NIS2: The EU’s new cyber security legislation
Blog|by Leanne Bevan|13 April 2023
What is NIS2?
The Network and Information Systems Directive (NIS2) is a new European Union (EU) legislation aimed at strengthening the cyber security of critical infrastructure providers and digital service providers. The directive aims to ensure that these entities take the necessary measures to prevent and manage cyber security incidents.
Which industries need to comply with NIS2?
NIS2 builds upon the first NIS directive, which was adopted in 2016. The original directive established a set of requirements for the cyber security of operators of essential services in critical sectors, such as energy, transport, healthcare, and finance. NIS2 extends the scope of the directive to include digital service providers, such as cloud service providers, search engines, and online marketplaces.
The directive mandates that critical infrastructure providers and digital service providers must take adequate measures to manage cyber security risks and prevent cyber security incidents. They are required to implement robust cyber security strategies, including risk management, incident management, and business continuity plans.
NIS2 also requires these entities to report significant cyber security incidents to competent authorities within 24 hours of detection. The competent authorities are responsible for enforcing the NIS2 directive in their respective countries and ensuring compliance with the requirements.
One of the key features of NIS2 is the establishment of a European Cybersecurity Competence Centre (ECCC) and a European Cybersecurity Industrial, Technology and Research Competence Centre (ECITRC). The ECCC is responsible for developing and promoting cyber security knowledge and expertise across the EU, while the ECITRC is responsible for developing and promoting cyber security technologies and innovation.
NIS2 is a crucial step in strengthening the cyber security of critical infrastructure providers and digital service providers in the EU. The directive aims to create a more secure and resilient digital environment, which is essential for the functioning of the EU economy and society.
The challenges
However, compliance with NIS2 can be challenging for many organisations, especially small and medium-sized enterprises (SMEs). SMEs may lack the necessary resources and expertise to implement the required cyber security measures, and they may struggle to report cyber security incidents to competent authorities within the required timeframe.
To address these challenges, the EU has established a support programme for SMEs called the Cyber Security Competence Centre for SMEs (CC-SME). The programme provides SMEs with access to cyber security expertise, training, and support to help them comply with the NIS2 directive.
Key takeaways about NIS2
The NIS2 directive is a critical step in improving the cyber security of critical infrastructure providers and digital service providers in the EU. The directive aims to create a more secure and resilient digital environment, which is essential for the functioning of the EU economy and society. However, compliance with the directive can be challenging for many organisations, especially SMEs. The EU’s support programme for SMEs aims to address these challenges by providing them with access to cyber security expertise, training, and support.
How Grey Matter can help you with cyber security and compliance with NIS2
Grey Matter partners with several leading and niche cyber security software companies that can provide many of the cyber security solutions required to help you comply with NIS2. For instance, we can help you with cyber security training, endpoint detection and response software or managed services, patch management, firewalls and more.
Our cyber security specialists are on hand to answer any questions you have and are there to ensure you have the right tools and licensing needs to effectively secure your business and comply with regulations.
Fill in the form below to arrange a call with one of our specialists.
Contact Grey Matter
If you have any questions or want some extra information, complete the form below and one of the team will be in touch ASAP. If you have a specific use case, please let us know and we'll help you find the right solution faster.
By submitting this form you are agreeing to our Privacy Policy and Website Terms of Use.
Author
Leanne Bevan
Vendor Marketing Manager at Grey Matter
Leanne has been part of our team for over a decade, and has worked as a vendor marketing manager for a number of our key vendors. Now with a keen focus on cyber security as well as developer technologies, Leanne continues to manage marketing across several vendors, including Embarcadero, Acronis, ESET, and more.
Related News
Data security in a cloud and AI world
Cloud and AI are hot topics in the technology industry. But what are the security implications and considerations your business needs to keep front of mind? In this episode of our podcast Grey Matter Talks Tech, our security expert Scott...
New release: RAD Studio 13.1 Florence
What’s new in RAD Studio 13.1 Florence? The latest version of Embarcadero’s RAD Studio is here. This release focuses on future-proofing your development environment, streamlining the design process, and ensuring your applications meet the latest Google and Apple mobile store...
Beyond vibe coding: JetBrains Junie – agentic AI for developers
Explore agentic AI for developers and JetBrains’ approach with Junie AI In this episode of Grey Matter Talks Tech, Leanne Bevan is joined by JetBrains’ Nick Frolov to delve into how AI is changing software development. They discuss JetBrains’ approach...
AI security in 2026: How to stay ahead
AI adopter vs. builder vs. scaler security stacks – and the threats leaders can’t ignore In this episode of Grey Matter Talks Tech, Gail Lundgren is joined by Shannon Murphy (Trend AI) to unpack the biggest cyber security threats facing organisations in...