat_UA-326213-2 | 1 year | No description |
_gat_UA-326213-2 | 1 year | No description |
_gid | 1 year | This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the wbsite is doing. The data collected including the number visitors, the source where they have come from, and the pages viisted in an anonymous form. |
_gid | 1 year | This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the wbsite is doing. The data collected including the number visitors, the source where they have come from, and the pages viisted in an anonymous form. |
_gid | 1 year | This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the wbsite is doing. The data collected including the number visitors, the source where they have come from, and the pages viisted in an anonymous form. |
_gid | 1 year | This cookie is installed by Google Analytics. The cookie is used to store information of how visitors use a website and helps in creating an analytics report of how the wbsite is doing. The data collected including the number visitors, the source where they have come from, and the pages viisted in an anonymous form. |
attributionCookie | session | No description |
cookielawinfo-checkbox-analytics | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Analytics" category . |
cookielawinfo-checkbox-necessary | 1 year | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-necessary | 1 year | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-non-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Non Necessary". |
cookielawinfo-checkbox-non-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Non Necessary". |
cookielawinfo-checkbox-non-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Non Necessary". |
cookielawinfo-checkbox-non-necessary | 1 year | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Non Necessary". |
cookielawinfo-checkbox-performance | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to store the user consent for cookies in the category "Performance". |
cppro-ft | 1 year | No description |
cppro-ft | 7 years 1 months 12 days 23 hours 59 minutes | No description |
cppro-ft | 7 years 1 months 12 days 23 hours 59 minutes | No description |
cppro-ft | 1 year | No description |
cppro-ft-style | 1 year | No description |
cppro-ft-style | 1 year | No description |
cppro-ft-style | session | No description |
cppro-ft-style | session | No description |
cppro-ft-style-temp | 23 hours 59 minutes | No description |
cppro-ft-style-temp | 23 hours 59 minutes | No description |
cppro-ft-style-temp | 23 hours 59 minutes | No description |
cppro-ft-style-temp | 1 year | No description |
i18n | 10 years | No description available. |
IE-jwt | 62 years 6 months 9 days 9 hours | No description |
IE-LANG_CODE | 62 years 6 months 9 days 9 hours | No description |
IE-set_country | 62 years 6 months 9 days 9 hours | No description |
JSESSIONID | session | The JSESSIONID cookie is used by New Relic to store a session identifier so that New Relic can monitor session counts for an application. |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
viewed_cookie_policy | 1 year | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
viewed_cookie_policy | 1 year | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
VISITOR_INFO1_LIVE | 5 months 27 days | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
wmc | 9 years 11 months 30 days 11 hours 59 minutes | No description |
Cookie | Duration | Description |
---|---|---|
__cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
sp_landing | 1 day | The sp_landing is set by Spotify to implement audio content from Spotify on the website and also registers information on user interaction related to the audio content. |
sp_t | 1 year | The sp_t cookie is set by Spotify to implement audio content from Spotify on the website and also registers information on user interaction related to the audio content. |
Cookie | Duration | Description |
---|---|---|
_hjAbsoluteSessionInProgress | 1 year | No description |
_hjAbsoluteSessionInProgress | 1 year | No description |
_hjAbsoluteSessionInProgress | 1 year | No description |
_hjAbsoluteSessionInProgress | 1 year | No description |
_hjFirstSeen | 29 minutes | No description |
_hjFirstSeen | 29 minutes | No description |
_hjFirstSeen | 29 minutes | No description |
_hjFirstSeen | 1 year | No description |
_hjid | 11 months 29 days 23 hours 59 minutes | This cookie is set by Hotjar. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. |
_hjid | 11 months 29 days 23 hours 59 minutes | This cookie is set by Hotjar. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. |
_hjid | 1 year | This cookie is set by Hotjar. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. |
_hjid | 1 year | This cookie is set by Hotjar. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID. |
_hjIncludedInPageviewSample | 1 year | No description |
_hjIncludedInPageviewSample | 1 year | No description |
_hjIncludedInPageviewSample | 1 year | No description |
_hjIncludedInPageviewSample | 1 year | No description |
_hjSession_1776154 | session | No description |
_hjSessionUser_1776154 | session | No description |
_hjTLDTest | 1 year | No description |
_hjTLDTest | 1 year | No description |
_hjTLDTest | session | No description |
_hjTLDTest | session | No description |
_lfa_test_cookie_stored | past | No description |
Cookie | Duration | Description |
---|---|---|
loglevel | never | No description available. |
prism_90878714 | 1 month | No description |
redirectFacebook | 2 minutes | No description |
YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
yt-remote-connected-devices | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
yt-remote-device-id | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
yt.innertube::nextId | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |
yt.innertube::requests | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |