731 901 601
New cybersecurity obligations for businesses – what do you need to know?

New cybersecurity obligations for businesses – what do you need to know?

The NIS 2 Directive is not just a set of new legal obligations. Above all, it represents a shift in the way organisations think about cybersecurity. Until now, many companies have treated IT security as a technical matter, confined to the IT department. NIS 2 introduces a completely different approach – a systemic one, based on risk management and business accountability.

Cybersecurity as part of risk management

One of the most significant changes is the move away from treating security as solely an IT matter. Companies must now identify key assets – such as systems, data and processes – and then analyse threats and assess their impact on business continuity.

This means adopting a risk-based approach, where measures are tailored to actual threats rather than merely to formal requirements. Regular security testing, updating procedures and continuous monitoring of the IT environment are becoming increasingly important.

Cybersecurity is no longer a one-off implementation, but is becoming an ongoing process, integrated into the wider management system of the organisation and its operational resilience.

The role of the board and organisational responsibility

The new regulations clearly shift responsibility to board level. It is the company’s senior management that is responsible for overseeing cybersecurity, making decisions and ensuring adequate resources – both technological and organisational.

As a result, the issue of security is elevated to a strategic level and becomes part of business risk management. The board must not only approve measures, but also understand the key threats, their potential consequences and their impact on the company’s operations.

This translates into greater involvement from senior management, the need to make informed decisions, and the integration of cybersecurity into the organisation’s long-term development planning.

Penalties and consequences as part of the system

Many companies still treat the NIS 2 Directive as ‘just another formal obligation’. This is a serious mistake.

The new regulations introduce not only obligations, but also real financial penalties and personal liability for senior management. In practice, this means that ignoring NIS 2 can have very costly consequences. Financial penalties can be as high as 10 million euros or up to 2 per cent of global annual turnover.

Penalties may be imposed, amongst other things, for:

1. Failure to implement security measures. If a company fails to adequately secure its IT systems, it exposes itself to sanctions – even in the absence of an incident.

2. Failure to report an incident. Failing to report a cyberattack within the required timeframe is one of the most common breaches.

3. Inadequate risk management. Failure to carry out a threat analysis or ignoring risks.

4. Supply chain issues. Liability also extends to suppliers and partners.

Preparing early for the requirements of NIS 2 helps to minimise risk and ensure your organisation adapts smoothly to its new obligations. Find out how we can help your company achieve compliance with NIS 2.

 

Read other posts

BRCGS Food Safety – an international food safety standard. What do manufacturers need to know?

BRCGS Food Safety – an international food safety standard. What do manufacturers need to know?

Food manufacturers operating within the supply chains of international retail chains are increasingly required to hold BRCGS Food Safety certification. read more
Deposit-refund schemes and the PPWR – how is the regulation changing the approach to returnable packaging?

Deposit-refund schemes and the PPWR – how is the regulation changing the approach to returnable packaging?

In October 2025, a deposit-refund scheme was launched in Poland for selected single-use packaging – PET bottles up to 3 litres, glass bottles up to 1.5 litres and aluminium cans up to 1 litre. read more
FSC in the furniture industry – when does certification cease to be a choice and become a tender requirement?

FSC in the furniture industry – when does certification cease to be a choice and become a tender requirement?

Furniture manufacturers have known for years that the quality of materials and precision of workmanship are fundamental. Increasingly, however, it is proving that this is not enough to win a contract. read more
More posts