Nenašli sa žiadne položky.
Nenašli sa žiadne položky.
Všetky príspevky

NIS2; riziká a príležitosti pre podniky

autori

Fabio Borri
Nenašli sa žiadne položky.

Obsah

Toto bude URL adresa, ktorú treba skopírovať

Introduction and regulatory references


NIS is an acronym that stands for "Network and Information Security".

With this acronym; the European Community intended to denote the legislative effort to define a standardised approach to cyber security in all EU Member States.

In 2018; the first European regulation called NIS1 (EU Directive 2016/1148) was passed; transposed at national level by Legislative Decree 65 of 18/05/2018.

The NIS Decree also provided for the adoption of a 'national cyber security strategy' by establishing the Italian CSIRT (Computer Security Incident Response Team) with technical tasks related to the prevention; response and monitoring of cyber incidents; in collaboration with European CSIRTs.

NIS1 was subsequently superseded by NIS2 (EU Directive 2022/2555); transposed at national level by Legislative Decree 138 of 4 September 2024.

NIS 2 aims to overcome the limitations of NIS 1; which left too much discretion to Member States during transposition; resulting in a failure to achieve the objective of harmonisation; and also excluded certain categories of entities that should have been regulated because of their importance to the European market.

Furthermore; NIS2 was introduced to respond to the increase in the rate of digitisation that has taken place in all Member States and has been accelerated by the pandemic; which has expanded the surface area for cyber attacks without a corresponding increase in security systems.

Finally; another objective of NIS2 is to oblige operators of essential and important services and digital service providers to adopt adequate security measures and to report incidents promptly to the competent authorities and users of their services.

The new directive has been aligned with other specific European sectoral regulations; including:

- the Directive on Digital Operational Resilience for the Financial Sector (DORA). This is the Regulation approved on 10/11/2022 with the aim of increasing security measures in favour of the resilience and cybersecurity of the financial sector through the implementation of a series of mandatory security measures that guarantee the integrity of information and the cybersecurity of services;

- the Critical Entity Resilience Directive (CER); aimed at ensuring legal clarity and consistency between the various directives.

The companies concerned have been divided into:

  • Essential entities (energy; transport; health; water supply; public administration; finance; space; digital infrastructure)
  • Important entities (research; chemicals; food; industrial production; digital providers; postal services; waste)
  • Public bodies: Central government (constitutional and constitutionally relevant bodies; the Prime Minister's Office and ministries; tax agencies; independent administrative authorities) | Regional government (regions and autonomous provinces) | Local government (metropolitan cities; municipalities with > 100;000 inhabitants; regional capitals; local health authorities) | Other public entities (economic regulatory bodies; economic service providers; associations; welfare; recreational and cultural service providers; research bodies and institutions; experimental zooprophylactic institutes) | Other types of entities (entities providing local public transport services; educational institutions carrying out research activities; entities carrying out activities of cultural interest; in-house companies; investee companies and publicly controlled companies)
  • Suppliers: organizations that provide critical services to entities affected by NIS2 must strengthen their digital security; even if they are explicitly included in the mandatory sectors.

Content of NIS2


The general obligations inherent in the content of NIS2 can be summarised on the basis of four main pillars:

Governance: Management must approve the risk management measures adopted by the organization and assess their effectiveness over time: follow regular training on cybersecurity issues and offer similar training to employees.

Risk management: the organization must assess security and network risks and adopt appropriate and proportionate technical; operational and organisational measures to prevent or minimise the impact of incidents on the recipients of its services.

Business continuity: the organization must adopt solutions to ensure business continuity (e.g. backups; disaster recovery plan and crisis management procedure); aimed at minimising the impact of any interruptions to the services provided.

Supply chain: the company must assess the vulnerabilities of each direct supplier and the overall quality of its suppliers' products and cybersecurity practices. The assessment will cover ICT suppliers and other critical suppliers that could cause disruption to the service for which the organization has been included in the NIS2 perimeter.

Companies will therefore be required to be able to measure and report on:

  • Risk analysis and information system security policies
  • Incident management procedures
  • Business continuity solutions (backup and disaster recovery) and crisis management and communication procedures
  • Supply chain security policies (suppliers and service providers)
  • Security in the acquisition; development; maintenance and management of information system and network vulnerabilities

NIS2 Timeline


Companies and public administrations will have to carry out an assessment to understand whether or not they are subject to the obligations of the NIS2 Directive.

From 1 December 2024 to 28 February 2025; companies should have authenticated themselves on the ACN (National Cybersecurity Agency) Portal using their SPID credentials. During this period; users designated as contact points for each company should have completed a declaration via the NIS/Registration Service.

In particular; companies are required to:

  • Indicate whether the entity is part of a group of companies and provide the tax code of the parent company; if applicable.
  • List the related companies and provide their tax codes.
  • List the ATECO codes describing the entity's activity.
  • Indicate the relevant European Union sectoral regulations.
  • Provide turnover; balance sheet and number of employees figures to determine the category of the company.
  • List the types of entities to which the company belongs.


By 17 January 2025; operators of top-level domain name registries; providers of domain name system and domain name registration services; cloud computing; data centers; content delivery network providers; managed service providers; managed security service providers; as well as online marketplace providers; online search engine providers and social networking service platform providers should have registered on the platform.

By 31 March 2025; the ACN compiled a list of essential and important entities based on the registrations received through the platform.

Between 1 April 2025 and 15 April 2025; the ACN notified the entities concerned whether they had been included in the list of essential or important entities.

By 15 April 2025; the entities that received the notification were required to appoint; by means of a specific act; an entity responsible for fulfilling the obligations of the decree.

After that; the entities affected by the Directive will have to comply with further requirements:

  • by 1 January 2026; incident reporting obligation
  • by 1 October 2026; obligations regarding administrative bodies and security measures must be fulfilled


Each year; the ACN will update the list of entities involved. Companies and public administrations will have the opportunity to register each year; between January and February; if they consider themselves to be among the entities concerned.

Risks for companies but also opportunities


Following the entry into force of NIS2 and the identification of the operators involved; the competent authorities may carry out surveillance and spot checks to verify their compliance with the Directive. In the event of non-compliance; penalties will be applied to the companies involved.

The penalties are very severe: for large companies; up to €10 million or 2% of global turnover; for medium-sized enterprises; up to €7 million or 1.4% of global turnover.

Although compliance with the regulations requires a clear effort and investment on the part of companies; it must also be recognized that the regulations themselves seek to provide a substantial remedy to the problem of cyber attacks; to which Italian companies are still very susceptible and which they often tend to cover up for image reasons. In economic terms; the estimated average damage for each individual cyber attack is more than €2 million; regardless of the company's turnover.

How ERA can help with NIS2 compliance management


Despite all of the above; which might suggest that companies are extremely interested and involved in cyber security issues; it is not uncommon; especially among small SMEs; to find companies that have done little or nothing about these issues and are currently unable to define their position in terms of the risks to which they are exposed; both from a technical point of view and in terms of compliance with the various existing regulations.

Some companies address the issue of cybersecurity through insurance coverage. However; insurance companies are often reluctant to offer this type of protection to companies that have never taken concrete action in the cyber sphere. This is because there is no reliable method for accurately estimating the damage caused by a cyber attack. As a result; 'NIS2 packages' focus on cyber risk assessment services; but leave it up to companies to take the necessary measures to address any gaps. ERA can offer a more comprehensive service; relying on a network of highly qualified suppliers at very competitive commercial terms.

In detail; ERA's support consists of:

  • An assessment of the company's organisational and technical structure; with the aid of self-assessment questionnaires using predefined indicators;
  • Awareness-raising and training courses; with basic courses for all staff and advanced modules for top and middle management; in line with NIS2 guidelines;
  • Specific and highly qualified tests on vulnerability analysis; phishing treatment and ransomware risk assessment;
  • Support from dedicated consultants during the remediation phase following the assessment;
  • Specialised support from dedicated consultants to guide strategic decisions in the field of cybersecurity.


Our solution includes analysis of compliance with NIS2 regulations; which is certainly the most urgent concern; but can also accompany the customer in the project management of the remediation phase; i.e. the phase in which the customer must remedy the various 'flaws' identified in the diagnosis process; and is the phase in which the difficulties of some companies are most apparent; both in terms of internal skills and the availability of time and resources.

Súvisiace články

Mohlo by sa vám páčiť aj

Postrehy

Barometer riadenia nákladov 2025: vydanie pre maloobchod a veľkoobchod

Postrehy

SORP 2026: Čo by mali charitatívne organizácie vedieť a ako sa pripraviť

Postrehy

Medzera v dohľade: Keď je optimalizácia nákladov „už pokryté“

Postrehy

Skryté náklady pri rozdeľovaní poplatkov za služby: Čo by mali vedieť finanční riaditelia v pozícii nájomcu

Postrehy

Prehľad roku 2025: Náklady, zložitosť a cesta k roku 2026

Postrehy

Trhové informácie 2026.1

Postrehy

Skupina ERA vstupuje na indický trh!

Postrehy

Vyhľadávač paliva: Nástroj na zabezpečenie transparentnosti alebo prostriedok na zvýšenie zisku?

Postrehy

Ako vybudovať odolné digitálne jadro

Postrehy

Umelá inteligencia v oblasti nákupu: Premena finančnej inteligencie na štrukturálnu výhodu

Postrehy

Skupina ERA vymenovala Marcela Lala za nového globálneho riaditeľa pre rozvoj

Postrehy

Využitie analýzy nákladov v praxi – zdravotníctvo

Postrehy

Tlak na zisky po prekonaní vrcholu: Priority na 1. štvrťrok pre generálnych riaditeľov a finančných riaditeľov v maloobchode

Postrehy

Viac ako len odolnosť: Príručka pre rast dodávateľského reťazca v roku 2026

Postrehy

Výrobné náklady, náklady na prepravu: Výroba v prostredí ovplyvnenom clami a vysokými cenami energie

Postrehy

Odolné (ale stále neisté) svetové hospodárstvo

Postrehy

Prečo musia vedúci pracovníci neziskových organizácií dosahovať viac s menej prostriedkami – a dokázať to

Postrehy

Od zmluvy k výhodám: Ako lídri premieňajú zmluvy s dodávateľmi na hnacie sily výkonu

Postrehy

Generálna riaditeľka spoločnosti BNI Global, Mary Kennedy Thompsonová, nastupuje do spoločnosti ERA Group ako poradkyňa predstavenstva

Postrehy

5 priorít v oblasti obstarávania na rok 2026: Od prehľadu o nákladoch k analýze nákladov

Postrehy

Tlak na škótsky pohostinský sektor: Keď vyššie ceny znamenajú, že prežitie je skutočnou výzvou

Postrehy

Nové pohľady na technológie: Ako uspieť v čase neustálych zmien

Postrehy

Napätie na Blízkom východe a jeho vplyv na podnikateľské náklady

Postrehy

Šok z odvodov zamestnávateľa: Prečo sa nábor zamestnancov spomaľuje – a ako to vykompenzovať

Postrehy

Strategický potenciál obstarávania

Postrehy

Budovanie lepšej budúcnosti pre britský herný priemysel

Postrehy

Konflikt v Iráne má vplyv na pevné tarify za elektrinu a plyn

Postrehy

Barometer riadenia nákladov 2026

Postrehy

V ten deň sa aj na elektrickom stĺpe objavil nápis „vypredané“

Postrehy

Skupina ERA identifikuje štyri kľúčové výzvy, ktoré nútia spoločnosti poskytujúce profesionálne služby konať bezodkladne

Postrehy

Dohody o odklade splatnosti v náročných daňových časoch

Postrehy

Trhové informácie 2025.4

Postrehy

Vypnutie verejnej telefónnej siete (PSTN): Čaká nás povinná zmena

Postrehy

Prežije vaša značka, alebo bude úspešná?

Postrehy

Tvorba budúcnosti: Finančné výzvy v oblasti súkromného zdravotníctva a farmaceutického priemyslu do roku 2026

Postrehy

Čo musia teraz urobiť firmy s viac ako 10 zamestnancami

Postrehy

Búrlivé časy: Eskalácia napätia na Blízkom východe a čo by mali britské firmy teraz zvážiť

Postrehy

Spoločnosť Vilmers UAB si vybrala skupinu ERA na optimalizáciu nákladov

Postrehy

4. štvrťrok 2025: Novinky z oblasti spotrebného materiálu a obalov pre výrobný priemysel

Postrehy

Dopyt po odborných službách zameraných na znižovanie nákladov prudko stúpa

Postrehy

Čo som…

Postrehy

Výhľad na trh expresných zásielok a balíkov do roku 2025

Postrehy

5 tipov na optimalizáciu nákladov v odvetví cestovného ruchu a zabezpečenie dodávateľského reťazca

Postrehy

Program... Sary Monte e Freitasovej

Postrehy

Čo znamená koniec zliav v rámci programu EA od spoločnosti Microsoft pre vašu firmu

Postrehy

Nový partner v spoločnosti ERA Group v Portugalsku

Postrehy

Cieľ 2030: Podporujte udržateľnú transformáciu vašej spoločnosti

Postrehy

Trojka bola to číslo, ktoré pokazilo všetko

Postrehy

Kyberbezpečnosť: strategický pilier udržateľnosti podnikania

Postrehy

Na ceste: Informácie o nákladnej preprave za 3. štvrťrok

Postrehy

Súbor nástrojov ERA Group pre obstarávanie spája ľudskú inteligenciu a umelú inteligenciu s cieľom premeniť proces výberového konania

Postrehy

Skupina ERA predstavila štyri opatrenia, ktoré môžu podniky využiť na zvýšenie efektívnosti a odolnosti prostredníctvom optimalizácie spotreby vody

Postrehy

3. štvrťrok 2024: Správy z oblasti výroby, spotrebného tovaru a obalov

Postrehy

Štyri oblasti výdavkov, ktoré by mali podniky v oblasti pohostinstva a voľného času práve teraz prehodnotiť

Postrehy

Vitajte, nový partner Johan de Bie

Postrehy

Finančná odolnosť: Ako sa môžu kalifornskí výrobcovia potravín pripraviť na rok 2026

Postrehy

Chystáte sa opäť otvoriť svoje prevádzkové priestory? Odporúčania pre správnu dezinfekciu

Postrehy

Tím ERA sa posilnil príchodom nového partnera

Postrehy

Zachovať ľudský rozmer v ére umelej inteligencie

Postrehy

Stojí vašu firmu „dostatočná kvalita“ peniaze?

Postrehy

Skupina ERA poukazuje na tri stratégie na oživenie cestovného ruchu

Postrehy

3. štvrťrok 2025: Správy z oblasti výroby, spotrebného tovaru a balenia

Postrehy

Spoločnosť Stavanger Steel podpísala s ERA dohodu o optimalizácii nákladov

Postrehy

Riadenie zmien; kľúč k splneniu očakávaní

Postrehy

Sponzorstvo 3. portugalského kongresu manažérov

Postrehy

Ako sa vyrovnať s výkyvmi v clách: Aktuálne informácie pre odosielateľov v regióne ANZ

Postrehy

Spoločnosti odolné voči krízam

Postrehy

Vitajte, nový partner Wouter Blom

Postrehy

Nedostatok surovín urýchľuje transformáciu v doprave

Postrehy

Webinár: Vaša tajná zbraň na úsporu peňazí v hotelierstve

Postrehy

Chybiť je ľudské, ale nielen to

Postrehy

Spoločnosť ERA uzatvára partnerstvo so spoločnosťou Hapro Electronics AS

Postrehy

Kybernetická bezpečnosť v digitálnom prostredí

Postrehy

Je vaša stredná firma pripravená na hospodársky pokles?

Postrehy

4 postupy na prepracovanie nákupnej stratégie a zabezpečenie kontinuity podnikania

Postrehy

Skupina ERA posilňuje svoju prítomnosť na domácom trhu o troch nových partnerov

Postrehy

Vitajte, nový partner John Smith

Postrehy

Čo vám výkaz ziskov a strát neprezradí: Ako odhaliť úspory vďaka analýze nákladov

Postrehy

1. štvrťrok 2025: Novinky z oblasti spotrebného materiálu a obalov pre výrobný priemysel

Postrehy

Nikdy sa nepýtaj holiča, či potrebuješ ostrihať

Postrehy

Ako by nás kríza v oblasti kontajnerovej a námornej dopravy mohla pripraviť o Vianoce

Postrehy

Zmeny v licenčnej politike spoločnosti Microsoft v roku 2025: Prečo by mali americké firmy konať už teraz

Postrehy

Spoločnosť SSG si vybrala skupinu ERA ako dôveryhodného partnera v oblasti optimalizácie nákladov a zlepšovania procesov.

Postrehy

Opatrenia na ochranu životného prostredia „v kapse“

Postrehy

Organizácia ERA sa pripája k solidárnej kampani siete Food Emergency Network

Postrehy

Spoločnosť Hofseth International AS si vybrala skupinu ERA

Postrehy

Ako je možné optimalizovať náklady na zdravotnú starostlivosť bez toho, aby to malo negatívny vplyv na zdravie pacientov?

Postrehy

Využite svoj čas naplno: čas je dôležitý

Postrehy

2. štvrťrok 2025: Správy z oblasti výroby, spotrebného tovaru a balenia

Postrehy

Päť varovných signálov, že vaša firma stagnuje

Postrehy

Skupina ERA posilňuje svoju činnosť v Katalánsku o troch nových partnerov

Postrehy

Pohľad do zákulisia: Najdôležitejšie aktivity za uplynulý mesiac

Postrehy

Zrušenie objednávok vedie rebríček problémov, s ktorými sa podnikatelia stretávajú

Postrehy

Rozhovor s naším novým partnerom Ronaldom Batenburgom

Postrehy

Skupina ERA sponzoruje ocenenia Castilla y León Económica pre najlepších manažérov

Postrehy

5 krokov, ktoré vám pomôžu urýchliť oživenie vašej firmy

Postrehy

Agropotravinárstvo: 3 oblasti, v ktorých umelá inteligencia podporuje udržateľnosť v tomto sektore

Postrehy

Spoločnosť NORBIT ASA nadviazala spoluprácu so skupinou ERA.

Postrehy

Spoločnosť Expense Reduction Analysts mení svoj názov na ERA Group a oznamuje nové vedenie

Postrehy

Skupina ERA na oslavách výročia AER (Španielskeho združenia maloobchodníkov)

Získajte informácie, ktoré posunú vaše podnikanie vpred

Ďakujeme! Vaša žiadosť bola prijatá!
Ups! Pri odosielaní formulára došlo k chybe.