The NIS2 Directive Will Impact The Security Ecosystem Across The EU

In our increasingly digital and interconnected world, it’s little surprise that business leaders and governments are focusing on the cybersecurity of everything connected to the Internet. As the Internet of Things (IoT) expands, so do the opportunities for malicious actors to exploit devices, either as gateways to larger cyberattacks or to access data.

Indeed, the European Union Agency for Cybersecurity, ENISA, sees new threats to cybersecurity emerging because of the wealth of data that devices can now collect and the advances in AI that now make cyber-attacks more complex and scalable.

Here Comes The NIS2 Directive

The NIS2 Directive, a Europe-wide legislation that aims to improve the cybersecurity of network and information systems across the EU, goes some way in combatting the increased risk of cyber-attacks. It is a continuation of the first NIS Directive, with an expanded remit including digital infrastructure such as cameras and IoT devices. Any business that uses cameras and other connected devices will need to take additional steps to protect video network security and its data from 18 October 2024. 

Europe has had a long track record of leading the way in terms of data protection, with GDPR being a recent example. So, we can expect the NIS2 Directive to have some sway over other governments’ legislation in the coming years. It’s a savvy move for all organisations to follow the practices and guardrails put in place by the legislation, especially if they operate in, or do business with, Europe. 

Complying With The NIS2 Directive 

The NIS2 Directive focuses on two main areas: Protecting networks and information systems through proactive measures; and responding quickly when under a cyberattack.

Protecting your video network and other devices
Your video and IoT network is a unique target for hackers thanks to the data it collects, and which can be used to gain confidential information, for blackmail, or even to inform future cyber or physical attacks, through mapping out a building’s floor plan and schedules. 

Checking the fundamentals are in place to secure cameras is the first to-do on any user’s list. You can separate this into two main areas: asset management and access management. 

Asset management involves securing the hardware within your security system. That’ll include cameras, servers, and sensors. 

Of course, every device in your network will become vulnerable if its firmware isn’t kept updated. Users should check for the latest version as soon as it is installed, as some time can pass between a camera leaving the factory and its installation. Likewise, camera drivers should be updated to the latest software version. Some camera models come with factory passwords and these need to be changed quickly.

This brings us to access management best practices. Password sharing is common in many workplaces, but it can introduce significant vulnerabilities through stolen or misused passwords. Without unique login credentials, you cannot track who is in your system, and what they are doing. So, every individual needs their own access credentials for a video system. 

Individuals should be granted the level of access appropriate to their role, and that extends to a physical space too. If someone isn’t directly working on the maintenance or administration of the hardware and software, they shouldn’t have access to a server room and shouldn’t have admin rights. 

Getting the basics of video cybersecurity right will greatly reduce a system’s attractiveness to malicious actors. 

Rapid Cyber-Attack Responses
If the worst-case scenario happens and you find that someone has gained unauthorised access to your system, you’ll need to respond quickly. Where separation exists between a video network and wider IT infrastructure, containment will be relatively straightforward (hence, this is greatly advised to have in place!). 

Users should identify the affected devices and networks and, if possible, take them offline to disconnect them and prevent a widespread gateway attack. Checking audit reports will help understand who has accessed the system, what they did, and when.

It’s worth simulating an attack on your video system on a regular basis. This’ll allow you to test response times and processes, identify unused licenses or other vulnerabilities, and train your team. Under pressure, people often revert back to their habits and training, so ensuring that they understand what to do and what to avoid can make a huge difference in a cyber-attack. 
Your choice of partner matters
Partnering with a responsible manufacturer who puts cybersecurity at the core of product development can make a serious difference to cyber-resilience. 

Compliance with NIS2 Directive is just the start for anybody working in the digital realm. Governments worldwide are making concerted efforts to improve cybersecurity. Working together with a reputable manufacturer, organisations can rest assured that their video security ecosystems won’t be an easy target.

Jos Beernink is VP EMEA at Milestone Systems

Image: 

You Might Also Read:

Resilience As Regulation: Preparing For The Impact Of CER:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« Mobile & On-Line Banking Cyber Security [extract]
For Many Businesses Experiencing MultiCloud Data Breach, Multi-Cloud Security Could Be The Answer »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Digital Forensics Inc (DFI)

Digital Forensics Inc (DFI)

Digital Forensics Inc. is a nationally recognized High Technology Forensic Investigations and Information System Security firm

CyberArk Software

CyberArk Software

CyberArk is an established leader in privileged access management and offers the most complete set of Identity Security capabilities.

Axiomatics

Axiomatics

Axiomatics provides dynamic authorization and access control solutions to protect critical data assets.

ThreatBook

ThreatBook

ThreatBook is dedicated to providing real-time, accurate and actionable threat intelligence to block, detect and prevent attacks.

VADO Security Technologies

VADO Security Technologies

VADO Security enables the safe transfer of data between low & high security networks.

Secudos

Secudos

SECUDOS is an innovative appliance technology and services provider focused on IT security and compliance.

Culinda

Culinda

Culinda secures medical IoT devices in hospitals with An Artificial Intelligence platform and security gateway.

Workz Group

Workz Group

Workz connects and protects mobile subscribers of today and tomorrow by providing secure removable or embedded SIMs and remote provisioning solutions for consumer, M2M and IOT devices.

Horiba Mira

Horiba Mira

Horiba Mira is a global provider of automotive engineering, research and test services including services and solutions for automotive cybersecurity.

Newberry Group

Newberry Group

The Newberry Group provides comprehensive IT services and solutions that optimize operations, minimize risk and deliver measurable business value.

Precursor Security

Precursor Security

Precursor Security are information security specialist, delivering all aspects of Security testing, Cyber Risk Management, and Continuous Security Testing.

Sevco Security

Sevco Security

Sevco Delivers Real-time Asset Intelligence to Identify and Close Unknown Security Gaps.

Trisul Network Analytics

Trisul Network Analytics

Trisul helps organizations deploy full spectrum deep network monitoring which can serve as a single source of truth for performance monitoring, security analytics, threat detection and compliance.

IDECSI

IDECSI

IDECSI delivers cutting-edge technology and engages all employees in the security system for effective and cost-efficient data protection.

Tenchi Security

Tenchi Security

Tenchi Security are specialized in Third-Party Cyber Risk Management (TPCRM) and aim to reduce information asymmetry when it comes to third and Nth-Party security and compliance risk management.

Deepware

Deepware

Deepware is an emerging AI research company dedicated to exploring the potential of GenAI in both generation and detection.