As promised, we're now also stepping into Industrial Cyber Security! First up: NIS2. Expect more of these articles and podcasts in the months to come :)
Every possible risk is in-scope when it comes to NIS2, as it is explicitly based on an all-hazards approach (Article 21, 2). Some companies try to avoid risks by definining them away. This will not work with NIS2 😊
It is also important to note that NIS2 requires any measures taken against these risks to be measurably effective (article 21 2-f). To enact measures is not enough.
All in all I think this is a shock to a lot of OT suppliers, and based on my own expericence - something too few suppliers have implemented in their core business. This is the GDPR moment IT went through a few years ago, where it was required to implement data protection by design. NIS2 requires cyber security by design in iT and OT.
Great article!
Every possible risk is in-scope when it comes to NIS2, as it is explicitly based on an all-hazards approach (Article 21, 2). Some companies try to avoid risks by definining them away. This will not work with NIS2 😊
It is also important to note that NIS2 requires any measures taken against these risks to be measurably effective (article 21 2-f). To enact measures is not enough.
All in all I think this is a shock to a lot of OT suppliers, and based on my own expericence - something too few suppliers have implemented in their core business. This is the GDPR moment IT went through a few years ago, where it was required to implement data protection by design. NIS2 requires cyber security by design in iT and OT.
Thank you! Great addition
And I agree, the sense of urgency still feels really low…