NIS2 Directive: Action required
Cybersecurity is becoming increasingly regulated, also through Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (the “NIS2 Directive”), the text of which was published at the end of 2022. The Netherlands intends to implement this Directive in a new Cybersecurity Act.
The responsible minister has announced that the Netherlands will be unable to meet the deadline for the implementation of the NIS2 Directive (17 October 2024). Nevertheless, we advise companies to take action well before that date. Given the widened scope, renewed standards and increased sanctions, large parts of the public and corporate sectors will be affected. At any rate, self-regulatory organisations will want to take security measures in good time. As the NIS2 Directive will also have consequences for supply chains, it is important that both regulated companies and their trading partners make sound contractual arrangements. We will explain this below.
Existing laws and regulations
The NIS2 Directive replaces the current NIS Directive, which stems from 2016 and was implemented in the Netherlands on 9 May 2018 in the Security of Network and Information Systems Act (Wet beveiliging netwerk- en informatiesystemen ("Wbni")). The Wbni currently regulates “operators of essential services” like health care companies, energy companies, public transport companies and financial institutions, and “digital service providers” like online marketplaces, online search engines and cloud computer services. The operators of essential services and digital service providers have two important obligations already under existing law: taking suitable and proportionate security measures, and reporting incidents that may have significant implications to the Computer Security Incident Response Team (CSIRT, founded by the Ministry of Economic Affairs and Climate) and to a competent sectoral authority.
Expansions arising from the NIS2 Directive
Despite the relatively recent implementation of the first NIS Directive, the European Union believes that technical developments and the increased social importance of digital systems call for an expansion of laws and regulations. The NIS2 Directive regulates this in more than one way.
Firstly, the scope of application of legislation is broadened. Enterprises in sectors such as postal and courier services, chemicals, food, waste management, telecom, IT services, and central and regional governments fall within the scope of the Directive. The Directive will apply to large and medium-sized enterprises in these sectors. The distinction between operators of essential services and digital service providers will be replaced by two categories, namely “essential enterprises” that are subject to ongoing supervision, and “important enterprises” that are subject to ex post supervision.
Secondly, the existing security and reporting requirements will be aggravated. Security measures will have to meet more requirements, for example the security of the supply chain, policies and procedures regarding the use of cryptography and encryption, the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the regulated entity.
Application and sanctions
As a consequence of these expansions, compliance with security and reporting requirements is gaining importance. An increasing number of enterprises is expected to step up control of the cybersecurity risks posed to their activities or services, in order to prevent incidents and to minimise the impact of incidents on recipients of their services. The reporting of incidents will also become more standardised.
The importance of compliance follows also from the applicable sanctions. If essential enterprises fail to take sufficient security measures or to comply with their duty to report incidents, they risk big fines, among other things. Member States that implement the NIS2 Directive must set these fines at EUR 10 million or 2% of the total worldwide annual turnover, whichever is higher. Such sanctions are heavier than those for violation of the current Wbni, which carries a penalty of EUR 5 million maximum.
Action recommended
We recommend that you examine what the NIS2 Directive will mean for your enterprise well ahead of its implementation. Enterprises may not only be within the direct scope of application, but may also be involved indirectly as suppliers of the regulated enterprises.
Supply chains are important as cybercriminals will often take advantage of the weakest link in IT security. Then again, enterprises that have their own cybersecurity in order may be vulnerable through the deployment of less well secured suppliers. The NIS2 Directive expressly mentions the importance of supply chains, as well as the essential risk of supply chain attacks. Supervision at EU level will therefore also have to look at supply chains, for example by performing cybersecurity assessments.
In light of the above, we advise regulated enterprises and entities within supply chains to make sound contractual arrangements. These arrangements should at least concern the various technical, organisational and operational measures to control security risks. Besides, making arrangements about a fast exchange of information is recommended, as this will allow regulated entities to report security incidents to the relevant supervisory authority in time.
Do you have questions about what the NIS2 Directive means for your enterprise? Please contact Robert, Rosalie or Sabina.