Regulatory requirements for all organisations: NIS2 (Europe) and the IT Security Act (Germany)
The entry into force of the EU-wide ‘Network and Information Security’ (NIS2) Directive brings with it new regulations and security requirements that must be implemented by October 2024. Compared with the first version of NIS, NIS2 significantly broadens the scope of affected organisations, their obligations and regulatory oversight.
- The directive applies to all organisations with 50 or more employees and an annual turnover of EUR 10 million. Certain operators, such as those managing digital infrastructure or working in public administration, are to be regulated regardless of their size.
- Under NIS2, 18 different sectors are classified as critical infrastructure. These include providers of public electronic communications networks and services, data centre services, wastewater and waste management, the manufacture of critical products, postal and courier services, and public administration bodies. However, certain areas of the healthcare sector and research are also subject to the directive, for example where the development and manufacture of medicinal products are concerned. There is some discretion in the case of smaller companies belonging to one of these sectors.
- The NIS2 Directive tightens the requirements for cyber security risk management, which organisations are obliged to comply with. Organisations must implement technical, operational and organisational measures. This includes, for example, establishing policies on risk and information security, setting up an incident management system, implementing authentication measures, providing training for staff, and setting out guidelines for encryption and emergency communication. It is also essential to ensure the security of the entire supply chain, right down to secure development at suppliers.
- Breaches of the regulations may result in fines of up to EUR 10 million or two per cent of global turnover.
The European NIS2 Directive is being incorporated into the German IT Security Act.
Regulatory framework for KRITIS: BSI Act
Operators of critical infrastructure, as well as energy supply networks and energy facilities, have been obliged since 1 May 2023 to implement intrusion detection systems as part of their organisational and technical safeguards.
The attack detection systems (SzA) used must continuously and automatically record and evaluate suitable parameters and characteristics from day-to-day operations. They should be capable of continuously identifying and preventing threats, as well as providing for appropriate remedial measures in the event of incidents.
- From 1 May 2025 at the latest, KRITIS operators (excluding the energy sector) will be subject to a duty to provide evidence to the Federal Office for Information Security. For operators of energy supply networks and energy facilities, this requirement already came into force on 1 May 2023.
- This obligation to provide evidence must be fulfilled every two years using a maturity model.
- The BSI has published guidance for affected organisations, which sets out the requirements for providing this evidence.
- The requirements cover general technical, organisational and personnel frameworks, such as gathering information on current attack patterns or establishing processes for effective attack detection, as well as logging, detecting security-related incidents and responding appropriately.
Regulatory framework in the banking sector: the ‘Digital Operational Resilience Act’ (DORA)
DORA came into force in January 2023. Following a two-year implementation period, the regulation will be enforceable from January 2025. Non-compliance may result in severe penalties for financial institutions and providers of information and communication technologies (ICT service providers). These can include fines of up to one per cent of global daily turnover.
This new and far-reaching European Union regulation sets out specific requirements for IT operations. In addition to financial firms themselves, the ICT service providers they use now also fall within the scope of the regulation. The aim is to require a holistic approach to the digital operational stability of financial firms, in order to make their IT systems more resilient to external and internal disruptions and thereby strengthen business continuity.
The DORA Regulation can essentially be divided into the following key areas:
- Risk management and operational resilience of the organisation’s own ICT departments
- Management of ICT-related incidents and their reporting to the authorities
- Regular internal and external resilience testing, as well as its planning and documentation
- Monitoring of risks, including those posed by third-party ICT providers
These key areas will be further specified by mid-2024 in various documents relating to the Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS).
The requirements under DORA are based on existing national regulations, such as the ‘Banking Supervisory Requirements for IT’ (BAIT) and the ‘Insurance Supervisory Requirements for IT’ (VAIT), or the ‘Minimum Supervisory Requirements for the Business Organisation of Insurance Undertakings’ (MaGo) and the ‘Minimum Requirements for Risk Management’ (MaRisk).
You can find out how the diverse requirements of the various guidelines and laws can be implemented in a way that is as seamless and coherent as possible in further posts in this blog series.
All posts from the “Cyber Security 2024” blog series:
- It will affect us all eventually – mandatory IT security requirements for 2024
- Improving resilience: How to make your IT a rock-solid foundation
- Intelligent attack detection with a Security Information and Event Management (SIEM) system
- Responding more quickly to attacks with SecOps – Part 1
- Responding more quickly to attacks with SecOps – Part 2
- Responding more quickly to attacks with SecOps – Part 3
- NIS2 Directive: Implementing legislation not yet in sight – what organisations should do now