Inga träffar.
Inga träffar.
Alla inlägg

NIS2: risker och möjligheter för företag

författare

Fabio Borri
Inga träffar.

Innehåll

Det här är den URL som ska kopieras

Introduction and regulatory references


NIS is an acronym that stands for "Network and Information Security".

With this acronym; the European Community intended to denote the legislative effort to define a standardised approach to cyber security in all EU Member States.

In 2018; the first European regulation called NIS1 (EU Directive 2016/1148) was passed; transposed at national level by Legislative Decree 65 of 18/05/2018.

The NIS Decree also provided for the adoption of a 'national cyber security strategy' by establishing the Italian CSIRT (Computer Security Incident Response Team) with technical tasks related to the prevention; response and monitoring of cyber incidents; in collaboration with European CSIRTs.

NIS1 was subsequently superseded by NIS2 (EU Directive 2022/2555); transposed at national level by Legislative Decree 138 of 4 September 2024.

NIS 2 aims to overcome the limitations of NIS 1; which left too much discretion to Member States during transposition; resulting in a failure to achieve the objective of harmonisation; and also excluded certain categories of entities that should have been regulated because of their importance to the European market.

Furthermore; NIS2 was introduced to respond to the increase in the rate of digitisation that has taken place in all Member States and has been accelerated by the pandemic; which has expanded the surface area for cyber attacks without a corresponding increase in security systems.

Finally; another objective of NIS2 is to oblige operators of essential and important services and digital service providers to adopt adequate security measures and to report incidents promptly to the competent authorities and users of their services.

The new directive has been aligned with other specific European sectoral regulations; including:

- the Directive on Digital Operational Resilience for the Financial Sector (DORA). This is the Regulation approved on 10/11/2022 with the aim of increasing security measures in favour of the resilience and cybersecurity of the financial sector through the implementation of a series of mandatory security measures that guarantee the integrity of information and the cybersecurity of services;

- the Critical Entity Resilience Directive (CER); aimed at ensuring legal clarity and consistency between the various directives.

The companies concerned have been divided into:

  • Essential entities (energy; transport; health; water supply; public administration; finance; space; digital infrastructure)
  • Important entities (research; chemicals; food; industrial production; digital providers; postal services; waste)
  • Public bodies: Central government (constitutional and constitutionally relevant bodies; the Prime Minister's Office and ministries; tax agencies; independent administrative authorities) | Regional government (regions and autonomous provinces) | Local government (metropolitan cities; municipalities with > 100;000 inhabitants; regional capitals; local health authorities) | Other public entities (economic regulatory bodies; economic service providers; associations; welfare; recreational and cultural service providers; research bodies and institutions; experimental zooprophylactic institutes) | Other types of entities (entities providing local public transport services; educational institutions carrying out research activities; entities carrying out activities of cultural interest; in-house companies; investee companies and publicly controlled companies)
  • Suppliers: organizations that provide critical services to entities affected by NIS2 must strengthen their digital security; even if they are explicitly included in the mandatory sectors.

Content of NIS2


The general obligations inherent in the content of NIS2 can be summarised on the basis of four main pillars:

Governance: Management must approve the risk management measures adopted by the organization and assess their effectiveness over time: follow regular training on cybersecurity issues and offer similar training to employees.

Risk management: the organization must assess security and network risks and adopt appropriate and proportionate technical; operational and organisational measures to prevent or minimise the impact of incidents on the recipients of its services.

Business continuity: the organization must adopt solutions to ensure business continuity (e.g. backups; disaster recovery plan and crisis management procedure); aimed at minimising the impact of any interruptions to the services provided.

Supply chain: the company must assess the vulnerabilities of each direct supplier and the overall quality of its suppliers' products and cybersecurity practices. The assessment will cover ICT suppliers and other critical suppliers that could cause disruption to the service for which the organization has been included in the NIS2 perimeter.

Companies will therefore be required to be able to measure and report on:

  • Risk analysis and information system security policies
  • Incident management procedures
  • Business continuity solutions (backup and disaster recovery) and crisis management and communication procedures
  • Supply chain security policies (suppliers and service providers)
  • Security in the acquisition; development; maintenance and management of information system and network vulnerabilities

NIS2 Timeline


Companies and public administrations will have to carry out an assessment to understand whether or not they are subject to the obligations of the NIS2 Directive.

From 1 December 2024 to 28 February 2025; companies should have authenticated themselves on the ACN (National Cybersecurity Agency) Portal using their SPID credentials. During this period; users designated as contact points for each company should have completed a declaration via the NIS/Registration Service.

In particular; companies are required to:

  • Indicate whether the entity is part of a group of companies and provide the tax code of the parent company; if applicable.
  • List the related companies and provide their tax codes.
  • List the ATECO codes describing the entity's activity.
  • Indicate the relevant European Union sectoral regulations.
  • Provide turnover; balance sheet and number of employees figures to determine the category of the company.
  • List the types of entities to which the company belongs.


By 17 January 2025; operators of top-level domain name registries; providers of domain name system and domain name registration services; cloud computing; data centers; content delivery network providers; managed service providers; managed security service providers; as well as online marketplace providers; online search engine providers and social networking service platform providers should have registered on the platform.

By 31 March 2025; the ACN compiled a list of essential and important entities based on the registrations received through the platform.

Between 1 April 2025 and 15 April 2025; the ACN notified the entities concerned whether they had been included in the list of essential or important entities.

By 15 April 2025; the entities that received the notification were required to appoint; by means of a specific act; an entity responsible for fulfilling the obligations of the decree.

After that; the entities affected by the Directive will have to comply with further requirements:

  • by 1 January 2026; incident reporting obligation
  • by 1 October 2026; obligations regarding administrative bodies and security measures must be fulfilled


Each year; the ACN will update the list of entities involved. Companies and public administrations will have the opportunity to register each year; between January and February; if they consider themselves to be among the entities concerned.

Risks for companies but also opportunities


Following the entry into force of NIS2 and the identification of the operators involved; the competent authorities may carry out surveillance and spot checks to verify their compliance with the Directive. In the event of non-compliance; penalties will be applied to the companies involved.

The penalties are very severe: for large companies; up to €10 million or 2% of global turnover; for medium-sized enterprises; up to €7 million or 1.4% of global turnover.

Although compliance with the regulations requires a clear effort and investment on the part of companies; it must also be recognized that the regulations themselves seek to provide a substantial remedy to the problem of cyber attacks; to which Italian companies are still very susceptible and which they often tend to cover up for image reasons. In economic terms; the estimated average damage for each individual cyber attack is more than €2 million; regardless of the company's turnover.

How ERA can help with NIS2 compliance management


Despite all of the above; which might suggest that companies are extremely interested and involved in cyber security issues; it is not uncommon; especially among small SMEs; to find companies that have done little or nothing about these issues and are currently unable to define their position in terms of the risks to which they are exposed; both from a technical point of view and in terms of compliance with the various existing regulations.

Some companies address the issue of cybersecurity through insurance coverage. However; insurance companies are often reluctant to offer this type of protection to companies that have never taken concrete action in the cyber sphere. This is because there is no reliable method for accurately estimating the damage caused by a cyber attack. As a result; 'NIS2 packages' focus on cyber risk assessment services; but leave it up to companies to take the necessary measures to address any gaps. ERA can offer a more comprehensive service; relying on a network of highly qualified suppliers at very competitive commercial terms.

In detail; ERA's support consists of:

  • An assessment of the company's organisational and technical structure; with the aid of self-assessment questionnaires using predefined indicators;
  • Awareness-raising and training courses; with basic courses for all staff and advanced modules for top and middle management; in line with NIS2 guidelines;
  • Specific and highly qualified tests on vulnerability analysis; phishing treatment and ransomware risk assessment;
  • Support from dedicated consultants during the remediation phase following the assessment;
  • Specialised support from dedicated consultants to guide strategic decisions in the field of cybersecurity.


Our solution includes analysis of compliance with NIS2 regulations; which is certainly the most urgent concern; but can also accompany the customer in the project management of the remediation phase; i.e. the phase in which the customer must remedy the various 'flaws' identified in the diagnosis process; and is the phase in which the difficulties of some companies are most apparent; both in terms of internal skills and the availability of time and resources.

Relaterade artiklar

Du kanske också gillar

Insikter

Kostnadshanteringsbarometern 2025: Utgåva för detalj- och grossisthandeln

Insikter

SORP 2026: Vad välgörenhetsorganisationer behöver veta och hur de ska förbereda sig

Insikter

Övervakningsluckan: När kostnadsoptimering redan är ”täckt”

Insikter

De dolda kostnaderna vid fördelning av serviceavgifter: Vad ekonomichefer behöver känna till i egenskap av hyresgäst

Insikter

2025 i korthet: Kostnader, komplexitet och vägen mot 2026

Insikter

Marknadsinformation 2026.1

Insikter

ERA Group lanseras i Indien!

Insikter

Bränslesökare: Verktyg för öppenhet eller vinstgenerator?

Insikter

Hur man bygger en robust digital kärna

Insikter

AI inom inköp: Omvandla finansiell intelligens till en strukturell fördel

Insikter

ERA Group utnämner Marcel Lal till ny global utvecklingschef

Insikter

Kostnadsanalys i praktiken – Hälso- och sjukvård

Insikter

Vinstpressen efter toppen: Prioriteringar för första kvartalet för VD:ar och ekonomichefer inom detaljhandeln

Insikter

Mer än bara motståndskraft: En handbok för tillväxt i leveranskedjan 2026

Insikter

Tillverkningskostnader och transportkostnader: Tillverkning i en värld präglad av tullar och höga energipriser

Insikter

Den motståndskraftiga (men fortfarande osäkra) världsekonomin

Insikter

Varför ledare inom ideella organisationer måste åstadkomma mer med mindre resurser – och bevisa det

Insikter

Från avtal till konkurrensfördel: Hur ledare omvandlar leverantörsavtal till drivkrafter för prestanda

Insikter

Mary Kennedy Thompson, VD för BNI Global, ansluter sig till ERA Group som styrelserådgivare

Insikter

5 prioriteringar inom upphandling för 2026: Från kostnadsöversikt till kostnadsanalys

Insikter

Skottlands hotell- och restaurangbransch i knipa: När höjda priser gör överlevnaden till den verkliga utmaningen

Insikter

Att se på tekniken med nya ögon: Att blomstra när förändringen aldrig står still

Insikter

Spänningarna i Mellanöstern och deras inverkan på företagens kostnader

Insikter

Chocken med arbetsgivaravgifterna: Varför rekryteringen går trögt – och hur man kan motverka det

Insikter

Upphandlingens strategiska betydelse

Insikter

Att bygga en starkare framtid för den brittiska videospelbranschen

Insikter

Konflikten i Iran påverkar de fasta el- och gaspriserna

Insikter

Barometer för kostnadshantering 2026

Insikter

Den dagen då även elen började visa en skylt med texten ”slutsåld”

Insikter

ERA Group pekar ut fyra centrala utmaningar som tvingar företag inom tjänstesektorn att agera snabbt

Insikter

Betalningsuppskov i svåra tider

Insikter

Marknadsinformation 2025.4

Insikter

Avstängning av det fasta nätet: En oundviklig förändring väntar

Insikter

Kommer ditt varumärke att överleva, eller kommer det att lyckas?

Insikter

Att forma framtiden: De ekonomiska utmaningarna för den privata hälso- och sjukvårdssektorn och läkemedelsbranschen inför 2026

Insikter

Vad företag med över 10 anställda måste göra nu

Insikter

Oroliga tider: Eskaleringen i Mellanöstern och vad brittiska företag bör tänka på just nu

Insikter

Vilmers UAB väljer ERA Group för kostnadsoptimering

Insikter

Q4 2025: Nyheter om tillverkning av förbrukningsvaror och förpackningar

Insikter

Efterfrågan på professionella tjänster för att sänka kostnaderna skjuter i höjden

Insikter

Vad jag är…

Insikter

Utsikterna för express- och paketmarknaden 2025

Insikter

5 tips för att optimera kostnaderna inom turistbranschen och säkra leveranskedjan

Insikter

Dagordningen för... Sara Monte e Freitas

Insikter

Vad upphörandet av Microsofts EA-rabatter innebär för ditt företag

Insikter

Ny partner hos ERA Group i Portugal

Insikter

Mål 2030: Driv på den hållbara omställningen av ditt företag

Insikter

Det var siffran tre som blev fel

Insikter

Cybersäkerhet: den strategiska pelaren för företagens hållbarhet

Insikter

På resande fot: Nyhetsbrev om godstransporter – tredje kvartalet

Insikter

ERA Groups upphandlingsplattform kombinerar mänsklig intelligens och AI för att förnya anbudsprocessen

Insikter

ERA Group presenterar fyra åtgärder som företag kan vidta för att öka effektiviteten och motståndskraften genom vattenoptimering

Insikter

Q3 2024: Tillverkningsindustrin; nyheter om förbrukningsvaror och förpackningar

Insikter

Fyra utgiftsområden som företag inom hotell- och fritidsbranschen bör se över just nu

Insikter

Välkommen, vår nya partner Johan de Bie

Insikter

Finansiell motståndskraft: Hur livsmedelsproducenter i Kalifornien kan förbereda sig inför 2026

Insikter

Förbereder du dig för att öppna din verksamhet igen? Rekommendationer för korrekt desinfektion

Insikter

ERA-teamet har förstärkts med ankomsten av en ny partner

Insikter

Att behålla det mänskliga i AI-åldern

Insikter

Kostar ”bra nog” ditt företag pengar?

Insikter

ERA Group pekar ut tre strategier för turismens återhämtning

Insikter

Q3 2025: Nyheter om tillverkning, förbrukningsvaror och förpackningar

Insikter

Stavanger Steel tecknar avtal med ERA om kostnadsoptimering

Insikter

Förändringshantering – nyckeln till att uppfylla förväntningarna

Insikter

Sponsring av den tredje portugisiska chefsmässan

Insikter

Att navigera i tullturbulensen: En uppdatering för avsändare inom ANZ

Insikter

Bulletproof-företag

Insikter

Välkommen, vår nya partner Wouter Blom

Insikter

Bristen på råvaror påskyndar omställningen inom transportsektorn

Insikter

Webinar: Ditt hemliga vapen för att spara pengar inom hotellbranschen

Insikter

Att fela är mänskligt, men inte bara det

Insikter

ERA ingår samarbete med Hapro Electronics AS

Insikter

Cybersäkerhet i en digital värld

Insikter

Är ditt medelstora företag förberett för en konjunkturnedgång?

Insikter

4 metoder för att omarbeta en inköpsstrategi och säkerställa verksamhetens kontinuitet

Insikter

ERA Group stärker sin nationella närvaro genom att ta in tre nya partners

Insikter

Välkommen, vår nya partner John Smith

Insikter

Vad resultaträkningen inte avslöjar: Hitta besparingsmöjligheter med hjälp av kostnadsanalys

Insikter

Q1 2025: Nyheter om tillverkning av förbrukningsvaror och förpackningar

Insikter

Fråga aldrig en frisör om du behöver klippa dig

Insikter

Hur container- och sjöfartskrisen kan göra att vi går miste om julen

Insikter

Ändringar i Microsofts licensvillkor 2025: Varför amerikanska företag bör agera redan nu

Insikter

SSG väljer ERA Group som en pålitlig partner för kostnadsoptimering och processförbättring.

Insikter

Miljöåtgärder – ”i hamn”

Insikter

ERA ansluter sig till solidaritetskampanjen Food Emergency Network

Insikter

Hofseth International AS väljer ERA Group

Insikter

Hur kan sjukvårdskostnaderna optimeras utan att patienternas hälsa äventyras?

Insikter

Utnyttja din tid på bästa sätt: tiden är viktig

Insikter

Q2 2025: Nyheter om tillverkning, förbrukningsvaror och förpackningar

Insikter

Fem varningssignaler på att ditt företag har nått en platå

Insikter

ERA Group stärker sin närvaro i Katalonien genom att välkomna tre nya samarbetspartner

Insikter

En inblick i arbetet: Månadens viktigaste aktiviteter

Insikter

Avbokningar av beställningar toppar listan över de svårigheter som företagare ställs inför

Insikter

Intervju med vår nya partner Ronald Batenburg

Insikter

ERA Group är sponsor för utmärkelsen ”Castilla y León Económica” för bästa företagsledare

Insikter

De 5 stegen som kan hjälpa dig att påskynda ditt företags återhämtning

Insikter

Livsmedelssektorn: Tre områden där artificiell intelligens främjar hållbarheten inom branschen

Insikter

NORBIT ASA inleder ett samarbete med ERA Group.

Insikter

Expense Reduction Analysts byter namn till ERA Group och presenterar ny ledning

Insikter

ERA Group vid AER:s (Spanska detaljhandelsförbundet) jubileum

Få insikter som driver din verksamhet framåt

Tack! Vi har mottagit din anmälan!
Oj! Det uppstod ett fel när formuläret skickades in.