A European directive strengthening the cybersecurity obligations of a broad range of essential and important entities.
The NIS2 directive, which succeeds the first directive on the security of network and information systems, is the European framework aiming to raise the common level of cybersecurity within the Union. It considerably broadens the scope of entities covered compared with the initial text, encompassing a wide range of sectors deemed essential or important, energy, transport, health, digital infrastructure, public administration, manufacturing, among others. It imposes on these entities enhanced cybersecurity risk-management obligations, minimum technical and organizational measures, an obligation to notify significant incidents within short deadlines, and engages the responsibility of management bodies on these matters. Penalties for breach can be substantial. Transposition by member states has followed varying timetables, creating a period of uneven application across countries. For cyber insurance, NIS2 is structuring on two counts, by raising the required level of security it can reduce the frequency of certain losses, but by multiplying obligations it also creates new regulatory and directors' liability exposures, which fuel demand for dedicated covers.
A mid-sized company deemed an important entity under NIS2 must now formalize its cyber risk management and report its major incidents, its directors potentially being held responsible for a breach.
NIS2, directive NIS 2, network and information security 2