- Register

 
 

Home>IIot & Smart Technology>Cyber Security>Addressing NIS2 cybersecurity implementation
ARTICLE

Addressing NIS2 cybersecurity implementation

12 August 2026

NIS2 is raising the bar for cybersecurity across Europe. Chris Whyborn explores what organisations need to do to strengthen cyber resilience, address supply chain risks and build a robust compliance framework.

THE REQUIREMENTS of Network & Information Systems 2 (NIS2), the European Directive, include supply chain security, incident handling and regular cybersecurity training. Organisations across the EU must now meet these cybersecurity requirements to ensure compliance. UK-based companies are legally required to comply with NIS2 if they provide services within the EU, regardless of their physical location. 

To avoid a regulatory gap and ensure the UK remains a safe place to do business, the government is introducing the Cyber Security and Resilience Bill (CSR). Its core principles have been aligned to ensure trading fluidity with the EU, while maintaining specific powers to tailor regulations to the UK’s unique infrastructure. Organisations that comply with the CSR are likely to have addressed a substantial proportion of NIS2 obligations.

NIS2 compliance importance

Businesses that comply with NIS2 can effectively identify and mitigate cybersecurity risks. This minimises operational disruptions caused by cyber incidents, as well as avoiding significant fines or reputational damage.

Cybersecurity vulnerabilities can affect network and information systems along an entire supply chain. NIS2 not only requires businesses to protect their own systems, they must also assess the risks in their supply chain. They must demonstrate that third parties with IT access and rights to remote maintenance or data processing are integrated into a robust security management system. Achieving NIS2 compliance builds trust and offers a competitive edge, as supply chain partners are reassured of cybersecurity.

NIS2 splits businesses into two categories – “essential” or “important”. Essential entities are in sectors like energy, health and banking, while important entities include those such as waste management, postal services or manufacturing. Both must implement the same baseline security measures, like encryption, incident reporting and multi-factor authentication, but how regulators deal with them differ. 

Regulators have the power to regularly inspect and audit essential entities at any time, while important entities are only approached by regulators if they have evidence of non-compliance, an incident or complaint.

Taking action

Regardless of whether they are considered essential or important entities, every company can take the following four steps for compliance to increase its cyber resilience.

• Risk assessments and gap analysis

Risk assessments and gap analysis reveal weaknesses in existing cybersecurity measures. The impact of data loss by a service provider or encryption of a specific system with ransomware is analysed. The differences between security measures and the ideal target state are identified, as well as an action plan to improve and minimise potential security risks. This enables companies to focus their resources efficiently on the most critical areas, optimise their cybersecurity investments, and reduce the risk of financial losses and reputational damage.

• Cyber awareness culture

Human behaviour remains an important gateway for cybercriminals, so employees should receive ongoing training. NIS2 emphasises the role and accountability of senior management, who are expected to be aware of cybersecurity risks and enforce their treatment through processes, controls, documentation and training.

• Supply chain focus

Vulnerabilities in suppliers’ systems give cybercriminals many options for exploiting the supply chain. For example, through the injection of malware into legitimate software updates, the compromise of third-party providers with access to a company's networks, an insider attack or even infected hardware. Companies should therefore examine these interfaces and other possible points of entry and secure them thoroughly. They must demonstrate that third parties with IT access are integrated into a robust security management system.

• Building trust and continuous improvement through internal audits and testing

Regular internal audits and penetration tests are essential. They provide insight into emerging vulnerabilities, support ongoing regulatory compliance and improve incident response capabilities. They also offer a systematic way to adapt security practices and maintain effectiveness and resilience across different types of facilities. Any gaps and vulnerabilities that are discovered must be addressed immediately and company-specific guidelines and processes adapted.

International standards

Internationally recognised cybersecurity standards ISO 27001 and IEC 62443 provide a useful basis for NIS2 compliance.

ISO 27001 provides a framework for establishing and maintaining an information security management system (ISMS) that can be applied internally and to external partners. An ISMS certified according to ISO 27001 covers some of the key requirements of the NIS2 Directive, which must be supplemented by appropriate measures.

The international IEC 62443 series of standards is intended to ensure the security of industrial control systems, control devices and development processes. These international standard guidelines for plant security cover all phases of industrial cybersecurity and underpin NIS2 in that environment.

Cohesive cybersecurity

NIS2 is a significant step in a cohesive cybersecurity framework, with it its implications extending beyond the EU. Sound cybersecurity practice, the UK’s CSR and other international standards offer a practical starting point for a structured compliance path towards. Organisations that comply with NIS2 requirements will strengthen their resilience, build trust with stakeholders, and gain a competitive advantage in a cybersecurity-conscious marketplace.

Chris Whyborn is head of cybersecurity services (UK & Europe) at TÜV SÜD Business Assurance

www.tuvsud.com/en-gb/cybersecurity

 
OTHER ARTICLES IN THIS SECTION
FEATURED SUPPLIERS
 
 
TWITTER FEED