The NIS2 Directive addresses operational continuity and crisis management through a series of requirements aimed at strengthening the cybersecurity posture of essential and important entities, promoting cooperation, and establishing frameworks for incident and crisis management. If you want to better understand what the main objective of the NIS2 Directive is, you can read more in the dedicated article.
Operational Continuity Measures
- Article 21: This article establishes that essential and important entities must implement appropriate technical, operational, and organizational measures to manage cybersecurity risks to their systems and services. This includes measures to “prevent or minimize the impact of incidents” on their operations and the recipients of their services.
- Specific Requirements for Operational Continuity: Article 21, Paragraph 2, explicitly lists “continuity operations, such as backup management and disaster recovery, and crisis management” as key elements of the measures required for cybersecurity risk management. Organizations that want to structure a plan for compliance with the NIS2 directive must start precisely from these operational requirements.
- Focus on Supply Chain Security: The Directive recognizes the importance of supply chain security to ensure operational continuity.
- Article 21, Paragraph 2, includes “supply chain security” as a necessary element of cybersecurity risk management. This concerns aspects related to the security of relationships between entities and their direct suppliers or service providers.
- Article 22, Paragraph 1, tasks Member States, in cooperation with the Commission and ENISA, with conducting coordinated risk assessments of critical supply chains. Addressing vulnerabilities and dependencies within critical supply chains is essential to ensure operational continuity, especially in the event of disruptions.
Crisis Management Framework
- National Crisis Management Authorities: Article 9, Paragraph 1, establishes that each Member State must designate or establish one or more competent authorities for the management of large-scale cybersecurity incidents and crises. These authorities are referred to as “cybersecurity crisis management authorities“.
- National Response Plans: Each Member State is required to adopt a “national plan for the response to large-scale cybersecurity incidents and crises.” This plan must provide for:
- Objectives and procedures for managing cybersecurity incidents and crises.
- Roles and responsibilities of cybersecurity crisis management authorities.
- Integration of cybersecurity crisis management procedures into the general national crisis management framework.
- National preparedness measures, including exercises and training activities.
- Identification of relevant public and private sector stakeholders.
- Procedures and arrangements to ensure the effective participation of the Member State in the coordinated management of large-scale incidents and crises at the EU level.
- EU-CyCLONe (European Cyber Crisis Liaison Organisation Network): Article 16 establishes EU-CyCLONe to support the coordinated management of large-scale cybersecurity incidents and crises at the operational level. This network:
- Is composed of representatives of the cybersecurity crisis management authorities of the Member States. The Commission also participates, both as a full member (if the incident or crisis significantly affects services regulated by the NIS2 Directive) and as an observer.
- Aims to improve preparedness, develop shared situational awareness, assess impacts, coordinate crisis management, and support political decision-making during large-scale cybersecurity incidents and crises.
- Cooperation and Information Sharing: NIS2 emphasizes cooperation and information sharing between Member States, competent authorities, and relevant entities to improve crisis management. This includes provisions related to:
- Cooperation Group: Article 14 establishes a Cooperation Group composed of representatives from each Member State to facilitate strategic cooperation and information exchange on cybersecurity. This group is tasked with contributing to policy decisions, discussing best practices, and providing strategic guidance on crisis management.
- CSIRT Network: Article 15 establishes a network of CSIRTs composed of representatives from national CSIRTs. This network focuses on operational cooperation, including the exchange of information on incidents, discussion of coordinated responses, and mutual assistance during cybersecurity incidents. For NIS entities, it is also useful to know the obligations for designating a CSIRT contact person provided for by Italian legislation.
Training and Awareness
- Article 20, Paragraph 2: While primarily focused on cybersecurity risk management, this article requires Member States to ensure that members of the management bodies of essential and important entities receive adequate training. Furthermore, it encourages these entities to offer similar training to their employees to equip them with the knowledge and skills necessary to identify risks and assess cybersecurity risk management practices. Although not explicitly stated, this training likely includes aspects of operational continuity and crisis management.
What this means for organizations subject to NIS2
- NIS2 adopts a proactive approach to operational continuity by mandating cybersecurity risk management measures and highlighting the importance of continuity planning.
- The Directive establishes comprehensive frameworks for crisis management at both the national and EU levels, with the goal of ensuring a coordinated and effective response to large-scale cybersecurity incidents and crises.
- Information sharing and cooperation are central to the NIS2 approach, recognizing that cyber threats often transcend national borders and require joint efforts.
Through these requirements, NIS2 aims to improve the resilience of essential and important entities and, by extension, to strengthen the resilience of the internal market and EU society in the face of evolving cyber threats. For those who need to verify their position regarding registration obligations, it is also useful to consult the information on ACN and the list of NIS2 entities.
Frequently Asked Questions about operational continuity in NIS2
- What concrete measures must an organization adopt to meet the operational continuity requirements of NIS2?
- Article 21 requires at least a documented backup and disaster recovery plan, crisis management procedures, and a periodic assessment of supply chain-related risks. The measures must be proportionate to the size and risk profile of the organization.
- Who is responsible for cybersecurity crisis management at the national level in Italy?
- In Italy, the National Cybersecurity Agency (ACN) is the competent authority designated for the management of cybersecurity crises under NIS2. ACN also coordinates relations with the EU-CyCLONe network at the European level.
- Does NIS2 also require organizations to train their staff on crisis management?
- Yes. Article 20 provides that members of management bodies receive adequate training on cybersecurity risk management, and encourages organizations to extend similar training paths to all employees involved in operational security.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
