Is your organization ready for the new cybersecurity law?
11 March 2025A new law will come into effect in mid-2025, arising from the NIS2 Directive established by the European Union. The directive is intended to improve the cybersecurity and resilience of companies by introducing stricter security standards and reporting requirements for cyber incidents.
Three obligations of NIS2
How the directive will be applied within legislation is not yet fully known. However, there is talk of three obligations that will shape the new cybersecurity legislation.
- Duty of care
The NIS2 directive requires companies to regularly assess their cybersecurity risks and take appropriate measures to protect their services and information. - Reporting obligation
According to the NIS2 directive, all incidents that disrupt the service must be reported to the regulator within 24 hours. Cyber incidents must also be reported to the CSIRT, an internal or external Computer Security Incident Response Team that can provide support. - Supervisor
Companies that fall under the NIS2 directive will be supervised to ensure compliance with the obligations of the directive. Failure to comply with the NIS2 directive can result in fines of up to 10 million euros or 2% of global annual turnover, depending on the type of incident and the size of the company.
Do you, as an SME, want to prepare for the new directive?
At the very least, ensure improvement of IT security. For example, by ensuring that each application generates sufficient login information. Through multifactor authentication, encrypted storage data, and determining and recording who has access to which data and systems. Also, making backups, checking them regularly, and ensuring updates of software and systems provide more IT security.
If your system administrator/MSP/IT supplier is ISO27001 certified, you are already well on your way, because we see that a number of NIS2 requirements must also be arranged for this certification.
Is the NIS2 directive also mandatory for your organization?
SMEs that must take the NIS2 directive into account are companies that belong to essential or important sectors, companies with at least 50 employees, or companies with an annual turnover/balance sheet total of more than 10 million euros. Do you want to know if your organization falls under this, then go to the government website. Even if your organization does not fall into these sectors, it is still very important to be resilient!
Need help preparing for the new NIS2 directive? Then contact us, we can help you take the right steps.