published on
NIS2 and Data-Centric Security Are Raising the Bar for Cybersecurity across the EU
For more than 10 years, cybersecurity threats, breaches, and compromises have troubled key stakeholders across the European Union (EU). This is partly due to cybersecurity incidents being seen as increasingly endemic, but also because of the intense regulatory scrutiny this area has been subjected to. With this ever-present threat to the digital systems, infrastructure, and economic drivers of the EU, new regulations incentivize organizations to protect these critical systems from increasingly complex and malicious cyber-attacks.
The NIS2 Directive is an evolution of the Network and Information Systems (NIS1) Directive adopted in 2016 by the European Union with the aim of increasing cyber resilience of Member States and critical organizations. The NIS1 regulation was geared towards strengthening cybersecurity capabilities at a national level and improving information sharing between Member States. The directive also standardized cybersecurity reporting and incident management capabilities and increased transparency across the EU.
NIS2 significantly expands the scope and coverage of NIS1, and adds an additional level of regulatory scrutiny to a greater number of organizations. This blog post will help you evaluate what NIS2 means for your organization, identify key requirements, and understand the benefits of data-centric security.
NIS2 Directive
NIS 2 (which needs to be transposed into national legislation by October 17, 2024) is a regulation that aims to improve the cybersecurity resilience of critical infrastructure across the EU. The regulation does this by enforcing rational and consistent cybersecurity requirements across a significantly expanded range of critical business sectors.
Previous regulations (NIS1) applied to just two groups of critical organizations: Operators of essential services (water, transportation and energy infrastructure), and digital service providers (cloud computing, IaaS, PaaS, SaaS, online marketplaces, online search engines). NIS2 takes a much more expansive approach where the essential entities category has been expanded and an additional classification category called important entities has been added.
In addition to expanded coverage, NIS2 is also much more rigorous. The regulation imposes a specific set of comprehensive compliance requirements that include a detailed set of risk management obligations, stricter incident reporting guidelines and stricter guidance on implementing security measures. NIS2 also requires entities to manage the cybersecurity risks associated with their partners, suppliers, supply chains, and security providers.
NIS2 represents a considerable expansion of the EU’s cybersecurity regulatory framework. While it’s not a new framework, there are significant additional elements that make compliance a challenging prospect for organizations of any size. Large organizations that are already in compliance with NIS1 won’t face as many challenges as their smaller counterparts, but there are new elements of the framework that demand significant changes to operational processes in a bid to ensure compliance.
NIS2 Dramatically Expands Coverage
One of the biggest changes related to NIS2 is the expansion of coverage to additional entities. The previously defined Critical Sector list has been increased and an additional group of important services has been added under Article 2 of the NIS2 framework.

Essential entities: Large or mid sized organizations that operate in sectors deemed critical for the functioning of society and the economy. These sectors include, but are not limited to, energy, transport, banking, financial market infrastructures, health, drinking water supply and distribution, and digital infrastructure.
Important entities: Large or mid sized organizations that operate in sectors deemed important for the functioning of society. These sectors include, but are not limited to manufacturing of critical products, food production, waste management, public administration, and postal or courier services.
The EU has also simplified entity classification by adding a size clause, so all entities operating in critical sectors that are large (250+ employees and €50+ million annual revenue) or medium (50+ employees and €10+ million annual revenue) are automatically included in the scope. Smaller entities are generally exempt, however, if a small entity plays a crucial role within a critical sector, it may be included in the NIS2 regulation at the discretion of national authorities.
Estimates suggest that an additional 100,000 organizations will need to be compliant with NIS2 regulation across the EU. It is the responsibility of relevant national authorities to define these lists by April 17th, 2025.
| NOTE: A number of organizations have been designated as centralized single state jurisdiction entities due to the cross-border nature of the services they provide. As a result, these companies will be listed in only one national register to avoid duplication. These entities include domain name registration services, cloud computing service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, social networking services platforms, online marketplaces, and online search engines. |
Organizations should note that essential and important entities must meet the same regulatory requirements. However, the level of scrutiny each of these entities will be subjected to may differ. More importantly, there is a significant difference in the penalties that entities of each type face for noncompliance.
- For Essential Entities: Fines can be up to €10 million or 2% of the worldwide annual turnover of the organization, whichever is higher.
- For Important Entities: Fines can reach up to €7 million or 1.4% of the worldwide annual turnover, whichever is higher.
NIS2, like other similar regulations, also includes a personal liability clause for senior executives of both essential and important entities. These sanctions even go as far to include potential criminal sanctions for senior management in cases of gross negligence as outlined in Article 21, 23 and recital 64.
Regulatory oversight will be driven by local national authorities as NIS2 (unlike DORA) must be legislated into the national legal frameworks of EU member nations. Therefore the responsibility for enforcement will fall onto the national authorities of the member states. Although there is still some ambiguity around enforcement, it’s likely that the bulk of regulatory scrutiny will fall on large scale organizations in critical service sectors. Regardless of where enforcement is focused today, the severe penalties imposed under NIS2 make compliance an imperative for cybersecurity teams in organizations across all related sectors.
NIS2 Compliance Challenges
Based on the number of affected companies and enforcement imperatives, NIS2 significantly overhauls existing regulatory frameworks. However, from a historical perspective, it seeks to build on an existing framework to enhance the cybersecurity of existing environments and mechanisms without being too disruptive. Despite this, there are still a number of changes that represent major challenges when it comes to implementing NIS2.
Incident Reporting
Under NIS2, organizations are required to notify their National Authorities of incidents with “significant impact” within 24 hours. This notification must be followed by a more detailed report within 72 hours and a full investigation due no later than 30 days after the initial notification. The regulation stipulates that not only incidents, but threats must be reported to relevant national authorities. Affected organizations must report these incidents to national Computer Security Incident Response Teams (CSIRTs) which will, under the coordination of The European Union Agency for Cybersecurity (ENISA), produce enhanced cybersecurity vulnerability reports on a bi yearly basis.
Enhanced Focus on Supply Chain Security
Much like DORA, NIS2 focuses on enhancing the overall end-to-end resilience of EU supply chains. Responding to many systemic supply chain attacks via third party vendors, the regulation outlines mandatory guidelines to conduct security audits and risk assessments of their respective supply chains and implements contractual cybersecurity obligations with vendors. The regulation provides the legal backdrop for EU-level regulatory agencies such as ENISA to conduct Coordinated Security Assessments of supply chains as per article 22.
More comprehensive risk management requirements
NIS2 introduces stricter risk management requirements for organizations. For example, Article 21(2) specifies ten specific subdomains that organizations must adhere to in order to achieve NIS2 compliance. These subdomains are wide-ranging, and focus on several cybersecurity themes from policies and procedures to the use of multi-factor authentication. The European Commission has stated that it will adopt implementing acts to define the technical and methodological requirements of the requirements by October 17th, 2024.
NIS2 and Data Security
NIS2 is wide-ranging, and many of its compliance requirements are driven by the need to properly secure and manage critical and important entities’ data. The below outline is meant to serve as a guide to the most important data security considerations in the full text of the legislation.
Four Areas of Data Security
- NIS2 holds that the security of data at rest and in transit is a fundamental aspect of information system security. Recital 78 of the regulation highlights that: “…The security of network and information systems should include the security of stored, transmitted and processed data…”
- NIS2 emphasizes the necessity of protecting Intellectual Property and critical data files of important and critical entities. Recital 88 of the regulation focuses on this aspect and states: “…Essential and important entities should also address risks stemming from their interactions and relationships with other stakeholders within a broader ecosystem, including with regard to countering industrial espionage and protecting trade secrets…”
- NIS2 highlights the need to use sophisticated encryption technologies and data-centric security concepts to secure data in all phases of its lifecycle. Recital 98 in the regulation preamble states that: In order to safeguard the security of public electronic communications networks and publicly available electronic communications services, the use of encryption technologies, in particular end-to-end encryption as well as data centric security concepts, such as cartography, segmentation, tagging, access policy and access management, and automated access decisions, should be promoted.
- Finally, the core risk management framework emphasizes the need for detailed and documented policies encouraging usage of cryptography and encryption. Article 21 subsection (h) states that critical and important entities should at least have policies and procedures regarding the use of cryptography and where appropriate, encryption.
It’s worth noting that the data security requirements listed above still serve as a guide rather than technical standards — which will be outlined in more detail in the implementation documentation that is due for publication on October 17th, 2024. That being said, it is a virtual certainty that data security will be a key consideration of the technical considerations issued as a part of the implementation protocols.
Data-Centric Security May be Necessary for NIS2 Compliance
Data-centric security solutions like Seclore are uniquely positioned to help organizations meet and exceed the new requirements and challenges presented by NIS2 regulations. These solutions add protection, visibility, and control to digital assets (like those containing intellectual property), so those assets are protected at rest and in transit — even after they’ve been shared with third and fourth parties throughout an organization’s supply chain.
Many of the 100,000+ entities that are now subject to the NIS2 regulatory framework can benefit greatly from Seclore’s Data-Centric Security Platform to quickly address several key requirements such as:
- Recital 78: Seclore effectively encrypts and protects data at rest and in transit
- Recital 88: Companies in manufacturing sub-industries such medical devices, pharmaceutical, electronics, and others — that have previously had no compliance obligations — can establish robust IP protection frameworks to persistently protect and control sensitive digital assets throughout their entire lifecycle using seclore’s enterprise digital rights management and access control solutions.
- Recital 98: Seclore helps mitigate internal and external risks by persistently protecting digital assets with a data-centric security approach that lets information owners encrypt data and determine who can access any file, and for how long.
- Article 21 subsection (h): Seclore uses advanced cryptography solutions to ensure that files containing sensitive data are always secure, and that information owners are always in control of their critical data.
Compliance with NIS2 can be costly and time-consuming, but Seclore gives companies of any size an advantage when it comes to protecting their most sensitive data (particularly when it’s shared outside their organization) and increasing their cyber resilience. For many organizations now subject to NIS2, sharing data with partners, suppliers, and other third parties is a core part of their business. Data-centric solutions apply security measures alongside the data itself, so digital assets that contain sensitive information are always protected no matter how broadly they are shared or how many times they’re copied. Another key benefit of Seclore’s data-centric security solution is the ability to track activity related to protected digital assets and remotely modify or revoke access at any time.
One of the primary purposes of NIS2 is to make the critical entities that power modern society in the EU more resilient. As cybersecurity attacks become more frequent and sophisticated in today’s charged geopolitical climate, there have been an increasing number of attempts to compromise the infrastructure and intellectual property of EU entities by nefarious means (including attacks on less-secure third party networks). For decades, Seclore has protected the infrastructure and operational resilience of key industries including energy, defense, finance, health, and life sciences. With the adoption of NIS2, it’s more important than ever that these key industries continue to invest in cybersecurity solutions that make them more secure and also protect the sensitive information they share with third and fourth parties.
Seclore continues to define data-centric security by applying modern encryption, access and usage controls, visibility, and control as close to your sensitive data as possible. It also integrates seamlessly with discovery and classification solutions to automatically protect sensitive data, and can help power your SOC with activity-level telemetry for protected files.
Schedule a personalized demo to learn more.
