The second iteration of the Network and Information Systems Directive, NIS2, is looming on the horizon. Having been formally passed into EU law, Member States now have until October 2024 to implement the laws at a local level needed to support this new directive. Even though the UK Government has stated they will not be adopting NIS2; this does NOT mean that all UK organisations are exempt. It may still apply to organisations that conduct business within an EU Member State. We will cover this in more detail in another article! The original Directive published in 2016 sought to improve on the cybersecurity capabilities of Member States. A review during the initial NIS Directive found that with a considerable increase in cybersecurity incidents in recent times, there now lies a major threat to the functioning of the network and information systems that so many countries and businesses rely on. This pushed the further development of the Directive to increase cybersecurity capability, improve resilience of both Member States and businesses, and increase cooperation by sharing information through reporting and increasing awareness on cross-border impacts. NIS2 seeks to further expand on these pillars by expanding the sectors that fall under the Directive’s jurisdiction, which replicates the increased rate of digitalisation that we see across all forms of business and everyday life. It also looks to modernise the original NIS Directive in order to keep pace with the rapid rate of technological advancements, from AI to Industry 4.0 and the increased use of IoT devices. The threat landscape is expanding with new threat vectors coming online faster than before. NIS2 looks to try to improve and bolster the EU and their Member States’ resilience and capability to deal with new and evolving threats against network and information systems.
Timeline
The transition from NIS Directive to NIS2 is a long and drawn-out process as all 27 members states are working to put the requirements into law.
As you can see from the timeline, we are on the final stretch toward implementation with Member States to finish implementing supporting legislature and to publish the detailed measures required by organisations to comply with NIS2.
What’s changed?
NIS2 is the latest iteration of the European Union’s Network and Information Security Direction first issued in 2016 as a response to increasing cyber attacks against critical services. The NIS Directive originally applied to entities within 7 key sectors called “Operators of Essential Services” (OES) and also included 3 sectors referred to as “Digital Service Providers” (DSP). The NIS2 regulations have expanded the sectors within scope, along with a new way of grouping them together. The sectors are now grouped as Annex I and Annex II sectors. Entities that fall into either of these Annexes are then categorised as “Essential” or “Important”. Services that fall into the Essential category would be expected to have serious consequences for a country’s economy and society as a whole, whereas Important entities still can offer a serious impact but to a lesser degree. Essential services are proactively monitored by the relevant Competent Authority (CA), while Important services are only scrutinised when they issue incident reports to the relevant Computer Security Incident Response Team (CSIRT). All Annex II sectors, as well as Annex I medium enterprises (earns more than 10 million Euros in annual revenue and has 50+ employees) are defined as Important. Whilst Annex I large enterprises (earns more than 50 million Euros in annual revenue and has 250+ employees), along with qualified trust service providers, TLD registries, DNS service providers, public administration entities, and OES are packaged as Essential. It is key to take away at this juncture that an EU Member State can classify any entity of any size as Essential or Important based on their risk profile. If you find that your organisation has an element that operates within the EU you may need to comply with NIS2 regulations.
What should I concern myself with?
There are four main Articles in the NIS2 Directive that are probably the most important ones to consider. These are the main areas that organisations should be concerning themselves with as they relate to increased accountability, obligations for cybersecurity risk-management, new more stringent reporting pathways, and certification. Article 20: Governance holds management bodies of essential and important entities accountable for approving risk-management measures and to oversee their implementation. They are also ultimately held liable in the event of non-compliance or gross negligence. Article 20 also holds management bodies responsible for following training and offering similar training to their employees on a regular basis. Management are required to ensure that their employees have sufficient knowledge and skills to help them identify risks and assess cybersecurity practices and their impact on services. This ties into Article 21: Cybersecurity risk-management measures, which pushes entities to have in place the appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the network and information system. This Article requires Essential and Important entities to implement and maintain a cybersecurity framework that is appropriate for the provision of their service; whether that is an Information Security Management System from the ISO 27000 series in your IT environment or a Cybersecurity Management System from ISA/IEC 62443 in your IACS environment. There are many different frameworks available to be implemented all with a selection of security controls that be customised to suit your organisation’s needs. Another Article that compliments the cybersecurity risk management is Article 24: Use of European cybersecurity certification schemes. This Article requires organisations to demonstrate compliance with Article 21 by using ICT products, services, and processes developed in-house or procured from third parties that are certified under European cybersecurity certification schemes. It also encourages the use of qualified trust services. These schemes are developed by the European Union Agency for Cybersecurity (ENISA) with the goal of harmonising recognition of the level of cybersecurity across the EU. The Article does note that where no appropriate scheme exists, ENISA may be requested to prepare one. The last Article of note is Article 23: Reporting obligations. The requirements are more stringent here than in the original NIS Directive. Essential and Important entities must report “significant” cyber incidents to their relevant CSIRT. An incident is considered significant when it has / could cause severe operational disruption of services or financial loss for the entity; and has / could affect persons by causing considerable material or non-material damage. There is now a more detailed process for organisations once a significant incident has been discovered. 
How will this impact me?
NIS2 puts the onus on Member States to ensure that supervisory and enforcement measures for the Directive are imposed and are effective, proportionate, and dissuasive, taking into account each individual case. It pushes Member States to assign a CA and imbue them with the power to inspect, conduct audits, security scans, requests for information and more. Audits are conducted regularly for Essential entities and when provided with evidence, indication or information of non-compliance for Important entities. The CA should then be empowered to issue warnings, binding instructions, or a variety of other actions can be ordered. The CA can also impose fines that are outlined in Article 34: General conditions for imposing administrative fines on essential and important entities of NIS2:
- Essential Entities (whichever is higher) –
- EUR 10,000,000 maximum
- OR
- 2% of the total worldwide annual turnover of the preceding financial year
- Important Entities (whichever is higher) –
- EUR 7,000,000 maximum
- OR
- 1.4% of the total worldwide annual turnover of the preceding financial year
The specifics of how each Member State plans to perform the supervisory and enforcement measures and how the regime will operate day to day has yet to be fully implemented by Member States. However, the European Commission have given them until October 2024 to finalise these measures and have the legislation in place to support the implementation of NIS2. But while the specifics are yet to be revealed, it is important that organisations get ahead of the curve and start to take steps to improve and bolster their cybersecurity, as once a robust, effective cybersecurity framework is in place, any changes (if even required) to meet Member State requirements will be minimal.
How can I get my organisation ready?
- Access control and Asset Management
-
- This concept is rather straightforward, you need to know what you have in order to protect it. What assets do you have? And remember “assets” include devices, data, systems, and people. Where are they? Are they stored securely? What are they doing? What other assets do they interact with? What are their vulnerabilities? What are the threats to them? How are you prioritising them? Knowledge is power and the more comprehensive and detailed the better.
-
- Policies and Procedures
-
- Policies and procedures are an integral form of support to your cybersecurity effort. Organisations should look to their Governance Framework to develop sets of policies that define the processes for risk analysis, and information and data security. They should also be written in such a way so as to allow for review and refinement of all processes they describe.
-
- Secure Lifecycles
-
- The main goal of secure lifecycles is to ensure that security is considered at every step. This includes the entire lifecycle from acquisition, development and maintenance, to disposal. This leans heavily into the defence-in-depth philosophy. This involves establishing and adhering to security requirements and product specifications, security guidelines for handling and disposal, vulnerability handling and disclosure, to ensure that security is “baked in”.
-
- Supply Chain
-
- The supply chain of an organisation can be one its greatest vulnerabilities with several attacks to organisations in recent times being achieved via the supply chain. It is important to know what your supplier has access to (this includes physical and data assets), and how they are securing them. You need some form of assurance that your suppliers and third-party providers take security as seriously as you do and are helping to protect the things that you find important.
-
- Business Continuity and Incident Response
-
- Due to the strict reporting requirements imposed by NIS2 along with the tight deadlines, it is important to have a clear and specific Incident Response plan. When an incident occurs your organisation should be clear what information needs to be collected, what needs to be reported, and how to prioritise if multiple incidents happen at once. It also needs to be clear about escalation procedures and who to contact / report incident data to and when.
-
- Cyber Hygiene and Training
-
- People are the biggest strength and weakest link of any organisation. Ensuring your people are aware of cyber threats and have the required knowledge and skills is one of the biggest wins you can have in your cyber security journey. NIS2 recognises this and specifically requires management bodies to be trained and subsequently provide training to their staff. Organisations need to determine the skill and knowledge levels required, and these need to be specific to roles in the organisation. They then need to establish a combination of awareness campaigns, and training programmes. Campaigns and programs should also be continuously reviewed and updated to meet the organisations needs and to match changing threat landscapes.
-
How can Arcanum help?
The effect of non-compliance to NIS2 can be costly, it imposes large financial burdens on organisations that are not prepared to have their cyber security posture scrutinised. There are several approved cyber frameworks and standards that can help to guide your organisation’s journey. However, it can be difficult to navigate that guidance, especially if your organisation does not have the appropriate resources to handle such a process. This is where expert, qualified third parties can be crucial to making sure you can get up to speed and are prepared to weather the incoming cyber storm. At Arcanum, our cyber security teams are experienced in implementing and assessing all aspects of security within both Information and Operational Technology environments. We can offer your organisation independent, vendor-agnostic advice that is tailored to your specific business needs while providing the highest level of risk reduction possible in your situation, without impacting normal business functions. Contact us or call: 02922 784452