Cyberattacks present a major risk to businesses. It is not just that internal systems might be affected — worst case, society as a whole suffers, even across borders. The NIS2 directive aims to remedy that by establishing European standards for dealing with cyberattacks. Since October 18th, 2024, the directive has become binding for organisations in the EU. Businesses that ignore it face significant fines.
This article will give you an overview of the new directive, who it concerns and what you need to do to ensure compliance.
What is NIS2?
Cybercrime has become an EU-wide problem. According to a 2022 survey, 28 percent of SMBs were affected. Russia’s attack on Ukraine has increased the pressure. It is not just renegade hackers attacking businesses anymore, but state-backed crime syndicates. Among the most common attack types are phishing and ransomware attacks.
NIS2 is an answer to these developments. It is short for “Network and Information Security”, and refers to the second iteration of the original NIS directive. The new directive defines standards that are meant to increase the security posture of European businesses. The first NIS directive was introduced in 2016 and then expanded upon in 2022, resulting in NIS2. The European governments had until October 17th, 2024 to translate the directive into national law. NIS2 has been in effect since October 18th, 2024.

Which businesses are affected?
Since October 18, 2024, certain businesses must comply with the standards defined in NIS2. There are three main criteria:
- Sector: The business belongs to one of 18 economic sectors outlined by the directive
- Size: The business has more than 50 employees
- Revenue: The yearly revenue is more than 10 million euros
However, even organisations that don’t tick all these boxes might still be subject to NIS2 if an attack on them would negatively impact the general public.
The 18 sectors are divided into two groups — “essential entities” (11 sectors) and “important entities” (7 Sectors). The difference matters both in terms of supervision level and potential fines. “Essential entities” are regularly audited (proactive supervision), and the fines are higher. With “important entities,” audits occur only if there are indicators of a violation (reactive supervision). The fines are somewhat milder.
Here is an overview of the 18 sectors:
| Essential entities | Important entities |
| – Energy – Transport – Banking – Financial market infrastructure – Health – Drinking water – Wastewater – Digital infrastructure – ICT service management – Public administration – Space | – Postal and courier services – Waste management – Chemicals – Food – Manufacturing – Digital providers – Research |
The goals of NIS2
As the digital transformation picks up speed, so does the cybercrime industry. NIS2 is meant to put a stop to that. The directive aims to increase the cyber resilience of both public and private organisations. At the same time, it is meant to empower government agencies to react to cybercrime more effectively.
The directive’s three main objectives are:
- Increase the level of preparedness of EU member states against cyberattacks
- Increase cooperation among EU member states, as well as communication among businesses
- All economic sectors central to the functioning of society should adopt a security-driven culture
What happens if you ignore NIS2?
Businesses that are subject to NIS2, but ignore its provisions, will have to deal with severe fines. “Essential entities” must pay up to 10 million euros or two percent of their annual global revenue (whichever is higher). “Important entities” must pay up to seven million euros or 1.4 percent of their annual global revenue (whichever is higher).
How does NIS2 affect non-EU businesses?
NIS2 primarily affects EU businesses. However, if a non-EU business is located in the EU or offers services to EU businesses or citizens, then they must comply, too. Suppliers of EU businesses are affected indirectly, even if they don’t qualify as important or essential entities. Their EU customers might approach them and ask them to implement additional security measures due to new supply chain regulations specified in NIS2.
NIS1 vs. NIS2: What is new?
NIS2 is based on its predecessor, NIS1, which was introduced in 2016. NIS2 expands significantly upon the original directive, though.
For starters, more businesses are affected now. NIS2 added several new economic sectors, which are now considered critical to society, too.
Also, the reporting requirements have become stricter, incidents now must be reported to the national security authorities shortly after they happen. In general, the risk management requirements have increased. Businesses must implement extensive security procedures to ensure compliance. Furthermore, organisations now face significant fines should they not comply. In this context, the fine structure has been standardised. This will make it easier for the authorities to punish infringements as soon as they happen.
The NIS2 directive pays special attention to the supply chain. Not just the business itself, but also its suppliers, must uphold high security standards. Last, but not least — NIS2 empowers the national cyber security authorities as well as the ENISA (European Network and Information Security Agency). Their roles are shifting from advisory to enforcing.
These are the most important requirements
How exactly must companies behave now? What steps do they need to take?
The first thing to do — check if your organisation falls under one of the 18 economic sectors defined by NIS2 and also matches the size and revenue criteria.
If that’s the case, there are four urgent actions to take:
- Register your business with your national security institution
- Bring your risk assessment and management up to speed
- Investigate your supply chain
- Pay attention to reporting requirements
Let’s look at these in more detail.
1. Register with your national security institution
If your business is required to comply with NIS2, your national security agency needs to know about it. Typically, you must initiate contact, not vice versa. The details depend on your respective national transposition of the NIS2 directive.
Your national security agency will then register you either as an “essential entity” or an “important entity.” Typically, “essential entities” have much less time to register, while “important entities” have more time. Again, the exact time frames depend on the transposition law in your respective country.
2. Bring your risk assessment and management up to speed
NIS requires businesses to conduct regular risk assessments. “[…] appropriate and proportionate technical, operational and organisational measures” must be taken to secure the systems. This applies to both the IT infrastructure and its physical environment. Action items include:
- Develop risk analysis frameworks
Businesses should develop frameworks for risk analysis and security management. This includes risk assessment processes and measures to minimise risks. These frameworks should be revisited regularly. - Implement incident management
In the event of an incident, procedures must be in place for rapid detection, analysis and threat containment. Companies should be able to react quickly. - Ensure business continuity
Companies must have detailed plans for how they can restore data and systems in the event of an attack, the goal being to avoid business interruptions, or at least keep downtime to a minimum. - Develop purchasing guidelines
Before any IT-related purchases are made, companies should consider security implications first. Businesses should only use safe technologies and upgrade their hardware and software assets regularly. - Evaluate security measures
As part of regular IT audits, businesses should evaluate the effectiveness of their current security measures. - Practice cyber hygiene
One-off implementation of security measures is not enough. Cyber hygiene must be practised on an ongoing basis. This includes regular employee training to increase awareness of common attack vectors. - Use encryption
Data should be encrypted to guarantee data integrity. - Set up access controls
Employees often have more permissions than they need. Hence, access rights should be given out sparingly and reassessed regularly. - Implement multi-factor authentication
Businesses should implement multi-factor authentication to prevent unauthorised access to systems. - Secure your communication
All communication channels should be adequately secured. This includes email, video calls and voice messages.
3. Investigate your supply chain
NIS2 requires organisations to extend their security efforts to the supply chain. The reason — hackers could use the supply chain as a gateway for attacks. But even if they don’t get through, they could indirectly bring a business’s operations to a halt.
An example: According to NIS2, energy companies are an essential entity, as they guarantee a country’s energy supply. However, manufacturers of wind turbines could also be affected by NIS2 when they are part of an energy company’s supply chain.
These security requirements must be included in the contracts with the suppliers. Depending on the products or services offered by the suppliers, the authorities can also ask for security certifications.
4. Pay attention to reporting requirements
In the event of a security incident, businesses must immediately inform the national security authorities. NIS2 defines specific deadlines:
- Early reporting within 24 hours
Once the incident has been discovered, businesses have 24 hours to report it. They must describe the incident as precisely as possible. They must also specify if the incident is “suspected of being caused by unlawful or malicious acts or could have a cross-border impact.” - Second report within 72 hours
Businesses must provide a first evaluation of the incident within 72 hours. They must specify the severity, the impact and indicators of compromise. - Final report after one month
Businesses must submit a final report no later than one month after the incident. The report should provide a detailed description and why the incident happened in the first place. The report should also specify mitigation measures.
What role does ENISA play?
ENISA (European Network and Information Security Agency) plays an important role in the NIS2 directive.
The agency was founded in 2004 to ensure a uniform level of cybersecurity in Europe. Part of that is providing technical advice to policymakers. But ENISA also supports member states with implementing new cybersecurity standards like NIS2. Overall, the role of ENISA will be strengthened by the new directive.
| Interesting fact: The member states are responsible for ensuring compliance with NIS2. They must appoint “Computer Security Incident Response Teams” (CSIRTs), which handle all national incidents. These single points of contact are meant to facilitate more cooperation among member states. This is accomplished by each CSIRT reporting to ENISA; here, all threads come together. In turn, ENISA will share relevant information with other member states, e.g., threat intelligence. |
How companies benefit from NIS2
In the current cyber threat landscape, the question is no longer “if” a company will be affected by an attack, but “when.” It should be in the company’s own interest to implement NIS2. Of course, the high fines imposed by NIS2 are another reason to take the directive seriously. Those who do so will benefit from several advantages:
Building trust
Businesses that make an effort to improve their security posture and protect customer data are seen as more reliable partners.
Competitive advantage
Imagine a new client is trying to choose between giving their business to you or a competitor. But unlike the competitor, you have had fewer cyber incidents and data breaches. The client will likely choose you, the “safe” option.
Future-proofing your business
By implementing NIS2, companies are better prepared for future legislative requirements, which are sure to come. They have already built on a solid foundation.
Faster response time
NIS2 requires companies to create incident response plans. This allows you to react quickly and efficiently. You are more likely to prevent a large-scale infection of your systems.
Culture change
By complying with NIS2, you promote a culture of security in your company. This makes you both more resilient and more economically efficient, as there are fewer business interruptions.

Challenges
Certain businesses that were not previously affected by the NIS directive are now subject to the new NIS2 directive. They have to play catch-up and implement numerous new security measures quickly.
Accomplishing this internally is difficult. The in-house teams of many SMEs are already busy with day-to-day operations. Also, there is often a lack of internal know-how when it comes to IT security. The solution is to partner with an external IT security provider. These providers have both the manpower and the expertise to quickly implement customised security solutions.
Another stumbling block is supply chain security. Companies must not just focus on their own systems, but also scrutinize the IT systems of their suppliers. This increases complexity. Also, the supplier might not always cooperate as wished. Again, working with a specialised security provider can help. They know the supply chain demands of NIS-2 in and out and have handled negotiations with suppliers before.
Finally, businesses must provide documentation and carry out regular IT audits — both tasks that are regularly postponed. Here too, an external provider can offer support. They have tried and tested tools that greatly simplify these tasks.
Proact is your reliable security partner when facing these challenges. We make sure you comply with NIS2 and reduce your attack surface. This way, you avoid fines that could jeopardise the future of your business.
7 steps for implementing NIS2
Proact has developed a seven-step framework to support companies implementing NIS2. This framework will strengthen your cyber resilience and make sure you recover quickly after an attack.
Step 1: Preparation
During this first phase, we sit down with your in-house team to evaluate potential risks and vulnerabilities. We identify critical assets and define recovery objectives.
Step 2: Backup
Next, we create a comprehensive backup strategy to safeguard your business. This includes performing regular backups of critical data, redundant storage locations and using multiple types of backup media.
Step 3: Detection and notification
Every organisation should have processes in place to immediately detect a cyberattack. Proact will set up modern detection tools to notify you right away in the event of an incident. With Proacts SOC (Security Operations Center) service you get a full MDR/XDR service with clear reporting, ongoing security posture reviews, and security improvement plans.
Step 4: Containment and recovery
Once an attack has been discovered, it is crucial to contain the threat and prevent it from spreading further, especially if you are dealing with a ransomware attack. To do so, the infected segments must be isolated. Sometimes, it might even be necessary to shut the systems down. Then the recovery process kicks in. Overall, our experts work hard to keep the downtime to a minimum. Proact has the capability to contain the threat, do the forensics, test and recover.
Step 5: Investigation
Once the attack has been contained, Proact conducts a thorough investigation. We determine infection vectors, look at the extent of the attack and assess the damage. This helps identify previously unknown risks and vulnerabilities.
Step 6: Remediation
During this phase, we help you close any newly discovered security gaps. This might include securing endpoints, improving your patch management or training your employees.
Step 7: Recovery
The final step is to fully restore all systems. In this context, we also check and validate the backup data once more.
As you can tell — IT security is an iterative process. You must constantly revisit and improve your security measures. Only those who embrace this process will protect their data in the long term. Proact can help you improve your security posture while complying with NIS2.

We help customers in their journey to be compliant
Would you like to become NIS2 compliant and increase your cyber resilience at the same time? Then you should talk to our Proact experts. With our managed security services, we address all the requirements of the new EU directive. Instead of putting a lot of extra stress on your in-house team, you can outsource to a highly specialised partner. This allows you to focus on your core competencies while we take care of your security needs. At the same time, we stay in close contact with your in-house experts to keep them in the loop and ensure efficient processes.
At the heart of our NIS2 strategy is our proven, seven-step resilience framework. Using this process, we have already created NIS2 compliance for numerous SMEs. These companies now enjoy peace of mind — their cyber resilience has been significantly improved, and high fines have been avoided. You will soon enjoy the same peace of mind with Proact!
Does this sound interesting? Then contact our team today for a free demo.