NIS2 Directive: How it promotes cybersecurity

Direttiva NIS2 Come Promuove la Cybersecurity

The NIS2 Directive provides for various measures to increase awareness of cybersecurity risks and promote best practices. If you want to understand the foundation of this approach, you can also read about what the main objective of the NIS2 Directive is.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

NIS2 Directive: Best practices

  • National cybersecurity strategies: Member States are required to adopt national cybersecurity strategies that outline the strategic objectives, priorities, and resources necessary to achieve a high level of cybersecurity. Such strategies must cover specific sectors, including those listed in Annexes I and II of the Directive.
  • Awareness-raising plans: Within these national strategies, Member States must develop plans with specific measures to increase citizens’ awareness of cybersecurity.
  • Education, training, and awareness activities: The Directive encourages Member States to promote and develop education, training, and awareness activities related to cybersecurity. These activities must be aimed at citizens, stakeholders, and entities covered by the Directive, providing guidance on best practices and cyber hygiene controls.
  • Support for SMEs: Recognizing the specific needs of Small and Medium-sized Enterprises (SMEs), the Directive emphasizes the importance of providing them with accessible guidance and support to strengthen their cyber resilience and improve cyber hygiene.
  • Coordinated vulnerability disclosure: The NIS2 Directive establishes a framework for coordinated vulnerability disclosure, facilitating the reporting and responsible resolution of security flaws in ICT products and services.
    • This framework provides for the designation of a CSIRT contact point in each Member State to act as a coordinator for managing vulnerability reports and serving as a trusted intermediary between reporters and vendors.
    • This process aims to ensure that vulnerabilities are addressed in a timely manner, minimizing risks to users.
  • European vulnerability database: ENISA, in consultation with the Cooperation Group, will create and maintain a European vulnerability database containing information on publicly known vulnerabilities in ICT products and services.
    • This database will be accessible to all stakeholders, promoting transparency and enabling organizations to proactively address security gaps.
  • Information sharing: The Directive promotes information sharing between entities covered by the Directive, competent authorities, and CSIRTs, fostering a collaborative approach to addressing cybersecurity risks. This includes the exchange of information on cyber threats, incidents, vulnerabilities, best practices, and awareness-raising initiatives.
  • Peer reviews: The Directive encourages voluntary peer reviews among Member States to assess and improve their cybersecurity capabilities and policies. These reviews, conducted by cybersecurity experts from other Member States, can help identify areas for improvement and promote best practices.
  • Reporting of significant incidents: Entities covered by the Directive are required to report significant cybersecurity incidents to the CSIRT or the designated competent authority.
    • This reporting requirement helps ensure that incidents are addressed promptly and effectively, and that lessons are learned for the future.
    • If necessary, CSIRTs or competent authorities may inform the public about significant incidents to raise awareness and mitigate risks.
  • Biennial report on cybersecurity: ENISA, in collaboration with the Commission and the Cooperation Group, publishes a biennial report on the state of cybersecurity in the EU.
    • This report assesses the cybersecurity risk landscape, capacity building, awareness levels, and the maturity of cybersecurity resources in the EU.
    • The report is made public and provides recommendations for improving cybersecurity in the EU.

Through these comprehensive measures, the NIS2 Directive aims to promote a culture of awareness and responsibility regarding cybersecurity across the EU, encouraging organizations and individuals to take proactive steps to mitigate risks. For organizations that need to structure a concrete path toward NIS2 Directive compliance, it is useful to start with an assessment of the measures already implemented and the gaps to be filled. You can also consult the official document of the NIS2 Directive for the full reference text.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In