{"id":1837,"date":"2024-06-14T10:30:46","date_gmt":"2024-06-14T08:30:46","guid":{"rendered":"https:\/\/advaso.com\/nis2-new-cyber-security-standards-for-companies\/"},"modified":"2024-11-18T16:07:04","modified_gmt":"2024-11-18T15:07:04","slug":"nis2-new-cyber-security-standards-for-companies","status":"publish","type":"post","link":"https:\/\/advaso.com\/en\/nis2-new-cyber-security-standards-for-companies\/","title":{"rendered":"NIS2: New cyber security standards for companies"},"content":{"rendered":"<p>[et_pb_section fb_built=&rdquo;1&Prime; _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; da_disable_devices=&rdquo;off|off|off&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo; da_is_popup=&rdquo;off&rdquo; da_exit_intent=&rdquo;off&rdquo; da_has_close=&rdquo;on&rdquo; da_alt_close=&rdquo;off&rdquo; da_dark_close=&rdquo;off&rdquo; da_not_modal=&rdquo;on&rdquo; da_is_singular=&rdquo;off&rdquo; da_with_loader=&rdquo;off&rdquo; da_has_shadow=&rdquo;on&rdquo;][et_pb_row _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;][et_pb_column type=&rdquo;4_4&Prime; _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;][et_pb_text _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; text_font_size=&rdquo;17px&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;]<\/p>\n<p>The implementation of appropriate cyber security in industry, public authorities and service providers is one of the greatest challenges of our time. In order to better meet this challenge and protect IT systems from hacker attacks, the European Union has adopted the NIS2 (Network and Information Security) Directive. <\/p>\n<p>In this blog post, we explain the key measures that companies should take in accordance with the NIS2 Implementation Act.<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; text_font_size=&rdquo;16px&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;]<\/p>\n<h2><strong>What is NIS 2?<\/strong><\/h2>\n<p>NIS 2 is the revised version of the original 2016 NIS Directive and aims to improve the security requirements for network and information systems in the EU and help Member States prevent or mitigate the impact of cyber threats. NIS 2 was adopted in December 2022 and must be transposed into national law by the EU member states by October 17, 2024.  <\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; text_font_size=&rdquo;16px&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;]<\/p>\n<h2><strong>Important innovations and requirements<\/strong><\/h2>\n<h3><strong>Extended area of application<\/strong><\/h3>\n<p>One of the most significant changes in NIS 2 is the extended scope of application. While the original NIS Directive only covered certain sectors (critical infrastructure such as energy, transport and health), NIS 2 now covers a broader range of sectors, including medium-sized companies that are considered essential to the economy and society. This includes, for example, the food industry, mechanical engineering, IT service providers and the public sector.  <\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Stricter safety requirements<\/strong><\/h3>\n<p>NIS 2 specifies stricter security requirements for companies and organizations. These requirements include, among other things: <\/p>\n<ul>\n<li><strong>Risk management<\/strong>: Companies must implement a robust risk management system that is regularly reviewed and adapted to the threat situation.<\/li>\n<li><strong>Security measures<\/strong>: Technical and organizational measures must be taken to protect and manage network and information systems. These include, for example, regular security checks including the supply chain, employee training, the use of cryptography and encryption or backup and recovery management.  <\/li>\n<li><strong>Reporting obligations<\/strong>: Cyber incidents must be reported immediately to the competent national authorities. The deadline for reporting is usually 24 hours after the incident is discovered. <\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Stronger supervision and sanctions<\/strong><\/h3>\n<p>Supervision of compliance with the NIS 2 Directive will be tightened. National authorities will be given extended powers to check and enforce the directive. Non-compliance could result in significant penalties. This is intended to ensure that companies take the requirements seriously and actively take measures to improve their cyber security.   <\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&rdquo;4.25.2&Prime; _module_preset=&rdquo;default&rdquo; text_font_size=&rdquo;16px&rdquo; global_colors_info=&rdquo;{}&rdquo; theme_builder_area=&rdquo;post_content&rdquo;]<\/p>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>NIS 2 lays the foundations for improving cyber security in the EU. By expanding the scope of application and the institutions affected by NIS2, introducing stricter security requirements and monitoring them by national supervisory authorities, the directive is intended to help increase resilience to cyber threats. At the same time, companies should be prepared to continue business operations, at least in an emergency, in the event of a cyberattack.  <\/p>\n<p>For the affected companies and organizations, this means that they must continuously rethink their existing security strategies and adapt them on a risk-based basis in order to meet the requirements of NIS 2.<\/p>\n<p>Time is of the essence, the deadline for the introduction of NIS2 as applicable law is October 24, 2024. ADVASO helps you to meet the legal requirements. <\/p>\n<p>&nbsp;<\/p>\n<p><strong>Interesting external links on the topic:<\/strong><\/p>\n<p><a href=\"https:\/\/www.bmi.bund.de\/SharedDocs\/gesetzgebungsverfahren\/DE\/nis2umsucg.html\" target=\"_blank\" rel=\"noopener\">Information from the BMI on the draft law<\/a><\/p>\n<p><a href=\"https:\/\/www.bmi.bund.de\/SharedDocs\/gesetzgebungsverfahren\/DE\/Downloads\/kabinettsfassung\/CI1\/nis2-regierungsentwurf.pdf;jsessionid=6FAD7B930D6C3B7E1889642BAD8307CF.live872?__blob=publicationFile&amp;v=1\" target=\"_blank\" rel=\"noopener\">NIS2 draft law as PDF (BMI from 22.07.2024)<\/a><\/p>\n<p><strong>Stay tuned:<\/strong> In the next blog, we will inform you about the current status of the legislative process of the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) and explain the criteria for particularly important institutions.<\/p>\n<p><a href=\"https:\/\/advaso.com\/en\/?p=1799\">Click here for the blog post NIS2 Implementation Act<\/a><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NIS2 obliges companies to improve IT security measures and strengthens risk management against growing threats.<\/p>\n","protected":false},"author":7,"featured_media":1688,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[50,55],"tags":[65],"ppma_author":[18],"class_list":["post-1837","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security-and-data-protection","category-nis2-en","tag-nis2-en"],"authors":[{"term_id":18,"user_id":7,"is_guest":0,"slug":"sk_nrw","display_name":"Stefan Kr\u00f6ger","avatar_url":{"url":"https:\/\/advaso.com\/wp-content\/uploads\/2024\/04\/Stefan_kroeger.png","url2x":"https:\/\/advaso.com\/wp-content\/uploads\/2024\/04\/Stefan_kroeger.png"},"author_category":"","first_name":"Stefan","last_name":"Kr\u00f6ger","user_url":"","job_title":"","description":"Stefan Kr\u00f6ger ist zertifizierter Datenschutz- und Datensicherheitsexperte. Er verf\u00fcgt \u00fcber langj\u00e4hrige Projekterfahrung in den Bereichen Datenqualit\u00e4t, Datenschutz, Datensicherheit, Compliance und gesetzliche Rahmenbedingungen und Richtlinien. Stefan ist Gesch\u00e4ftsf\u00fchrer der Audit NRW GmbH und langj\u00e4hriger Partner der ADVASO GmbH."}],"_links":{"self":[{"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/posts\/1837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/comments?post=1837"}],"version-history":[{"count":2,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/posts\/1837\/revisions"}],"predecessor-version":[{"id":1847,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/posts\/1837\/revisions\/1847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/media\/1688"}],"wp:attachment":[{"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/media?parent=1837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/categories?post=1837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/tags?post=1837"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/advaso.com\/en\/wp-json\/wp\/v2\/ppma_author?post=1837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}