NIS2 and Operations: Key takeaways for OT
As promised, we're now also stepping into Industrial Cyber Security! First up: NIS2. Expect more of these articles and podcasts in the months to come :)
Since not everybody is working in cybersecurity, chances are you don’t really know what NIS2 is about nor why it matters to you. In this article, we’ll try to give you a high level view on what it means for you as an IT/OT professional. In the coming weeks and months, we’ll be publishing more in-depth guidance, stories and podcasts on the fascinating domain of Industrial Cyber Security!
But, for today, let’s start with what NIS2 is.
It isn’t a new standard or recommendation from a professional body. NIS2 or “Network and Information Security Directive” was adopted in the EU parliament in 2023 and describes what laws the member-countries need to implement to elevate the level of cybersecurity across the EU. At the moment of writing the law has been implemented in 21 of the EU27.
Unlike its older brother, NIS, NIS2 goes wider and deeper.
Wider because it now targets all manufacturing organizations, not just strategic ones like utilities.
Deeper because unlike NIS, the measures and requirements of NIS2 cover more scope, have higher fines (up to 2% of global annual turnover) and make C-level management personally liable in case of gross negligence.
That still doesn’t answer the question why this becomes your problem as a non cybersecurity and (probably) non C-level person. Just let the cybersecurity folks do what they need to do right?
Well, the addition of a single phrase expands the scope of NIS2 from your typical IT scope to every production site: NIS2 aims not only to protect your data and IT systems but the physical environment as well. This (non-accidental) addition means that systems that control your shopfloor are in scope: your SCADA, MES and even your HMI and PLC are now part of NIS2 scope.
If you want even more proof that the walls between IT and OT are becoming thinner, look no further. Thinking that you’re safe with a DMZ between level 3 and 4 and having the Purdue model implemented in your networks is simply not going to cut it anymore.
“Nice article David and Willem, but I’m not based in the EU, why should I care?”.
True, you won’t be audited, but your EU customers might. The directive explicitly requires companies to take a look at their entire supply chain and how it impacts their cybersecurity risks. Your customers must assess who they buy from, what security practices those suppliers have, and whether vulnerabilities in their supply chain could affect their own operations. That means a components manufacturer in the US supplying EU automotive or energy companies will find their security practices scrutinised by their own customers. Expect questionnaires, contractual security requirements, and requests for proof. NIS2 doesn’t need to apply to you directly to change what’s expected of you.
So we have personal liability of the CEO, huge fines, impact on the shopfloor and requirements that will propagate down the supply chain across the globe. But what exactly must be done? We saved you the time of going through the directive and picked out 4 elements that matter to you (don’t be afraid to check the official texts, it isn’t as scary as you’d expect)
The company’s management carries the responsibility for the cybersecurity governance : They must approve and oversee the measures that are set in place. That means that the moment they ask whether the organization is compliant and what the gaps are they’ll need a response and actions from IT and OT. (Chapter IV, Article 20)
Cybersecurity risk management measures are the ‘what you must do’ items on the list, and they’re not separated neatly in IT and OT categories. Some of them are broad and don’t make distinction between shopfloor and corporate IT systems like multifactor authentication requirements. And others require a concerted effort to set up business continuity plans and incident response plans where both IT and OT must work together. We’ll cover those in more depth in a follow-up article (Chapter IV, Article 21)
Reporting Obligations: Your organization has the obligation to report serious incidents in strict timelines: 24 hours for an early warning, 72 hours for full notification, one month for a final report. Those deadlines don’t care about IT or OT silos. (Chapter IV, Article 23)
Supervision & enforcement: Auditors can come in and start requesting evidence whether you’ve properly implemented and enforced the 10 measures. And while most IT organizations are already used to that, most plants would find it hard to come up with a complete asset inventory on the spot, have documented disaster recovery exercises or prove how MFA is implemented in their entire landscape. (Chapter VII)
Of those four, the risk management measures are the most interesting to us. In the next Cyber Security article we’ll go deeper into them and find where the IT/OT boundary makes each one harder to implement than it looks on paper.




Great article!
Every possible risk is in-scope when it comes to NIS2, as it is explicitly based on an all-hazards approach (Article 21, 2). Some companies try to avoid risks by definining them away. This will not work with NIS2 😊
It is also important to note that NIS2 requires any measures taken against these risks to be measurably effective (article 21 2-f). To enact measures is not enough.
All in all I think this is a shock to a lot of OT suppliers, and based on my own expericence - something too few suppliers have implemented in their core business. This is the GDPR moment IT went through a few years ago, where it was required to implement data protection by design. NIS2 requires cyber security by design in iT and OT.