Brutalist concrete structure

REGULATION — NIS2

Under NIS2, cyber accountability reaches the management board.

NIS2 widens the EU cyber baseline to essential and important entities across energy, transport, water, health, digital infrastructure, public administration, manufacturing and more — and member states were required to transpose it into national law by 17 October 2024.

WHAT IT DEMANDS

A wider net, and a named owner at the top.

NIS2 — Directive (EU) 2022/2555 — replaced the original 2016 NIS Directive. It pulls far more organisations into scope, classifying them as essential or important entities, generally where they cross a size threshold. If you sit in one of the covered sectors and clear that bar, the directive applies to you.

The shift that catches people out is governance. Management bodies must approve and oversee the entity's cyber risk-management measures, and can be held liable for failures. Senior management can face sanctions. Cyber is no longer something the board receives — it is something the board owns.

THE ARTICLE 21 BASELINE

Industrial infrastructure

The 24-hour clock starts whether or not you're ready for it.

THE REPORTING TIMELINE

24h

Early warning

An initial early warning to the relevant authority within 24 hours of becoming aware of a significant incident.

72h

Incident notification

A fuller notification within 72 hours, updating and assessing the incident as understanding develops.

1mo

Final report

A final report within one month, setting out the incident, its cause, and the measures taken.

WHERE FIRMS TRIP

HOW WE HELP

Bring the board into the room, and the rest of NIS2 gets a lot easier.

Start a conversation