731 901 601
New cybersecurity obligations for businesses – what do you need to know?

New cybersecurity obligations for businesses – what do you need to know?

The NIS 2 Directive is not just a set of new legal obligations. Above all, it represents a shift in the way organisations think about cybersecurity. Until now, many companies have treated IT security as a technical matter, confined to the IT department. NIS 2 introduces a completely different approach – a systemic one, based on risk management and business accountability.

Cybersecurity as part of risk management

One of the most significant changes is the move away from treating security as solely an IT matter. Companies must now identify key assets – such as systems, data and processes – and then analyse threats and assess their impact on business continuity.

This means adopting a risk-based approach, where measures are tailored to actual threats rather than merely to formal requirements. Regular security testing, updating procedures and continuous monitoring of the IT environment are becoming increasingly important.

Cybersecurity is no longer a one-off implementation, but is becoming an ongoing process, integrated into the wider management system of the organisation and its operational resilience.

The role of the board and organisational responsibility

The new regulations clearly shift responsibility to board level. It is the company’s senior management that is responsible for overseeing cybersecurity, making decisions and ensuring adequate resources – both technological and organisational.

As a result, the issue of security is elevated to a strategic level and becomes part of business risk management. The board must not only approve measures, but also understand the key threats, their potential consequences and their impact on the company’s operations.

This translates into greater involvement from senior management, the need to make informed decisions, and the integration of cybersecurity into the organisation’s long-term development planning.

Penalties and consequences as part of the system

Many companies still treat the NIS 2 Directive as ‘just another formal obligation’. This is a serious mistake.

The new regulations introduce not only obligations, but also real financial penalties and personal liability for senior management. In practice, this means that ignoring NIS 2 can have very costly consequences. Financial penalties can be as high as 10 million euros or up to 2 per cent of global annual turnover.

Penalties may be imposed, amongst other things, for:

1. Failure to implement security measures. If a company fails to adequately secure its IT systems, it exposes itself to sanctions – even in the absence of an incident.

2. Failure to report an incident. Failing to report a cyberattack within the required timeframe is one of the most common breaches.

3. Inadequate risk management. Failure to carry out a threat analysis or ignoring risks.

4. Supply chain issues. Liability also extends to suppliers and partners.

Preparing early for the requirements of NIS 2 helps to minimise risk and ensure your organisation adapts smoothly to its new obligations. Find out how we can help your company achieve compliance with NIS 2.

 

Read other posts

FSC 2026 – changes to the standards and their significance for businesses

FSC 2026 – changes to the standards and their significance for businesses

Forest Stewardship Council (FSC) certification is undergoing a major update in 2025–2026, covering both the forest management standard and the rules for the use of FSC labels. read more
The Energy Efficiency Act and the ISO 50001 standard – what do you need to know?

The Energy Efficiency Act and the ISO 50001 standard – what do you need to know?

ISO 50001 is an international standard setting out the requirements for an energy management system. read more
Do you weld without ISO 3834 certification? Here’s what you’re risking

Do you weld without ISO 3834 certification? Here’s what you’re risking

Most welding companies that don’t have ISO 3834 certification aren’t doing a bad job. They weld well, have experienced staff, and satisfied customers. read more
More posts