NIS2 Regulations Are Coming – Are You Ready?

The European Union's Network and Information Security (NIS) directive is evolving, with tighter rules and tougher sanctions that will apply to more organisations than was previously the case.

Those that assume they won’t fall under its remit could find themselves on the back foot, unless they get up to speed with the likely compliance requirements now. 

Many UK businesses have had to comply with the EU Network and Information Systems (NIS) cyber security standards for years. The regulations were imposed in 2016 to better protect the security and resilience of essential everyday services – such as water, energy, healthcare, transport and digital infrastructure – from online attacks, and they remain part of British law. The regulations are tightening for those countries that are still part of the EU, with stricter rules and reporting requirements, and higher penalties for compliance failures.

When it takes effect in 2024, the updated legislation will apply to medium-sized and large UK businesses that provide their services or carry out their activities in the EU. Those that only operate in the UK can’t relax, however, as the original NIS regulations will continue to apply to UK organisations. In addition, a number of new industry sectors not covered by NIS1 are now being pulled in. 

More significantly, a UK version of the rules is coming very soon: at the start of this year the government stated that “the NIS regulations will be updated as soon as Parliamentary time allows”. The intention is to strengthen the UK’s cyber laws against digital threats, according to Cyber minister Julia Lopez, in order to protect essential services and the IT providers which keep them running.

Once the rules come into force, affected organisations will be subject to random checks, regular security audits, on-site inspections and off-site supervisions. For those found to be in breach of the regulations, penalties could be as high as 10 million Euros or 2% of their global turnover - whichever is higher.

The Ground It Will Cover

It’s highly likely that the UK’s NIS framework will be very similar to the EU’s version. This means that entities which come under its remit will be required to perform regular security assessments, adopt incident response plans, appoint a chief information security officer (CISO), and report significant incidents to the national authorities, among other obligations.

The UK government has indicated that its NIS update will follow the EU’s lead in improving and streamlining the way in which cyber incidents are reported to regulators. Under NIS2, organisations must notify of any incident that has a significant impact on the provision of their services, for instance by causing severe operational disruption or financial loss. 

There is also plenty of focus in NIS2 on the cornerstones of sound cyber risk management – in particular the proper control of administrator-level account credentials, privileged access, and endpoints, all of which are prime targets for attackers.

Expanding The Scope

A number of new sectors are being pulled into the regulations, including space, waste management, research and development and a wider range of healthcare companies. Organisations are split into ‘critical’ and ‘important’ entities.

The burgeoning third party threat will also be addressed. Managed Service Providers (MSPs) are being added to the list of ‘critical entities’ to which the directive applies, in a move designed to keep the digital supply chains involved in the running of essential services secure. MSPs are often granted privileged access to corporate systems and networks, which creates security risks. Cyber criminals can take advantage of any vulnerabilities to attack and disrupt multiple organisations, as illustrated in the devastating MOVEit breach earlier this year. 

How Should You Prepare?

Organisations should take action now to establish whether the EU or UK NIS2 regulations will apply to them, and ensure they can implement and demonstrate best practice in good time.

They need to determine their obligations in relation to cyber risk management. What changes need to be made to existing processes, policies and practices to meet them? Are the basic cyber hygiene principles in place? As a priority, businesses must review their incident response plans and incident management and reporting procedures. It’s also a good idea to get a head start on undertaking third party security assessments, and incorporating security requirements into contracts. 

Given the framework’s focus on protecting privileged admin accounts, businesses should take measures to limit who possesses these powerful credentials – both across the organisation and within the supply chain. Implementing privileged access management (PAM) will allow IT to control who is granted access to which systems, applications and services, for how long, and what they can do while they’re using them.

It’s important that organisations engage now with the requirements of the updated NIS2, and build an understanding of what it means for them - especially those that weren’t covered by NIS1.

This should be viewed as more than just a compliance exercise. By adhering to the strengthened framework, businesses will build a foundation of resilience that protects the organisation, the services they provide, the communities that use them, and the wider UK economy from threats that could cause significant disruption and even endanger lives. 

Graham Hawkey is  PAM specialist at Osirium

You Might Also Read: 

Connected Devices Must Be More Secure:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« British Police On High Alert After Supply Chain Breach
Undetected Attackers Could Be Inside Your IT Systems Now »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Indium Software

Indium Software

Indium Software is an Independent Software Testing Company offering software testing services (including security testing) and offshore Quality Assurance solutions.

National Association of Software and Services Companies (NASSCOM) - India

National Association of Software and Services Companies (NASSCOM) - India

NASSCOM is a trade association of Indian Information Technology and Business Process Outsourcing industry. Areas of activity include cyber security.

Red Alert Labs

Red Alert Labs

Red Alert Labs is an IoT security provider. We created an independent security lab with a disruptive business offer to solve the technical and commercial challenges in IoT.

Cybersecurity Coalition

Cybersecurity Coalition

The mission of the Cybersecurity Coalition is to bring together leading companies to help policymakers develop consensus-driven policy solutions to achieve improvements in cybersecurity.

Wolf Hill Group

Wolf Hill Group

Wolf Hill Group, a Slone Partners company, is a national recruitment firm focused on Cybersecurity.

Spamhaus

Spamhaus

Spamhaus is the world leader in supplying realtime highly accurate threat intelligence to the Internet's major networks.

Digitpol

Digitpol

Digitpol’s Cyber Crime Investigation experts investigate hacking incidents, ransomware, extortion and conduct security audits and IT upgrades.

Keysight Technologies

Keysight Technologies

Keysight is dedicated to providing tomorrow’s test technologies today, enabling our customers to connect and secure the world with their innovations.

LiveAction

LiveAction

LiveAction provides end-to-end visibility of network and application performance from a single pane of glass.

Nexon Asia Pacific

Nexon Asia Pacific

Nexon solutions include cloud infrastructure and services, unified communications, managed security services, business continuity, secured high-performance network and business applications.

Ipstack

Ipstack

Ipstack offers one of the leading IP to geolocation APIs and global IP database services worldwide. Protect your site and web application by detecting proxies, crawlers or tor users at first glance.

SYN Ventures

SYN Ventures

SYN Ventures invests in disruptive, transformational solutions that reduce technology risk.

Unisys

Unisys

Unisys is a global information technology company providing industry-focused solutions integrated with leading-edge security to clients in the government, financial services and commercial markets.

Gorilla Technology Group

Gorilla Technology Group

Gorilla specializes in video analytics, OT network security and big data to support a wide range of solutions for commercial, industrial, cities and government purposes.

PCCW Global

PCCW Global

PCCW Global is a leading communications service provider, offering mobility, voice and data solutions to multinational enterprises, telecomms partners, cloud and application service providers.

Forthright Technology Partners

Forthright Technology Partners

Forthright Technology Partners (Forthright) is a next-generation cloud and managed IT services provider serving a global clientele.