Home Solutions Services About Us Discovery Contact Us

Strawinskylaan 411 1077XX,
Amsterdam, Netherlands

Wilhelmina van Pruisenweg 35,
2595 AN Den Haag

+31 6 11 10 62 26

[email protected]

Are You Ready for the NIS-2 Directive?

The European Union is bolstering its member states’ cybersecurity with the NIS-2 Directive (Network and Information Systems Security Directive), which will be fully enforceable from October 2024. NIS-2 obliges the management of the organizations to take responsibility regarding their cybersecurity maturity. Penalties for non-compliance, including fines of up to 10% of an entity's annual turnover. Now is the time for companies to assess their readiness for the NIS-2 Directive and take proactive steps to ensure compliance.
How Netsmart Can Help?
+
How Netsmart Can Help?
+
How Netsmart Can Help?
+
How Netsmart Can Help?

Our approach includes

Netsmart’s consulting services and solutions are designed to support organizations in implementing the NIS-2 Directive effectively and efficiently.

We help you assess your readiness, define your roadmap to compliance, identify your scope, set up and implement your risk and security management frameworks, secure your IT supply chain and optimize your cybersecurity awareness program.

A typical NIS-2 compliance process, including security assessments, auditing, consulting, and tool implementation, takes 6 to 12 months (depending on the size of the organization).

Take Action Now. Contact Netsmart today and let us help you navigate the complexities of the NIS-2 Directive.

Analysis

An in-depth analysis to assess the impact of the guidelines on your organization.

Readiness Assessment

Evaluation of the current status of your regulatory security measures.

Gap Assessment

Identification of gaps in your technology and processes, defining necessary measures to ensure successful compliance with the NIS-2 Directive.

Roadmap

Development of a roadmap considering your company’s individual cyber risks.

Cyber Governance

Supporting your company in mitigating risks and implementing appropriate security measures.

Reporting

Analysis and evaluation of existing processes to develop a customized reporting process.

Training

Customized workshops and training sessions, providing practical insights and knowledge to ensure that participants gain the knowledge required to effectively implement the NIS-2 Directive.

Sectors Affected By The NIS2 Directive

The directive defines two categories for entities in scope: important and essential.

Essential Entities
Energy, Transport, Finance, Healthcare, Water, Digital Infrastructure, Public Administration, Space Activities

Important Entities
Postal Services, Waste Management, Chemicals, Food, Manufacturing, Digital Providers, Research

Entities in both categories will have to meet the same requirements. However, the distinction will be in the supervisory measures and penalties. Essential entities will be required to meet supervisory requirements as of the introduction of NIS-2, while the important entities will be subject to ex-post supervision, meaning that in case authorities receive evidence of non-compliance, action is taken.

Understanding the NIS-2 Directive

The NIS-2 Directive (Network and Information Systems Security Directive) aims to establish harmonized requirements across the EU to enhance resilience against cyber-attacks and improve responses to multinational incidents. As the scope extends to additional sectors, the cybersecurity capabilities of affected institutions will be rigorously tested.

Who Does it Apply To?

The directive categorizes entities into two groups: essential and important.

Essential Entities
These entities are critical to national infrastructure and include sectors like energy, transportation, finance, healthcare, and digital services.

Important Entities
This category encompasses a broader range of businesses, including postal services, waste management, manufacturing, and digital providers.

Both categories will have similar cybersecurity obligations. However, the enforcement approach differs slightly:

Essential Entities
Stricter supervision applies from the outset of NIS-2.

Important Entities
Supervision occurs after the fact (ex-post), meaning authorities may investigate potential non-compliance upon receiving evidence.

Expanded Scope

The directive simplifies how authorities determine which businesses fall under its umbrella. Large (headcount over 250 or more than 50 million revenue) and medium-sized (headcount over 50 or more than 10 million revenue) enterprises within defined sectors are automatically included in the scope. tly included in the scope.Member States also retain the authority to extend these requirements to smaller businesses deemed critical to specific sectors or services.

Management Accountability

The NIS-2 Directive assigns accountability to the management of organizations in scope. It is mandatory for management to take responsibility for their cybersecurity maturity. This includes conducting risk assessments and approving risk treatment plans for implementation, among other tasks.

To perform these actions, management must undergo cybersecurity training. The Directive even suggests training not only management but also employees, for a more comprehensive understanding of cybersecurity.

Increased Penalties

NIS-2 introduces stricter penalties for non-compliance, with fines potentially reaching a significant percentage of an entity’s annual turnover.

Essential Entities
Maximum fines can reach €10 million or 2% of annual turnover (whichever is higher).

Important Entities
Maximum fines can reach €7 million or 1.4% of annual turnover (whichever is higher).