2 Comments
User's avatar
Geir Thomas Nordskog's avatar

Great article!

Every possible risk is in-scope when it comes to NIS2, as it is explicitly based on an all-hazards approach (Article 21, 2). Some companies try to avoid risks by definining them away. This will not work with NIS2 😊

It is also important to note that NIS2 requires any measures taken against these risks to be measurably effective (article 21 2-f). To enact measures is not enough.

All in all I think this is a shock to a lot of OT suppliers, and based on my own expericence - something too few suppliers have implemented in their core business. This is the GDPR moment IT went through a few years ago, where it was required to implement data protection by design. NIS2 requires cyber security by design in iT and OT.

David Ariens's avatar

Thank you! Great addition

And I agree, the sense of urgency still feels really low…