22.06.2023
Blog
Europe
Regulatory
Cyber Security

NIS2 – Greater cyber security for the EU

The entry into force of the new EU-wide NIS2 Cybersecurity Directive brings with it new regulations and security requirements for businesses. The first Europe-wide directive establishing a common level of cybersecurity (NIS), which dates from 2016, was expanded in 2023 to include a number of additional provisions. Below, we explain which sectors are subject to this expanded directive and what businesses and public authorities must now do.

Heike Abels
Referentin für Unternehmenskommunikation

Increasing digital interconnectivity and digitalisation mean that attackers, too, are focusing more and more on digital targets. The NIS Directive (Network and Information Security) was introduced several years ago to ensure a common level of cyber security across the EU. Due to the further escalation of threats in the digital sphere, the EU refined and expanded the directive at the start of this year. The directive aims to better protect critical sectors and infrastructure within the EU and make them more secure. To achieve this, it is necessary to tighten security requirements for organisations swiftly and consistently, as attackers, too, are constantly developing new strategies. Organisations subject to the Directive must act now, as the timeline stipulates that the requirements must be transposed into national law by autumn 2024 at the latest. But which companies are actually affected, and what is required of them?

Inclusion of further sectors

The NIS2 Directive goes beyond the first version of the directive and now covers additional sectors that are of crucial importance to the economy and society. These include providers of public electronic communications networks and services, data centre services, wastewater and waste management, the manufacture of critical products, postal and courier services, and public administration bodies. Certain areas of the healthcare sector and research are also subject to the Directive, for example where the development and manufacture of medicinal products are concerned. The number of critical sectors has risen to seven. The number of important sectors has grown to eleven. There are now 18 different sectors classified as critical infrastructure. The Directive applies to all organisations with 50 or more employees or a turnover of EUR 10 million or more. Certain operators, such as those in the digital infrastructure sector or in public administration, are to be regulated regardless of their size. They are all subject to the prescribed security standard. For smaller companies operating in one of these sectors, there is some discretion, meaning they are only bound by certain cyber security obligations.

Enhanced security requirements

What security requirements does the EU-wide directive now impose on companies and public authorities? Here, too, the second version of the directive goes further than the first. The NIS2 Directive tightens the requirements for cyber security risk management, which companies are obliged to comply with. Organisations must implement technical, operational and organisational measures to manage cyber security risks and minimise the impact of potential incidents. To meet this requirement, NIS2 sets out specific, targeted measures, such as guidelines on risks and information security, the establishment of an incident management system, authentication measures, staff training, and requirements for encryption and emergency communication. Another new requirement is the need to secure the entire supply chain, right through to secure development at suppliers.

Strengthening cooperation

To improve the exchange of information and cooperation in managing cyber crises at both national and EU level, the Directive sets out precise reporting obligations for incidents. Those affected must immediately notify their national cyber security authority of significant disruptions, incidents and cyber threats – as well as their customers. In addition, there are stricter supervisory measures for national authorities, as well as stricter enforcement requirements and a list of administrative sanctions, including fines for breaches of cyber security risk management and reporting obligations.

What’s next?

Member States have until October 2024 to transpose the NIS2 Directive into national law. During this period, Member States will adopt and publish the measures necessary to comply with this Directive. In Germany, the IT Security Act 2.0 has already anticipated some changes, such as the expansion of the sectors covered. You can read more about this here. However, other provisions – such as the application of certain measures to medium-sized and large enterprises – are still missing and must be implemented via an amending act or regulation.

NIS2 will therefore lead to a significant expansion of the organisations covered and, with its transposition into German law (the IT Security Act), open up new scope for action to comprehensively protect our critical infrastructure. To actually achieve a uniform cyber security standard within the EU, we need the combined efforts of businesses, public authorities and security specialists working closely together across national borders.

Heike Abels
Referentin für Unternehmenskommunikation

Heike Abels arbeitet bei Materna als Referentin für Unternehmenskommunikation. Sie betreut redaktionell verschiedene Formate für die externe Kommunikation. Thematischer Schwerpunkt ist der Bereich Cross Market Services. Dazu zählen Enterprise Service Management, Customer Service und Cyber Security.