Discussion about this post

User's avatar
Geir Thomas Nordskog's avatar

Great article!

Every possible risk is in-scope when it comes to NIS2, as it is explicitly based on an all-hazards approach (Article 21, 2). Some companies try to avoid risks by definining them away. This will not work with NIS2 😊

It is also important to note that NIS2 requires any measures taken against these risks to be measurably effective (article 21 2-f). To enact measures is not enough.

All in all I think this is a shock to a lot of OT suppliers, and based on my own expericence - something too few suppliers have implemented in their core business. This is the GDPR moment IT went through a few years ago, where it was required to implement data protection by design. NIS2 requires cyber security by design in iT and OT.

1 more comment...

No posts

Ready for more?