NIS2 Regulations Are Coming – Are You Ready?

The European Union's Network and Information Security (NIS) directive is evolving, with tighter rules and tougher sanctions that will apply to more organisations than was previously the case.

Those that assume they won’t fall under its remit could find themselves on the back foot, unless they get up to speed with the likely compliance requirements now. 

Many UK businesses have had to comply with the EU Network and Information Systems (NIS) cyber security standards for years. The regulations were imposed in 2016 to better protect the security and resilience of essential everyday services – such as water, energy, healthcare, transport and digital infrastructure – from online attacks, and they remain part of British law. The regulations are tightening for those countries that are still part of the EU, with stricter rules and reporting requirements, and higher penalties for compliance failures.

When it takes effect in 2024, the updated legislation will apply to medium-sized and large UK businesses that provide their services or carry out their activities in the EU. Those that only operate in the UK can’t relax, however, as the original NIS regulations will continue to apply to UK organisations. In addition, a number of new industry sectors not covered by NIS1 are now being pulled in. 

More significantly, a UK version of the rules is coming very soon: at the start of this year the government stated that “the NIS regulations will be updated as soon as Parliamentary time allows”. The intention is to strengthen the UK’s cyber laws against digital threats, according to Cyber minister Julia Lopez, in order to protect essential services and the IT providers which keep them running.

Once the rules come into force, affected organisations will be subject to random checks, regular security audits, on-site inspections and off-site supervisions. For those found to be in breach of the regulations, penalties could be as high as 10 million Euros or 2% of their global turnover - whichever is higher.

The Ground It Will Cover

It’s highly likely that the UK’s NIS framework will be very similar to the EU’s version. This means that entities which come under its remit will be required to perform regular security assessments, adopt incident response plans, appoint a chief information security officer (CISO), and report significant incidents to the national authorities, among other obligations.

The UK government has indicated that its NIS update will follow the EU’s lead in improving and streamlining the way in which cyber incidents are reported to regulators. Under NIS2, organisations must notify of any incident that has a significant impact on the provision of their services, for instance by causing severe operational disruption or financial loss. 

There is also plenty of focus in NIS2 on the cornerstones of sound cyber risk management – in particular the proper control of administrator-level account credentials, privileged access, and endpoints, all of which are prime targets for attackers.

Expanding The Scope

A number of new sectors are being pulled into the regulations, including space, waste management, research and development and a wider range of healthcare companies. Organisations are split into ‘critical’ and ‘important’ entities.

The burgeoning third party threat will also be addressed. Managed Service Providers (MSPs) are being added to the list of ‘critical entities’ to which the directive applies, in a move designed to keep the digital supply chains involved in the running of essential services secure. MSPs are often granted privileged access to corporate systems and networks, which creates security risks. Cyber criminals can take advantage of any vulnerabilities to attack and disrupt multiple organisations, as illustrated in the devastating MOVEit breach earlier this year. 

How Should You Prepare?

Organisations should take action now to establish whether the EU or UK NIS2 regulations will apply to them, and ensure they can implement and demonstrate best practice in good time.

They need to determine their obligations in relation to cyber risk management. What changes need to be made to existing processes, policies and practices to meet them? Are the basic cyber hygiene principles in place? As a priority, businesses must review their incident response plans and incident management and reporting procedures. It’s also a good idea to get a head start on undertaking third party security assessments, and incorporating security requirements into contracts. 

Given the framework’s focus on protecting privileged admin accounts, businesses should take measures to limit who possesses these powerful credentials – both across the organisation and within the supply chain. Implementing privileged access management (PAM) will allow IT to control who is granted access to which systems, applications and services, for how long, and what they can do while they’re using them.

It’s important that organisations engage now with the requirements of the updated NIS2, and build an understanding of what it means for them - especially those that weren’t covered by NIS1.

This should be viewed as more than just a compliance exercise. By adhering to the strengthened framework, businesses will build a foundation of resilience that protects the organisation, the services they provide, the communities that use them, and the wider UK economy from threats that could cause significant disruption and even endanger lives. 

Graham Hawkey is  PAM specialist at Osirium

You Might Also Read: 

Connected Devices Must Be More Secure:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« British Police On High Alert After Supply Chain Breach
Undetected Attackers Could Be Inside Your IT Systems Now »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Vertical Structure

Vertical Structure

Vertical Structure services include Security & Penetration Testing, Information Assurance, Bespoke Training Programs and Secure Hosting.

Cyber Security Capital (CS^)

Cyber Security Capital (CS^)

Cyber Security Capital is a consultancy helping to mobilise and empower individuals, corporate leaders and entrepreneurs in cyber security.

Connectitude

Connectitude

Connectitude IIoT Platform ™ is a complete solution for industrial IIoT.

Jobsite

Jobsite

Jobsite is an award winning job board in the UK providing job listings in the key sectors of IT, Engineering and Finance.

Com Laude

Com Laude

Com Laude is a domain name management company that provides strategic consulting to help companies strengthen digital brand, safeguard customers & protect brand IP.

PreEmptive Solutions

PreEmptive Solutions

PreEmptive Protection hit the sweet spot between cost, convenience and functionality by helping you protect and secure your apps in a smarter way.

SecureWorx

SecureWorx

SecureWorx are a secure multi-cloud MSP, a provider of advanced IT security services and an independent cyber security advisory.

Mitiga

Mitiga

Mitiga uniquily combines the top cybersecurity minds in Incident Readiness and Response with a cloud-based platform for cloud and hybrid environments.

Computer Services Inc (CSI)

Computer Services Inc (CSI)

CSI is a leading fintech, regtech and cybersecurity solutions partner operating at the intersection of innovation and service.

Larsen & Toubro Infotech (LTI)

Larsen & Toubro Infotech (LTI)

LTI is a global technology consulting and digital solutions company with operations in 33 countries.

GoPlus Security

GoPlus Security

GoPlus is working as the "security infrastructure" for web3, by providing open, permissionless, user-driven Security Services.

HEROIC Cybersecurity

HEROIC Cybersecurity

HEROIC’s enterprise cybersecurity services help improve overall organizational security with industry best practices and advanced technology solutions.

Eficens Systems

Eficens Systems

Eficens Systems is a global IT services and consulting company. We specialize in empowering businesses to harness the potential of Information Technology as a strategic asset.

Fingerprints

Fingerprints

Fingerprints is the world-leading biometrics company. Our solutions are found in millions of devices providing safe and convenient identification and authentication with a human touch.

Fivecast

Fivecast

Fivecast is enabling a safer world. We help organizations around the world explore masses of data to uncover actionable insights.

Viatel Technology Group

Viatel Technology Group

Viatel Technology Group is a complete digital services provider. We have over 26 years’ experience delivering fully managed security, networking, cloud and communications services.