How NIS2 Will Impact Your Business and How to Identify Essential Services

With the adoption of the NIS2 Directive, new cybersecurity requirements are coming that will significantly impact businesses across the European Union, including the Czech Republic. This directive focuses on protecting essential and important services and their providers to minimize risks associated with cyber threats. For companies, it is crucial to understand whether they fall under this directive and what steps need to be taken to comply with the new rules.

What is the NIS2 Directive, and Who Does It Apply To?

The NIS2 Directive (Network and Information Security Directive 2) expands and tightens the requirements set by the original NIS Directive from 2016. Its aim is to raise the level of cybersecurity across the EU, placing greater emphasis on corporate leadership accountability and introducing stricter penalties for non-compliance.

The directive applies to:

  1. Essential Services: Businesses and organizations operating in critical sectors such as energy, healthcare, transport, finance, water, and digital infrastructure.
  2. Important Services: Entities in areas like manufacturing, food production, chemicals, or research that play a significant role in the economy and society.

How to Identify If Your Business Falls Under the NIS2 Directive

Determining whether NIS2 applies to your organization depends on several factors that require careful analysis. Below is a step-by-step guide to help you navigate this process:

1. Analyze Your Sector

Examine the list of sectors covered by the NIS2 Directive. These include:

  • Energy: Power plants, gas companies, and energy distribution firms.
  • Healthcare: Hospitals, laboratories, pharmaceutical manufacturers.
  • Digital Infrastructure: Providers of data centers, cloud services, and networks.

If your organization operates in any of these sectors, it likely falls into one of the two categories: essential or important services.

2. Assess the Importance of Your Services

  • Essential Services: These are crucial for the functioning of the economy and society. For example, power plants are vital providers of energy, without which infrastructure would fail.
  • Important Services: While having a lower impact than essential services, these are still significant to the economy and society. For instance, a manufacturing plant supplying parts to the automotive industry.

3. Evaluate Workforce Size and Turnover

The NIS2 Directive primarily applies to medium and large organizations:

  • Medium Businesses: 50–249 employees or an annual turnover of €10–50 million.
  • Large Businesses: 250 or more employees or turnover exceeding €50 million.

Small and micro-enterprises are largely exempt unless they operate in high-risk sectors.

4. Conduct an Asset Analysis

Map your critical assets, such as IT infrastructure, systems supporting operations, or sensitive information you manage. If these assets underpin essential or important services, you may fall under the directive.

5. Evaluate Your Impact on Society

Consider how a disruption of your services would affect customers, suppliers, and the public. If it would cause significant disruptions, your organization is likely classified as a provider of essential or important services.

How We Can Help

We’re here to guide you through the process of identifying and preparing for compliance with the NIS2 Directive. Our services include:

  1. GAP Analysis: We’ll help you identify what you already have in place and what needs improvement.
  2. Compliance Plan: We’ll create a clear roadmap of steps to ensure full compliance with NIS2.
  3. Asset Analysis and Assessment: We’ll map and evaluate your critical assets and recommend the best ways to protect them.
  4. Training and Awareness: We’ll help you and your employees understand the requirements of NIS2 and build a culture of security.
  5. Implementation Support: From audits to fully integrating security measures, we’ll be with you every step of the way.

Conclusion

The NIS2 Directive represents not only an opportunity to enhance cybersecurity but also a chance to improve processes and resilience in your business. The earlier you start preparing, the better protected you’ll be from risks and penalties.

Have questions or need help determining whether your business falls under the NIS2 Directive? Contact us to learn how we can help ensure a smooth path to compliance.