NIS2 Opens New Page in Cybersecurity for Businesses

We share the latest interview with Daticum’s CEO, Georgi Tsekov, which was featured in Forbes Bulgaria. In the interview, he advised the business community about the recommendations related to the amendments to the Network and Information Security Directive—NIS2 and the upcoming deadline (17 October 2024) for compliance with the requirements. (The material below is a transcript of the interview, available in Bulgarian).

Mr Tsekov, the EU has extended the scope of measures and prescriptions for cyber threat prevention in the updated NIS2 Directive. How will this help businesses to achieve a higher level of cyber protection?

The amendment to the existing Directive includes many new requirements that will be in place by autumn 2024. The changes aim to strengthen cybersecurity resilience by covering key sectors where stricter regulations and a more standardised approach are being introduced. However, this comes at a cost – this strengthened stance on security benefits society as a whole, but businesses operating in the identified sectors face new compliance challenges.

What will NIS2’s implications be for businesses, and what strategies are recommended to comply with the changes ahead?

One of the most significant changes introduced by NIS2 is the extension of coverage. Previously, the directive was aimed primarily at critical infrastructure operators such as energy, transport, and healthcare. Now, a more comprehensive range of sectors is covered, including waste management, postal services, food, utilities, etc. The Directive affects companies with 50+ employees and an annual turnover of more than €10M, ensuring that even medium-sized enterprises in these sensitive sectors are subject to its provisions. The broader scope reflects the interconnectedness of the digital infrastructure, recognising that a cyber-attack on a single entity can have a cascading effect on multiple industries.

Stricter security requirements are imposed beyond the scope of NIS2. The directive introduces a risk management approach, requiring enterprises to identify and mitigate potential vulnerabilities in their systems proactively. This includes implementing robust cyber security measures such as access controls, data encryption, and incident response plans. In addition, NIS2 establishes a minimum list of security measures organisations must adhere to, ensuring a baseline level of protection in all areas.

Can you give specific examples to illustrate the impact on business?

The first example impacts all consumers and companies in e-commerce. Picture a scenario where a large online retailer experiences a sophisticated cyber-attack. Hackers gain unauthorized access to their cloud-based database, compromising millions of customers’ personal information and card details. According to NIS2 regulations, the merchant must report the incident to the appropriate authorities within 24 hours. This swift notification is crucial to minimize potential damage and prevent further exploitation of vulnerabilities. The company will also need to conduct a thorough investigation to understand the extent of the breach, identify the root cause, and implement corrective measures to prevent similar incidents.

This scenario highlights the importance of robust data security measures for e-commerce businesses. Businesses should invest in solid encryption technologies to protect customer data, implement multi-factor authentication protocols to limit unauthorized access, and regularly conduct security audits to identify and remediate potential vulnerabilities. In addition, establishing a comprehensive incident response plan that outlines clear communication protocols and procedures for notifying authorities is essential to ensure a rapid and effective response to cyber threats.

The second example concerns the cloud industry, i.e. Daticum’s direct activity as a cloud service provider. Cloud service providers serving enterprises from different sectors may also be targeted. Cloud service providers themselves fall under the extended scope of NIS2, and we are obliged to comply with the security requirements of the directive and report incidents. Stricter security protocols are being introduced for data storage and access in the cloud environment. In addition, we must ensure the security of our supply chain, which means we must assess the cyber security practices of the companies we partner with.

That’s why at Daticum, we advise businesses on how to address the challenges and use a methodology that helps achieve compliance with the directive’s requirements specific to us as a cloud service provider. As a cloud provider, NIS2 involves a unique set of challenges requiring a multi-faceted approach to ensure compliance.

Let me name a few of the requirements that are standards for us:

Dual Compliance: As cloud service providers, we must secure our infrastructure to adhere to NIS2 regulations. This includes robust security measures for our data centres, server networks and access control systems. In addition, we must extend our security measures to cover the data and systems of our customers operating in the relevant sectors. This may require offering multi-tiered service options with different levels of security controls and compliance certifications. We use automation tools and security orchestration platforms to streamline these processes and ensure consistent security across our infrastructure.

Supply chain security: The NIS2 highlights the importance of robust supply chain security. Cloud service providers can no longer operate in isolation. We must assess our partners’ and suppliers’ cyber security practices and potentially require stronger contractual agreements to ensure compliance with the Directive’s security standards. This may include conducting security audits of vendors, implementing data residency requirements to ensure customer data remains within certain jurisdictions, and working with partners to develop joint incident response plans.

Transparency and communication: building trust and transparency with our customers is crucial. Cloud service providers must communicate their NIS2 compliance efforts and how they protect customer data. This may include offering detailed security reports that describe the company’s security posture, compliance certifications, and incident response procedures. In addition, we may engage in joint risk assessments with clients, proactively identifying potential vulnerabilities in the shared environment. By encouraging open communication and demonstrating a commitment to security, we at Daticum build trust with customers and position ourselves as trusted partners.

What are your final recommendations to companies?

NIS2 represents a significant step forward for the EU in its efforts to create a more secure digital environment. Adapting to stricter regulations is challenging for businesses in the industries mentioned, but the long-term benefits outweigh the initial obstacles. By prioritising investment in cyber security and fostering a culture of awareness and collaboration, stakeholders can play a vital role in strengthening the EU’s overall cyber resilience. Contact our experts and let them take care of your cyber security in the cloud!