Urgent.News

What's breaking now, across thousands of outlets.

Tech

NIS2 Isn't Compliance Theatre—It's a Liability Shift

The European Union's NIS2 Directive arrives with the force of a regulation but the clarity of a fog bank. I've spent the last months helping organisations navigate it, and I can tell you: the gap between what Brussels published and what your security team must actually do is enormous. This isn't a theoretical piece. This is what I'm seeing in real boardrooms, real infrastructure, real budgets…

The European Union's NIS2 Directive brings about significant changes to cybersecurity regulations. Contrary to popular belief, NIS2 is not just an updated version of the earlier NIS Directive from 2016; it represents a fundamental shift in the responsibility for cybersecurity in Europe, extending beyond the original scope that covered only essential services such as energy, water, transport, healthcare, and finance.

What sets NIS2 apart is its inclusion of roughly 150,000 additional organisations across the EU that were previously outside the regulatory net. These include digital service providers, cloud infrastructure operators, DNS providers, managed security service providers, and critical infrastructure manufacturers, indicating that supply chains now become a significant area of accountability.

Under NIS2, organisations are required to implement supply chain risk management, which involves auditing critical suppliers, documenting their security controls with the same rigor as internal controls, and continuously monitoring them. This creates a challenging intersection between procurement and security teams, as procurement teams may resist the idea of auditing every vendor, while security teams are obligated by the regulation to do so.

Another key change is the requirement for board-level accountability. The management body, typically the board, must now have cybersecurity expertise and actively oversee cyber risk. This change shifts the responsibility from solely relying on the CISO to ensuring that the board actively participates in cyber risk management, including having at least one board member with demonstrable cybersecurity knowledge and including cybersecurity as a regular item on board meetings.

Incident reporting under NIS2 is more forensic than before. The directive defines incidents with surgical precision, requiring reporting within 24 hours of detection, not merely within a vague timeframe. This means that organisations must initiate reporting processes immediately upon detection of an incident, even if the full nature of the incident is not yet clear. This change necessitates a revised incident response process that can handle parallel tracks of immediate notification and ongoing investigation.

In addition to these changes, NIS2 mandates a more documented, auditable, and continuous risk management approach. This involves maintaining active risk assessments, tying security measures directly to identified risks, documenting why certain risks are accepted and how their exposure is monitored. Unlike the more theoretical approach under NIS, NIS2 demands tangible proof of how risk management decisions are made and documented, making the process far more rigid and defensible to regulators.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Harvest Now, Decrypt Later: Why Post-Quantum Cryptography Can't Wait

The scenario sounds like science fiction. Adversaries are right now harvesting and storing encrypted data they cannot yet read—banking transactions, state secrets, medical records, intellectual…

  • Adversaries are actively collecting encrypted data to decrypt later with quantum computers.
  • Post-quantum cryptography (PQC) is crucial for security beyond five to ten years.
  • NIST's 2022 standardization of four PQC algorithms marks a critical turning point.

XGBoost Explained: From Gradient Boosting to Weighted Quantile Sketch

XGBoost Introduction: XGBoost XGBoost is a tree-based algorithm. It is a variant of Gradient Boosting which is one of the highest-scaled versions of it.

  • XGBoost is a faster tree-based algorithm than traditional Gradient Boosting.
  • It optimizes an objective function using 2nd-order Taylor series expansion.

More from Friday 28 August →