Ready for NIS2?

Klaar voor NIS2?

By the end of 2024, that's when the new NIS2 directive comes into effect. And, just as with the arrival of the AVG, we mostly hear, "What am I supposed to do with that? A duty of care, duty of notification and risk of fines; the new directive has a major impact on organizations. How do you ensure that this impact will be positive, rather than negative? In this blog, we discuss what exactly the directive is and how you can prepare your company.

What is NIS2?

The NIS2 guideline, or the "Network and Information Security Directive 2," replaces the current NIS directive, implemented in the Netherlands as the WBNI (Wet Beveiliging netwerk- en informatiesystemen). The new directive sets rules for organizations in the European Union, with the goal of increasing resilience against all threats posed by hackers and malware. And this is much needed, because the development of cybercrime does not stand still 1.

Who does NIS2 apply to?

Whether your organization must comply with NIS2 depends on its size and sector. Is your organization "large" or "medium-sized" and falls under a "critical sector"? Then you must comply with NIS2. We explain this.

Your organization is "great" if it meets any of these conditions:

  • 250 employees or more
  • An annual turnover of more than 50 million euros and a balance sheet total above 43 million euros

Your organization is "medium-sized" if it meets any of these conditions:

  • 50-249 employees with annual sales of 10 to 50 million euros
  • 50-249 employees with a balance sheet total of 10 to 43 million euros

The critical sectors are shown in the table below. Your organization must therefore comply with NIS2 if it falls into one of these sectors and is a "large" or "medium" sized organization.

The exceptions are organizations that do not meet these but are still considered such, such as central government agencies, DNS service providers and public electronic communications network providers.  

Sectors characterized as 'critical sectors'

Central government: NIS2 Self-assessment NL

Not sure if your organization is covered by the directive? The central government has developed a tool to check whether the NIS2 directive applies to your organization: rule-helps-for-businesses.com/NIS-2-NL

What does my company need to comply with?

What is important to know is that as the board of your organization, you are liable for compliance. Do you fail to do so? Then you risk a fine. Some organizations are actively monitored for compliance with NIS2. Others are monitored reactively, that is, for example, when customers report a non-conformity Nonconformity is a situation where something does not meet the required standards. . Which method of control applies to your organization, our security consultants can determine for you.

This is what you should at least implement/implement in your organization:

  • Risk analysis
  • Incident handling
  • Business continuity policy
  • Supply chain security (in relationships/suppliers)
  • Measuring effectiveness of measures (KPIs).
  • Cyber hygiene and staff training
  • Policies and procedures on use of cryptography and encryption
  • Security aspects v. personnel, such as access policies and asset management
  • Security in acquisition, development and maintenance of network and information systems
  • Use of 2FA, secure emergency communication system, etc.

Should an incident occur, it must be reported to the supervisor within 24 hours.

The role of ISO 27001

To make your organization compliant with NIS2, we recommend that you adopt the standard ISO 27001 implement. With this standard, you not only meet the requirements of NIS2, but at the same time you build a management system (the ISMS) that maintains all the measures you have in place. Instead of writing a fist-thick policy document to comply with NIS2 that - let's face it - you store in a dresser drawer, setting up an ISMS ensures a clear process of continuous improvement.

Getting started!

Don't let the impact of NIS2 be negative and instead see the positive in it. Because with improved cyber resilience, you can prevent a lot of trouble. Less chance of viruses as well as fines. So take the steps now, so you can sit down to Christmas dinner in 2024 with peace of mind.

  1. https://www.abnamro.nl/nl/zakelijk/insights/cybersecurity/cyberaanval/aantal-bedrijven-getroffen-door-cyberaanval-gestegen-tot-45procent.html

This article was written by Margo Sportel. Do you need help or have any questions? If so, please feel free to contact us using the form below.