{"id":73164,"date":"2024-10-01T13:34:38","date_gmt":"2024-10-01T11:34:38","guid":{"rendered":"https:\/\/www.cocus.com\/new-security-requirements-directive-nis2-what-companies-should-know\/"},"modified":"2024-10-11T17:16:02","modified_gmt":"2024-10-11T15:16:02","slug":"nis2-security-requirements-for-companies","status":"publish","type":"post","link":"https:\/\/www.cocus.com\/en\/nis2-security-requirements-for-companies\/","title":{"rendered":"New security requirements: Directive NIS2 &#8211; what companies should know"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"73164\" class=\"elementor elementor-73164 elementor-72840\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-64f56580 elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"64f56580\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2226542f lottie-bg-no\" data-id=\"2226542f\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-205e869 elementor-widget elementor-widget-text-editor\" data-id=\"205e869\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>From spring 2025<\/strong>, compliance with the NIS2 directive is expected to be mandatory for many affected companies in Germany. The regulation strengthens security measures for critical infrastructures and IT service providers. Whether energy, transport, healthcare or even the manufacturing industry &#8211; the law will have an impact on a large number of companies.  <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30e656a elementor-widget elementor-widget-text-editor\" data-id=\"30e656a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Starting in October 2024, countries will have to adopt NIS2, the latest EU directive on cybersecurity, into national law. We show how NIS2 will affect companies and how to comply with the regulations safely.   <\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-26c26fe elementor-widget elementor-widget-text-editor\" data-id=\"26c26fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW222997090 BCX4\" lang=\"DE-DE\" xml:lang=\"DE-DE\" data-contrast=\"none\"><span class=\"NormalTextRun SCXW222997090 BCX4\">Not in the mood to read? You can also watch our <a href=\"https:\/\/www.cocus.com\/en\/webinar-nis2-security-requirements\/\">webinar.<\/a><\/span><\/span><span class=\"EOP SCXW222997090 BCX4\" data-ccp-props=\"{}\"> <\/span><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1d8961b elementor-section-full_width elementor-section-height-default elementor-section-height-default lottie-bg-no\" data-id=\"1d8961b\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c89cfa8 lottie-bg-no\" data-id=\"c89cfa8\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;enable_lottie_background&quot;:&quot;no&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2e0e607 elementor-widget elementor-widget-heading\" data-id=\"2e0e607\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">What is behind the NIS2 guideline?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3bb5867 elementor-widget elementor-widget-text-editor\" data-id=\"3bb5867\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The abbreviation NIS stands for &#8220;Network and Information Systems Security Act&#8221;. Network and information security includes, but is not limited to, protecting computer networks, information systems, and data from unauthorized access, misuse, disclosure, destruction, or failure. The general goal of network and information security is to ensure the confidentiality, integrity and availability of information and systems. Various technologies, processes and methods are used for this purpose.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-07b2930 elementor-widget elementor-widget-text-editor\" data-id=\"07b2930\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>&#8220;NIS2&#8221; refers to the second stage of the EU Directive for NIS. The first NIS Directive already establishes a common security framework for network and information systems within the EU. It requires member states to establish national cybersecurity policies and regulations and requires operators of essential services and digital service providers to take appropriate security measures and report incidents.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28bd70f elementor-widget elementor-widget-text-editor\" data-id=\"28bd70f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NIS2 builds on NIS1, expanding the scope of the directive and the requirements placed on the security of network and information systems. The expansion serves to further harmonize cybersecurity requirements within the EU. It also aims to further strengthen the resilience of critical infrastructure against cyberattacks.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c13fe6 elementor-widget elementor-widget-heading\" data-id=\"6c13fe6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">To which companies does the EU directive NIS2 apply?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-701e4f5 elementor-widget elementor-widget-text-editor\" data-id=\"701e4f5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The more stringent security requirements for network and information systems in the NIS2 Directive are aimed at providers or operators of services of general economic importance. NIS2 thus affects companies that are classified as operators of critical infrastructure or producers or service providers of significant economic importance. These include, for example, classic critical infrastructure operators such as energy providers, transport companies, healthcare service providers, digital service providers or online marketplaces and now also, for example, manufacturing industry in certain sectors or postal and courier services.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c52ef28 elementor-widget elementor-widget-text-editor\" data-id=\"c52ef28\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In addition, direct suppliers of IT products and services must also expect more stringent requirements: NIS2 places great emphasis on supply chain risk management, so increased cybersecurity requirements for suppliers can be expected. The exact definition and classification of the companies concerned will still be determined in the context of legal ordinances when they are implemented in German legislation.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-144b16e elementor-widget elementor-widget-heading\" data-id=\"144b16e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">What requirements does NIS2 bring with it?<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-75c203c elementor-widget elementor-widget-text-editor\" data-id=\"75c203c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NIS2 introduces stricter security requirements for affected companies. These include:<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-edfc81a elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"edfc81a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><b>Risk management and implementation of minimum cyber security requirements:<\/b> Effective risk management and implementation of cyber security requirements helps organizations identify and counter cyber threats early. What exactly this looks like can vary depending on the industry and the size of the company. These requirements include, but are not limited to, implementation of basic cyber hygiene procedures and cybersecurity training, regular software updates, access restrictions, encryption technologies, and monitoring of IT systems.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><b>Registration obligation:<\/b> Under the NIS2 Directive, affected companies are required to register with national authorities. The purpose of registration is to record and monitor relevant companies in order to improve safety standards and cooperation in the event of safety incidents.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><b>Duty to provide evidence:<\/b> Companies classified as \"particularly important companies\" will have a duty to provide evidence in the future. This means that they must provide evidence that they have implemented the required safety measures. Demonstrating implementation of the Minimum Cyber Security Requirements is critical to ensure compliance and avoid potential sanctions.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-circle\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M256 8C119 8 8 119 8 256s111 248 248 248 248-111 248-248S393 8 256 8z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><b>Security incident reporting and information:<\/b> The NIS2 directive places great emphasis on improved collaboration and information sharing in the event of security incidents. Affected companies are required to report significant security incidents to the authorities without delay. This information must include the nature of the incident, its impact, and the countermeasures taken. In some cases, information obligations to customers also exist.<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2df6438 elementor-widget elementor-widget-heading\" data-id=\"2df6438\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Preparation for NIS2 <\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-56cdc46 elementor-widget elementor-widget-text-editor\" data-id=\"56cdc46\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>To meet the requirements of the NIS2 directive, you can start preparing now:<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d3eeac2 elementor-widget elementor-widget-text-editor\" data-id=\"d3eeac2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>1. companies should inform themselves about the NIS2 directive and its requirements in order to find out whether their own company is classified as a critical infrastructure, operator or provider with economic significance. <br \/><br \/>2. A thorough inventory and gap analysis is the first step in assessing a company&#8217;s security situation. A responsible person should be appointed who has the task of identifying critical assets and recognizing possible security gaps. A comprehensive gap analysis can be used to assess the maturity level of IT security measures and uncover optimization potential. <br \/><br \/>3. In addition, cyber risk management plays a central role in compliance with the NIS2 directive. It is important to review existing policies or introduce new ones as appropriate to adequately assess and address risks. Risks in the supply chain should also be taken into account in order to minimize vulnerabilities. <br \/><br \/>4. Setting up a <a href=\"https:\/\/www.cocus.com\/en\/siem-systems\/\">Security Information and Event Management (SIEM)<\/a> system or an attack detection system can be crucial for detecting potential security incidents at an early stage. In addition, incident management processes should be established to ensure effective incident response. Contacting Computer Security Incident Response Teams (CSIRTs) can help to ensure a coordinated and professional response to security incidents. <br \/><br \/>5. In order to maintain business operations at all times, the establishment of business continuity processes is of great importance. These processes should ensure that critical functions and services continue to be available even in crisis situations. In addition, it is also advisable to establish contact with CSIRTs in order to be able to draw on their support in the event of an emergency.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e8d706f elementor-widget elementor-widget-heading\" data-id=\"e8d706f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Consequences of non-compliance with NIS2 requirements<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6e5a1e4 elementor-widget elementor-widget-text-editor\" data-id=\"6e5a1e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Failure to comply with NIS2 requirements can have significant consequences for organizations. These can be fines and penalties in comparable amounts to the penalties for data protection violations. Management is held personally liable by NIS2 for compliance with the requirements. In addition, failure to comply with requirements can lead to cybersecurity incidents that can result in financial losses, data leaks, and business continuity impairments.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fd0a219 elementor-widget elementor-widget-text-editor\" data-id=\"fd0a219\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>It is therefore critical to take the requirements of NIS2 seriously and take appropriate measures to ensure the security of your network and information systems. As a trusted partner, COCUS AG develops customized solutions to meet the requirements of NIS2 and guarantee the security of network and information systems.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-621340a elementor-widget elementor-widget-button\" data-id=\"621340a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cocus.com\/en\/about-us\/contact\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Contact us<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>What is behind the NIS2 guideline? NIS2 introduces stricter security requirements for affected companies.<\/p>\n","protected":false},"author":24,"featured_media":72886,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[424,570],"tags":[426,428,518],"class_list":["post-73164","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-en","category-news-en","tag-cybersecurity-en","tag-endpointsecurity-en","tag-siem-en"],"_links":{"self":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/73164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/comments?post=73164"}],"version-history":[{"count":3,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/73164\/revisions"}],"predecessor-version":[{"id":91578,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/posts\/73164\/revisions\/91578"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media\/72886"}],"wp:attachment":[{"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/media?parent=73164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/categories?post=73164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cocus.com\/en\/wp-json\/wp\/v2\/tags?post=73164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}