Blogs & Opinions 17.10.2024
Ensuring NIS2 Compliance With Proactive Cyber Resilience
NIS2 is here. Are you ready?
Blogs & Opinions 17.10.2024
NIS2 is here. Are you ready?
In an era of hyperconnectivity, distributed work environments, fast AI roll-out, and advanced threat actors, companies face a complicated and diverse threat landscape that goes far beyond ransomware and phishing. October 17 2024 is the official deadline for EU Member States to pass national laws implementing the NIS2 Directive, which aims at strengthening the cyber resilience of Europe’s critical infrastructure.
“Organisations that fail to comply could face fines of up to €10 million or 2% of their global annual turnover”
It’s estimated that at least seven times more entities will be covered under the new directive, compared to its previous version, including medium and large organisations with more than 50 employees and organisations from covered sectors, such as healthcare, energy, water or transportation, that have more than €10 million in revenue.
Non-compliance with the NIS2 Directive is not an option. Organisations that fail to comply with the new law could face fines of up to €10 million or 2% of their global annual turnover or even see their executive leadership temporarily suspended from exercising managerial functions. Organisations in scope that do not already have continuous monitoring or incident response plans and processes need to get moving.
While regulation can be a catalyst for improving cyber resilience, it is not sufficient by itself. We need to incentivise organisations to invest in the people, processes and technology that together make for a successful security programme.
Organisations should not become complacent or assume compliance offers blanket protection from cyber attacks. NIS2 provides a baseline, but cybersecurity shouldn’t be seen as a mere compliance exercise. Rather, it’s an everyday critical matter for businesses. AI is empowering malicious actors by enhancing cyber attack tools and lowering the access barriers to deploy more sophisticated, targeted attacks. As a result, all strategy and process must be approached in an ongoing, iterative way to counter an ever-evolving cyber threat landscape.
This challenge is highlighted in the 2024 Cisco Cyber Readiness Index, which shows that very few European organisations feel prepared to defend themselves against today’s threat landscape. Only 3% were assessed as having a mature stage of readiness. This is despite over two thirds of respondents (IT and security leaders) in Europe anticipating a cybersecurity incident in the next one to two years.
The jump from NIS1 to NIS2 is a clear sign from the EU that it’s serious about achieving a common and higher level of cybersecurity across its Member States.
Chris Gow is the head of EU public policy at Cisco and Head of the Brussels Office for Cisco’s Government Affairs team, responsible for engagements with the EU institutions. Having joined Cisco in 2008, he oversees all of Cisco’s EU public policy positions and advocacy. He is currently deeply engaged in security, digital sovereignty, cloud, AI and data issues in region and globally. Chris has held multiple industry leadership roles. He is currently a member of the Board of the European Internet Forum (EIF) and has previously served on the Executive Board of DIGITALEUROPE and as the Chair of DIGITALEUROPE’s privacy and security group. Chris has been in Brussels since 2003, initially as an assistant to a member of the European Parliament, working on internal market and legal affairs issues. He studied philosophy, politics and economics at Oxford University.