EU’s NIS2 Directive Tightens Cybersecurity with Stricter Rules and Fines

The Network and Information Systems Directive (NIS2) takes effect on the 17th of October as the EU’s latest efforts to enhance cybersecurity across member states. Building on the original directive in 2016, NIS2 expands across critical sectors including energy, healthcare, transport and digital infrastructure and introduces stricter cybersecurity requirements for organisations classified

Facebook
LinkedIn
X

The Network and Information Systems Directive (NIS2) takes effect on the 17th of October as the EU’s latest efforts to enhance cybersecurity across member states.

Building on the original directive in 2016, NIS2 expands across critical sectors including energy, healthcare, transport and digital infrastructure and introduces stricter cybersecurity requirements for organisations classified as either ‘essential’ or ‘important’ entities.

Key provisions of NIS2 include mandatory risk assessments, enhanced supply chain security measures and a robust incident reporting process.

Cybersecurity incidents must be reported in three stages starting with an initial alert within 24 hours, a detailed report within 72 hours and a comprehensive final report within a month.

This structured reporting aims to improve threat monitoring and response coordination across the EU.

The directive also introduces severe penalties for non-compliance, with fines of up to €10 million or 2 per cent of global annual revenue, and for the first time, senior management can be held personally liable for security breaches caused by negligence.

This shift emphasises the shared responsibility for cybersecurity beyond IT departments.

NIS2 applies not only to EU-based organisations but also to any business operating within the EU, regardless of where they are headquartered, significantly expanding its global reach.

To prepare for NIS2, organisations must assess their cybersecurity vulnerabilities, including those in their supply chains, and establish plans to ensure business continuity in the event of an incident.

Sridhar Iyengar, Managing Director, Zoho Europe commented: “NIS2 is a welcome roadmap for the future of cybersecurity, putting further guardrails in place to safeguard digital operations amid the fast pace of technology evolution. Cyber threats are becoming increasingly frequent and sophisticated, demanding a proactive approach to cybersecurity that prioritises safety and privacy.”

“Additional safety measures are crucial to protect businesses and their customers, so businesses must ensure they have full awareness and comply with new security regulations introduced. Stricter reporting and fines of up to €10 million for non-compliance mean that businesses cannot afford to lag behind.”

“Customer data privacy and protection has always been at the heart of what we do so we welcome the enforcement of stronger access control measures within organisations to protect confidential data. Steps businesses can take to prepare for October’s NIS2 launch include considering the recommended use of multi-factor authentication, introducing a robust browser to help minimise exposure to ransomware attacks, offering a robust password management solution and ensuring systems offer control measures to manage conditional access to confidential data.”

“It is also important that organisations create awareness of the new regulations among their entire employee-base and host any new training required to ensure guidelines are followed by all. This corporate accountability is not just the right thing to do, but also forms part of the new Directive.”

Facebook
LinkedIn
X

Related Stories from Silicon Scotland

Other Stories from Silicon Scotland