No se han encontrado resultados.
No se han encontrado resultados.
Todas las entradas

NIS2; risks and opportunities for businesses

autores

Fabio Borri
No se han encontrado resultados.

Contenido

Esta será la URL que hay que copiar

Introduction and regulatory references


NIS is an acronym that stands for "Network and Information Security".

With this acronym; the European Community intended to denote the legislative effort to define a standardised approach to cyber security in all EU Member States.

In 2018; the first European regulation called NIS1 (EU Directive 2016/1148) was passed; transposed at national level by Legislative Decree 65 of 18/05/2018.

The NIS Decree also provided for the adoption of a 'national cyber security strategy' by establishing the Italian CSIRT (Computer Security Incident Response Team) with technical tasks related to the prevention; response and monitoring of cyber incidents; in collaboration with European CSIRTs.

NIS1 was subsequently superseded by NIS2 (EU Directive 2022/2555); transposed at national level by Legislative Decree 138 of 4 September 2024.

NIS 2 aims to overcome the limitations of NIS 1; which left too much discretion to Member States during transposition; resulting in a failure to achieve the objective of harmonisation; and also excluded certain categories of entities that should have been regulated because of their importance to the European market.

Furthermore; NIS2 was introduced to respond to the increase in the rate of digitisation that has taken place in all Member States and has been accelerated by the pandemic; which has expanded the surface area for cyber attacks without a corresponding increase in security systems.

Finally; another objective of NIS2 is to oblige operators of essential and important services and digital service providers to adopt adequate security measures and to report incidents promptly to the competent authorities and users of their services.

The new directive has been aligned with other specific European sectoral regulations; including:

- the Directive on Digital Operational Resilience for the Financial Sector (DORA). This is the Regulation approved on 10/11/2022 with the aim of increasing security measures in favour of the resilience and cybersecurity of the financial sector through the implementation of a series of mandatory security measures that guarantee the integrity of information and the cybersecurity of services;

- the Critical Entity Resilience Directive (CER); aimed at ensuring legal clarity and consistency between the various directives.

The companies concerned have been divided into:

  • Essential entities (energy; transport; health; water supply; public administration; finance; space; digital infrastructure)
  • Important entities (research; chemicals; food; industrial production; digital providers; postal services; waste)
  • Public bodies: Central government (constitutional and constitutionally relevant bodies; the Prime Minister's Office and ministries; tax agencies; independent administrative authorities) | Regional government (regions and autonomous provinces) | Local government (metropolitan cities; municipalities with > 100;000 inhabitants; regional capitals; local health authorities) | Other public entities (economic regulatory bodies; economic service providers; associations; welfare; recreational and cultural service providers; research bodies and institutions; experimental zooprophylactic institutes) | Other types of entities (entities providing local public transport services; educational institutions carrying out research activities; entities carrying out activities of cultural interest; in-house companies; investee companies and publicly controlled companies)
  • Suppliers: organizations that provide critical services to entities affected by NIS2 must strengthen their digital security; even if they are explicitly included in the mandatory sectors.

Content of NIS2


The general obligations inherent in the content of NIS2 can be summarised on the basis of four main pillars:

Governance: Management must approve the risk management measures adopted by the organization and assess their effectiveness over time: follow regular training on cybersecurity issues and offer similar training to employees.

Risk management: the organization must assess security and network risks and adopt appropriate and proportionate technical; operational and organisational measures to prevent or minimise the impact of incidents on the recipients of its services.

Business continuity: the organization must adopt solutions to ensure business continuity (e.g. backups; disaster recovery plan and crisis management procedure); aimed at minimising the impact of any interruptions to the services provided.

Supply chain: the company must assess the vulnerabilities of each direct supplier and the overall quality of its suppliers' products and cybersecurity practices. The assessment will cover ICT suppliers and other critical suppliers that could cause disruption to the service for which the organization has been included in the NIS2 perimeter.

Companies will therefore be required to be able to measure and report on:

  • Risk analysis and information system security policies
  • Incident management procedures
  • Business continuity solutions (backup and disaster recovery) and crisis management and communication procedures
  • Supply chain security policies (suppliers and service providers)
  • Security in the acquisition; development; maintenance and management of information system and network vulnerabilities

NIS2 Timeline


Companies and public administrations will have to carry out an assessment to understand whether or not they are subject to the obligations of the NIS2 Directive.

From 1 December 2024 to 28 February 2025; companies should have authenticated themselves on the ACN (National Cybersecurity Agency) Portal using their SPID credentials. During this period; users designated as contact points for each company should have completed a declaration via the NIS/Registration Service.

In particular; companies are required to:

  • Indicate whether the entity is part of a group of companies and provide the tax code of the parent company; if applicable.
  • List the related companies and provide their tax codes.
  • List the ATECO codes describing the entity's activity.
  • Indicate the relevant European Union sectoral regulations.
  • Provide turnover; balance sheet and number of employees figures to determine the category of the company.
  • List the types of entities to which the company belongs.


By 17 January 2025; operators of top-level domain name registries; providers of domain name system and domain name registration services; cloud computing; data centers; content delivery network providers; managed service providers; managed security service providers; as well as online marketplace providers; online search engine providers and social networking service platform providers should have registered on the platform.

By 31 March 2025; the ACN compiled a list of essential and important entities based on the registrations received through the platform.

Between 1 April 2025 and 15 April 2025; the ACN notified the entities concerned whether they had been included in the list of essential or important entities.

By 15 April 2025; the entities that received the notification were required to appoint; by means of a specific act; an entity responsible for fulfilling the obligations of the decree.

After that; the entities affected by the Directive will have to comply with further requirements:

  • by 1 January 2026; incident reporting obligation
  • by 1 October 2026; obligations regarding administrative bodies and security measures must be fulfilled


Each year; the ACN will update the list of entities involved. Companies and public administrations will have the opportunity to register each year; between January and February; if they consider themselves to be among the entities concerned.

Risks for companies but also opportunities


Following the entry into force of NIS2 and the identification of the operators involved; the competent authorities may carry out surveillance and spot checks to verify their compliance with the Directive. In the event of non-compliance; penalties will be applied to the companies involved.

The penalties are very severe: for large companies; up to €10 million or 2% of global turnover; for medium-sized enterprises; up to €7 million or 1.4% of global turnover.

Although compliance with the regulations requires a clear effort and investment on the part of companies; it must also be recognized that the regulations themselves seek to provide a substantial remedy to the problem of cyber attacks; to which Italian companies are still very susceptible and which they often tend to cover up for image reasons. In economic terms; the estimated average damage for each individual cyber attack is more than €2 million; regardless of the company's turnover.

How ERA can help with NIS2 compliance management


Despite all of the above; which might suggest that companies are extremely interested and involved in cyber security issues; it is not uncommon; especially among small SMEs; to find companies that have done little or nothing about these issues and are currently unable to define their position in terms of the risks to which they are exposed; both from a technical point of view and in terms of compliance with the various existing regulations.

Some companies address the issue of cybersecurity through insurance coverage. However; insurance companies are often reluctant to offer this type of protection to companies that have never taken concrete action in the cyber sphere. This is because there is no reliable method for accurately estimating the damage caused by a cyber attack. As a result; 'NIS2 packages' focus on cyber risk assessment services; but leave it up to companies to take the necessary measures to address any gaps. ERA can offer a more comprehensive service; relying on a network of highly qualified suppliers at very competitive commercial terms.

In detail; ERA's support consists of:

  • An assessment of the company's organisational and technical structure; with the aid of self-assessment questionnaires using predefined indicators;
  • Awareness-raising and training courses; with basic courses for all staff and advanced modules for top and middle management; in line with NIS2 guidelines;
  • Specific and highly qualified tests on vulnerability analysis; phishing treatment and ransomware risk assessment;
  • Support from dedicated consultants during the remediation phase following the assessment;
  • Specialised support from dedicated consultants to guide strategic decisions in the field of cybersecurity.


Our solution includes analysis of compliance with NIS2 regulations; which is certainly the most urgent concern; but can also accompany the customer in the project management of the remediation phase; i.e. the phase in which the customer must remedy the various 'flaws' identified in the diagnosis process; and is the phase in which the difficulties of some companies are most apparent; both in terms of internal skills and the availability of time and resources.

Artículos relacionados

Quizás también te interese

Perspectivas

Barómetro de gestión de costes 2025: Edición para el comercio minorista y mayorista

Perspectivas

SORP 2026: lo que deben saber las organizaciones benéficas y cómo prepararse

Perspectivas

La laguna en la supervisión: cuando la optimización de costes «ya está cubierta»

Perspectivas

Los costes ocultos en el reparto de los gastos de comunidad: lo que los directores financieros deben saber como inquilinos

Perspectivas

Resumen de 2025: costes, complejidad y el camino hacia 2026

Perspectivas

Información de mercado 2026.1

Perspectivas

¡El Grupo ERA se estrena en la India!

Perspectivas

Fuel Finder: ¿herramienta de transparencia o impulsor de beneficios?

Perspectivas

Cómo crear un núcleo digital resiliente

Perspectivas

La IA en las compras: convertir la inteligencia financiera en una ventaja estructural

Perspectivas

El Grupo ERA nombra a Marcel Lal nuevo director global de desarrollo

Perspectivas

La inteligencia de costes en la práctica: el sector sanitario

Perspectivas

La contracción de los beneficios tras el pico: prioridades del primer trimestre para los directores generales y financieros del sector minorista

Perspectivas

Más allá de la resiliencia: una guía estratégica para el crecimiento de la cadena de suministro en 2026

Perspectivas

Costes de producción y de transporte: la fabricación en un mundo marcado por los aranceles y los altos precios de la energía

Perspectivas

La economía mundial, resistente (pero aún incierta)

Perspectivas

Por qué los líderes de organizaciones sin ánimo de lucro deben hacer más con menos... y demostrarlo

Perspectivas

Del contrato a la ventaja: cómo los líderes convierten los acuerdos con los proveedores en motores de rendimiento

Perspectivas

La directora ejecutiva de BNI Global, Mary Kennedy Thompson, se incorpora al Grupo ERA como asesora del consejo de administración

Perspectivas

5 prioridades en materia de compras para 2026: de la visibilidad de los costes a la inteligencia de costes

Perspectivas

La crisis del sector hostelero en Escocia: cuando el aumento de los precios convierte la supervivencia en un verdadero reto

Perspectivas

Repensar la tecnología: prosperar cuando el cambio nunca descansa

Perspectivas

Las tensiones en Oriente Medio y su repercusión en los costes empresariales

Perspectivas

El impacto de las cotizaciones a la Seguridad Social a cargo del empleador: por qué se está ralentizando la contratación y cómo contrarrestarlo

Perspectivas

El poder estratégico de las compras

Perspectivas

Construyendo un futuro más sólido para la industria de los videojuegos del Reino Unido

Perspectivas

El conflicto en Irán está afectando a las tarifas fijas de electricidad y gas

Perspectivas

Barómetro de gestión de costes 2026

Perspectivas

El día en que la electricidad también empezó a mostrar un cartel de «agotado»

Perspectivas

El Grupo ERA identifica cuatro retos clave que están obligando a las empresas de servicios profesionales a actuar con urgencia

Perspectivas

Acuerdos de aplazamiento del pago en tiempos difíciles

Perspectivas

Información de mercado 2025.4

Perspectivas

El apagón de la red PSTN: se avecina un cambio obligatorio

Perspectivas

¿Sobrevivirá tu marca o tendrá éxito?

Perspectivas

Dando forma al futuro: los retos financieros del sector sanitario privado y farmacéutico de cara a 2026

Perspectivas

Lo que deben hacer ahora las empresas con más de 10 empleados

Perspectivas

Tiempos turbulentos: la escalada de tensión en Oriente Medio y lo que las empresas británicas deben tener en cuenta ahora

Perspectivas

Vilmers UAB elige a ERA Group para optimizar sus costes

Perspectivas

4.º trimestre de 2025: Noticias sobre consumibles y embalajes para la industria manufacturera

Perspectivas

Se dispara la demanda de servicios profesionales para reducir costes

Perspectivas

Lo que soy…

Perspectivas

Perspectivas del mercado de envíos urgentes y paquetería para 2025

Perspectivas

5 consejos para optimizar los costes en el sector turístico y garantizar la cadena de suministro

Perspectivas

La agenda de... Sara Monte e Freitas

Perspectivas

Qué supone para tu empresa el fin de los descuentos del programa EA de Microsoft

Perspectivas

Nuevo socio en ERA Group en Portugal

Perspectivas

Objetivo 2030: Impulsar la transformación sostenible de tu empresa

Perspectivas

El tres fue el número que falló

Perspectivas

Ciberseguridad: el pilar estratégico para la sostenibilidad empresarial

Perspectivas

En la carretera: Boletín de Q3 Freight

Perspectivas

La suite de compras de ERA Group combina la inteligencia humana y la inteligencia artificial para reinventar el proceso de solicitud de propuestas

Perspectivas

El Grupo ERA presenta cuatro medidas para que las empresas aumenten su eficiencia y resiliencia mediante la optimización del consumo de agua

Perspectivas

Tercer trimestre de 2024: Noticias sobre el sector manufacturero, los consumibles y el embalaje

Perspectivas

Cuatro áreas de gasto que las empresas del sector de la hostelería y el ocio deberían revisar ahora mismo

Perspectivas

Damos la bienvenida a nuestro nuevo socio, Johan de Bie

Perspectivas

Resiliencia financiera: cómo pueden prepararse los productores alimentarios de California para 2026

Perspectivas

¿Te estás preparando para reabrir tu local comercial? Recomendaciones para una desinfección adecuada

Perspectivas

El equipo de ERA se ha reforzado con la incorporación de un nuevo socio

Perspectivas

Mantener el lado humano en la era de la IA

Perspectivas

¿Le está costando dinero a tu empresa conformarse con «lo suficiente»?

Perspectivas

El Grupo ERA señala tres estrategias para la recuperación del turismo

Perspectivas

3.º trimestre de 2025: Noticias sobre fabricación, consumibles y embalaje

Perspectivas

Stavanger Steel firma un acuerdo con ERA para la optimización de costes

Perspectivas

La gestión del cambio: clave para cumplir las expectativas

Perspectivas

Patrocinio del III Congreso de Directivos Portugueses

Perspectivas

Cómo afrontar las fluctuaciones arancelarias: información actualizada para los transportistas de ANZ

Perspectivas

Empresas a prueba de balas

Perspectivas

Damos la bienvenida a nuestro nuevo socio, Wouter Blom

Perspectivas

La escasez de materias primas acelera la transformación del sector del transporte

Perspectivas

Seminario web: Tu arma secreta para ahorrar dinero en el sector hotelero

Perspectivas

Errar es humano, pero no solo eso

Perspectivas

ERA se asocia con Hapro Electronics AS

Perspectivas

La ciberseguridad en el panorama digital

Perspectivas

¿Está preparada tu empresa mediana para una recesión económica?

Perspectivas

4 técnicas para rediseñar una estrategia de compras y garantizar la continuidad del negocio

Perspectivas

El Grupo ERA refuerza su presencia a nivel nacional con la incorporación de tres nuevos socios

Perspectivas

Damos la bienvenida a nuestro nuevo socio, John Smith

Perspectivas

Lo que tu cuenta de resultados no te dice: cómo descubrir oportunidades de ahorro gracias al análisis de costes

Perspectivas

Q1-2025: Noticias sobre consumibles y embalajes para la industria manufacturera

Perspectivas

Nunca le preguntes a un peluquero si necesitas un corte de pelo

Perspectivas

Cómo la crisis de los contenedores y el transporte marítimo podría dejarnos sin Navidad

Perspectivas

Cambios en las licencias de Microsoft en 2025: por qué las empresas estadounidenses deberían actuar ahora

Perspectivas

SSG elige a ERA Group como socio de confianza para la optimización de costes y la mejora de procesos.

Perspectivas

Medidas medioambientales «en la bolsa»

Perspectivas

ERA se une a la campaña solidaria de la Red de Emergencia Alimentaria

Perspectivas

Hofseth International AS elige a ERA Group

Perspectivas

¿Cómo se pueden optimizar los costes sanitarios sin poner en peligro la salud de los pacientes?

Perspectivas

Aprovecha al máximo tu tiempo: el tiempo es importante

Perspectivas

2.º trimestre de 2025: Noticias sobre fabricación, consumibles y embalaje

Perspectivas

Cinco señales de alerta que indican que tu empresa se está estancando

Perspectivas

El Grupo ERA consolida su presencia en Cataluña con la incorporación de tres nuevos socios

Perspectivas

Detrás de las cámaras: actividades destacadas del mes

Perspectivas

Las cancelaciones de pedidos encabezan la lista de dificultades a las que se enfrentan los emprendedores

Perspectivas

Entrevista con nuestro nuevo socio, Ronald Batenburg

Perspectivas

El Grupo ERA patrocina los Premios Castilla y León Económica al Mejor Ejecutivo

Perspectivas

Los 5 pasos que pueden ayudarte a acelerar la recuperación de tu empresa

Perspectivas

Sector agroalimentario: tres ámbitos en los que la inteligencia artificial impulsa la sostenibilidad del sector

Perspectivas

NORBIT ASA inicia una colaboración con ERA Group.

Perspectivas

Expense Reduction Analysts cambia su nombre a ERA Group y anuncia una nueva dirección

Perspectivas

El Grupo ERA en el aniversario de la AER (Asociación Española de Minoristas)

Obtén información que impulse tu negocio

¡Gracias! ¡Hemos recibido tu solicitud!
¡Vaya! Ha surgido un problema al enviar el formulario.