Navigating NIS 2 Compliance: Strengthening Cybersecurity in the Face of EU’s New Directive

Author

October 17th, 2024 marks the deadline for businesses across the European Union (EU) to adhere to the common cybersecurity framework detailed within the Network and Information Security (NIS) 2 Directive. This regulation is in response to increasingly critical cybersecurity concerns of governments and businesses alike and is aimed at enhancing the baseline IT security practices across the EU.

The initial NIS Directive from 2016 attempted to reduce vulnerabilities across deemed essential service and infrastructure sectors of the European economy but was plagued by shortcomings of inconsistent implementation and limited scope across member countries.

The NIS 2 Directive Expanded Scope

NIS 2 addresses these issues by broadening the list of companies required to meet its standards and strengthening incident reporting and enforcement provisions. In addition to essential service providers such as energy, transportation, banking, healthcare, and public infrastructure entities, the NIS 2 Directive expands its scope to now require digital service providers and companies working with sensitive data, such as personal or financial information, to meet baseline cybersecurity standards.

Though originating and enforced only in the EU, many larger US-based companies will be affected depending on their exposure and operations in European markets. These indirectly affected companies will also have to accommodate their risk management, incident response, and cybersecurity practices accordingly.

Notably, the NIS 2 Directive operates under 3 main provisions.

  1.  The first provision outlines risk management and incident reporting services in which mandated service providers must carefully and comprehensively measure risk relating to cybersecurity elements of their business. This includes considerations from any vendor or partnered third-party security practices and highlights the potentially massive indirect implication of the NIS 2 standards globally.
  2. The second provision sets the bar for minimum cybersecurity requirements, mandating measures which are up-to-date and widely accepted best practices including compulsory vulnerability reporting, security-by-design principles, and supply chain security assessment. Outdated or unpatched systems, phishing, and spear phishing efforts continue to be a preventable vector of cybercrime which the new directive aims to prevent on scale. This provision also places an increased emphasis on detection and reporting of cybersecurity incidents to national tracking centers, providing proactive enhanced warning protection through awareness across the European continent.
  3. The third provision supports legal enforcement and defines non-compliance penalties, both of which will be enforced by the EU-member countries. Since January 2023, the individual governments comprising the European Union have been working to codify NIS 2 principles into law, supporting consistent enforcement across the Union. This distributed but standard enforcement model includes fines of up to €10 million or 2% of global turnover for non-compliance.

Liberty Advisor Group Provides Objective Advice

Among the several service offerings Liberty Advisor Group advises its clients on, objective analysis and consulting on cybersecurity frameworks, which support business operations, is foundational to the mission and unique expertise Liberty possesses. The best security practices may not always be the same depending on the market or vertical a business operates in, but they all tend to rhyme which is how Liberty is able to take insights across economic sectors and apply them in a tailored fashion.

Through technical evaluation, risk identification, and traditional evidence gathering, Liberty has helped portfolio companies increase the efficacy and sophistication of their IT security and advocate for greater visibility for an often overlooked or dismissed aspect of every business – it’s cyber and IT footprint practices.

About Liberty Advisor Group

Liberty Advisor Group is a goal-oriented, client-focused, and results-driven consulting firm. We are a lean, handpicked team of strategists, technologists, and entrepreneurs – battle-tested experts with a steadfast, start-up attitude. We collaborate, integrate, and ideate in real-time with our clients to deliver situation-specific solutions that work. Liberty Advisor Group has the experience to realize our clients’ highest ambitions. Liberty has been named as Great Place to Work.

References

Yannick Scheelen, Koen Machilsen, Andy Deprez, “How to prepare for the NIS 2 Directive?,” EY, 2023. [Online]. Available: https://www.ey.com/en_be/cybersecurity/how-to-prepare-for-the-nis2-directive

“The NIS 2 Directive,” [Online]. Available: https://www.nis-2-directive.com.

M. Negreiro, “The NIS 2 Directive: A high common level of cybersecurity in the EU,” European Parliamentary Research Service.

Author

Add insights to your inbox

Get the latest in leadership news delivered straight to your inbox with our weekly newsletter.