The NIS2 Directive increases the minimum requirements for the IT security of critical infrastructure and affects significantly more organisations than its predecessor. What changes are coming your way? What should you do now to be well prepared? Find the answers to the most important questions below.
The NIS2 Directive (Network and Information Systems 2) is a legal act that sets a goal to be reached by EU countries and defines minimum requirements for the cybersecurity of critical infrastructure. With its implementation, the European Commission is aiming to improve the level of cybersecurity in the European Union and strengthen international cooperation in combatting cyberattacks. NIS2 has been in force since 16 January 2023, and Member States must incorporate it into their national legislation by 17 October 2024. This is going to help around 160,000 entities tighten their grip on security and make Europe a safe place to live and work. It will also enable information sharing with the private sector and partners around the world. If we are being attacked on an industrial scale, we need to respond on an industrial scale.
Based on the new Directive, Belgium will have to adopt new provisions to replace the existing NIS Act by 17 October 2024. Work to prepare for the transposition will take place in the coming months. In any case, the new obligations for relevant entities should not come into effect until the end of the transposition period (October 2024). However, it is useful for companies to prepare now for the general obligations arising from the Directive, without waiting for the transposing legislation, taking into account the increasing threats and risks. Therefore, we can only advise entities that will clearly be subject to these new obligations to begin raising (or continuing to raise) their level of cybersecurity from now.
The CCB has published a Cyberfundamentals framework with specific audit objectives. This tool can help and advise companies to raise their security to an appropriate level right away.
By 17th October 2024, Luxembourg, as well as Belgium, will have to adopt and publish a national legislation incorporating the provisions of the new NIS2 Directive. NIS2 details cyber risk measures that need to put in place. The requirements are different for Essential and Important entities but both shall take appropriate and proportionate technical and organizational measures to manage the risks posed to the security of their network and information systems.
In Luxembourg the ILR: Institut Luxembourgeois de Régulation has published an overview on NIS2 with the specificities for the country and some guidance on the steps that need to be taken in order to be ready for the implementation of this directive.
The NIS2 Directive revises and replaces the 2016 NIS Directive. The most important changes are as follows:
Do you have any questions?
Michel Desmet
Sales Engineer
Belgium
Choose your expert: Talk about NIS2 and cybersecurity!
Decide yourself which expert best suits your needs. Whether you need strategic or technical support, we are here to help you become NIS2-compliant.
Murat Aksu
Sales Engineer
Luxembourg
Organisations must clarify themselves whether they fall within the scope of NIS2, and must register with the CCB if required. The criteria are as follows:
You were already critical infrastructure
Then you are automatically affected by NIS2.
You are in one of the 18 sectors
And you also have at least 50 employees and an annual turnover of at least 10 million euro.
Essential sectors vs important sectors
The NIS2 Directive differentiates between essential sectors and important sectors as well as between medium-sized and large sectors. This categorization affects the level of sanctions and supervision by authorities.
Company size
The following thresholds apply within the sectors:
Special cases
Several special cases included in the category of essential sectors are affected by the NIS2 Directive irrespective of their size, such as qualified trust service providers, TLD registries and DNS service providers.
Then you are also indirectly affected by NIS2, because the directive requires critical infrastructure providers as well as important and essential sectors in the 18 sectors identified to consider cybersecurity across their supply chains. Those who would like to continue receiving orders must assume that discussions on cybersecurity will become the norm in contract negotiations in future.
NIS2 places emphasis on cyber risk management forming part of corporate risk management – and for good reason, as cyberattacks are the greatest risk faced by businesses today. Ensuring business continuity is particularly important in the area of critical infrastructure. This is why NIS2 places responsibility on CEOs: they must support measures for cyber risk management and monitor implementation. CEOs that do not fulfil their cyber risk management obligations are personally liable for the associated risks and/or damages.
For CEOs that have not had much to do with cybersecurity so far, cyber risk management is new ground. In practice, NIS2 means CEOs must be able to identify and assess cyber risks and decide which are acceptable for the organisation and which are not. This involves considering the probability and the expected scope of damage of cyberattacks for their organisation. An essential precondition for this is conducting regular meetings with the individual or individuals responsible for IT security. Nevertheless, according to a study by Trend Micro, 51 percent of the IT teams included in the survey already speak to management about cyber risks once a week.
IT security managers are the ones that are faced with the challenge of implementing the NIS2 Directive. Article 21 of the directive lists the minimum requirements for cybersecurity. Apart from cyber risk management, the list also includes backup management, incident management, policies and procedures regarding the use of cryptography as well as access control and identity management, for example. The good news: If you have established standard security best practices, you can already tick off many of the requirements.
For cyber risk management, CISOs/IT security managers must be able to clearly communicate to management at any time what the current risk status looks like, which risks are most urgent and what measures the organisation should take. Cyber risk management must be conducted continuously, as the attack surface and threat environment are constantly changing.
Trend Micro supports the implementation of NIS2 by providing the most advanced security technology.
Cyber risk management made easy with ASRM
Attack Surface Risk Management (ASRM) by Trend Micro uses AI to automatically calculate the risk score of your IT environment. During this process, the technology approaches your environment from the attacker’s perspective: it collects internal data from connected sensors and correlates it with security information from countless external sources, including publications by government agencies, police organisations, security companies and analysts. A dashboard provides an overview, and traffic light visuals communicate immediately how dangerous the calculated risk is. ASRM will alert you as soon as a certain threshold is exceeded and will show you details – such as which systems are affected. It also recommends countermeasures and even allows you to automatically address risks.
Minimise the scope of damage with XDR
As all risks can never be eliminated, you should always consider the possibility of an attack, despite implementing the best security measures. To minimize the scope of damage, you should be able to quickly detect and stop any incident that may occur. The best way to do this is using Trend Micro XDR (Extended Detection and Response). XDR achieves transparency throughout your whole IT environment, collects Security Intelligence from all connected systems and uses AI to correlate it into actionable alerts. This reduces the number of false positives, allowing you to see at a glance what has happened, which systems are affected and where action is required.
How ASRM and XDR work together
ASRM and XDR are both integrated into the cybersecurity platform Trend Vision One, from which they can be centrally monitored and controlled. Both technologies access the same sensors and communicate with each other. If ASRM detects a risk, XDR will investigate it in more detail, and if XDR detects signs of a cyberattack, ASRM will immediately adjust the risk status. Together, the two technologies minimize both the probability of a cyberattack and the scope of damage.
Trend Micro recognized as a Leader
Forrester Wave™: Endpoint Security, Q4 2023
Trend Micro has been awarded the highest score in the Strategy category with the highest possible marks in Innovation, Roadmap, and Adoption.
Free webinar series on NIS2
#Get ready for NIS2
Trend Micro has put together a series of 6 webinars to help enterprises get ready for NIS2. Register for the live webinars or catch up on-demand and find out how Trend Micro is supporting enterprises in meeting the new guidelines.
To ensure that your organisation complies with NIS2, you must be thoroughly familiar with the regulatory requirements, document the measures taken and review their effectiveness. You should also provide training to raise awareness among employees of NIS2 compliance. Essential and important entities must report any significant incident without delay to the competent national authorities (including the national CSIRT – in Belgium, the CCB). Essential and important entities must immediately notify the competent national authorities (including the national CSIRT – in Belgium, the CCB) of any incident that seriously affects services in the sectors or sub-sectors listed in Annexes I and II of the Directive.
The final requirements in each member state will only become clear once the member states’ acts for implementing NIS2 are passed. Until then, the recommendation is to become familiar with the current state of legislation in your member country (and the European NIS2 directive).
GDPR will most likely rank higher than NIS2. In case of incidents involving both laws, the severity of penalties will be based on GDPR. The fines stipulated by GDPR for particularly serious violations are twice as high and can reach 20 million euro or 4 percent of worldwide annual turnover.
FAQs
Who monitors the implementation of the NIS2 Directive?
In Belgium, the competent supervisory authority is the Centre for Cybersecurity Belgium (CCB). Based on the new Directive, Belgium will have to adopt new provisions to replace the existing NIS Act by 17 October 2024. Work to prepare for the transposition will take place in the coming months. In any case, the new obligations for relevant entities should not come into effect until the end of the transposition period (October 2024). However, it is useful for companies to prepare now for the general obligations arising from the Directive, without waiting for the transposing legislation, taking into account the increasing threats and risks. Therefore, we can only advise entities that will clearly be subject to these new obligations to begin raising (or continuing to raise) their level of cybersecurity from now. The CCB has published a Cyberfundamentals framework with specific audit objectives. This tool can help and advise companies to raise their security to an appropriate level right away.
In Luxembourg, the primary NIS2 competent authority is Institut Luxembourgeois de Régulation (ILR). By exception, the Commission de Surveillance du Secteur Financier (CSSF) is the NIS2 competent authority for entities already subject to its prudential supervision, such as Support PSFs.
What penalties can be imposed in case of non-compliance with the NIS2 Directive?
Those who fail to fulfil their obligations under NIS2 must expect severe sanctions. The implementation of the directive provides for different fines that apply to important sectors or critical infrastructure providers and essential sectors. In case of common offences, the same heavy penalties apply to all groups.
Relevant resources
Do you have any questions?
Michel Desmet,
Belgium
Choose your expert: Talk about NIS2 and cybersecurity!
Decide yourself which expert best suits your needs. Whether you need strategic or technical support, we are here to help you become NIS2-compliant.
Murat Aksu,
Luxembourg