The new directive imposes significant requirements on levelling up the cybersecurity capabilities of organisations in various sectors that are characterised as essential or important.
NIS2 enhances EU network and information systems security by requiring critical infrastructure operators to implement a minimum set of cybersecurity standards and report on cyber incidents. It expands NIS's scope, covering more organisations and industries, and its objective is to improves supply chain security, streamline reporting, and enforce stricter measures and sanctions across Europe for a safer and more secure Europe.
These mandatory, risk-based cybersecurity standards can effectively contribute to a stronger cybersecurity security posture for organisations who adopt and adhere to the standards, many of which are likely part of an established cybersecurity policy. Failure to comply with these mandatory standards may result in significant fines.