Seeky

The NIS 2 Directive will affect 6 000 companies. Are you ready for it?

Date of issue

21. 11. 2023

Are you interested in the described topic?

contact us
The NIS 2 Directive will affect 6 000 companies. Are you ready for it?

Within the EU, it entered into force on 27. December 2022, it is now being implemented in the Czech legal system – it will probably be approved in mid-October and will come into force in 2024. This will be a significant extension and tightening of the older directive (NIS) from 2016. The directive will now affect up to 6,000 Czech companies out of the original 400 or so. And meeting its conditions will not be easy.

What exactly is it?

You can read the full text of the Directive (in English) HERE.

In short, the Directive states that EU Member States are obliged to identify all entities that provide backbone services and these entities must then implement defined measures to prevent cyber attacks. This is a way to unify national strategies, procedures or criteria and risk assessments, as in the past countries had different approaches to cybersecurity. Each Member State must also set up a national cyber security incident response team.

The Directive names the specific public and private sectors affected by the measure. At the same time, it divides firms into entities of fundamental and important importance.

Subjects of major importance (higher importance)Subjects of major importance (lower importance)
Energypostal and courier services
transportwaste management
financial marketschemical industry
Healthcarefood industry
water managementmanufacturing industry
digital infrastructure and services 
public administration 
space industry 

A disruption of services at a critical entity would have a serious or critical impact on the country’s economy or the functioning of society, so the conditions are more stringent for these companies.

A company of fundamental importance

  • adopts the full text of all the requirements of the Directive,
  • must report all security incidents,
  • must follow the NCIB’s warnings and respond to threats with proactive measures,
  • is under the control of the NCIB,
  • data and information must be processed on a server in the region,
  • must also vet their critical suppliers.

A company of major importance

  • adopts the reduced requirements of the Directive,
  • is only obliged to report security incidents with a significant impact,
  • do not have to follow the NCIB warnings,
  • is under the control of a certified inspector of the NUCIB,
  • data and information may not be processed on a server in the region,
  • they don’t have to vet their suppliers.

What changes will NIS2 bring in practice?

The new Directive introduces measures of an organisational and technical nature.

In the organisational area, managers need to focus on risk assessment and management, implement comprehensive security policies with an emphasis on sustainability of service operations, and ensure staff training. The focus is also on supply chain security.

In the area of technical measures, this primarily concerns the security of IT infrastructure. These include:

  • Telecommunications network protection and properly distributed systems, including those with high availability architectures.
  • Identity management and authentication, including external users and suppliers.
  • Control access permissions across the entire organization.
  • Cryptography and protection of sensitive data, emphasis on backup and recovery.
  • Protection of all devices with network access.

A new feature will be the requirement to record the resolution and reporting of vulnerabilities and incidents. The first report must be submitted within 24 hours of discovering a security problem, and a second, more detailed report must be submitted within one month.

The aim of the first notification is to limit the potential spread of incidents and to enable operators to eliminate a potential threat as quickly as possible. The second report is to ensure that lessons are learned from previous incidents.

It is the reporting obligation that is the biggest challenge for companies as they have to monitor and respond to incidents 24/7/365. At the same time, there is a shortage of qualified IT specialists on the market, so it will be difficult to find internal people for continuous operation. The focus should be on smart solutions with maximum use of advanced technologies.

The Directive will enter into force on 31 December at the latest. December 2024, and the control authority may impose sanctions for non-compliance from the following month.

With NIS2 we can help you

In response to the introduction of NIS2, our company System4u offers Managed Detection & Response – a package to cover all the requirements of the directive. This service includes:

  • A security audit of your IT infrastructure and a detailed analysis of its condition using modern techniques and penetration tests (on-premise and cloud hosting, networks, application layer, identity management, endpoints, data storage, data security, backup, recovery, etc.).
  • Expert consultation including architectural design and subsequent implementation of recommended changes.
  • Security Support Service (SOC365) including incident handling and reporting.

With Managed Detection & Response, you’ll be confident that you’re operating in compliance with NIS2 and other regulations such as GDPR or ISO 27001. If you want to talk more about it, let us know.

More posts

We live with digital technologies. And that’s why we write about them.

Latest Articles
More posts
1/10

Or contact us directly

Alena Valeckova

Alena Valeckova

office coordinator

Contact us

Fill out our form, we will contact you within a few days with a proposal for a non-binding consultation.

Kontaktujte System4u