Implementing NIS2 in your own organisation
Establish whether it applies to you, implement the ten requirements of section 30 of the German BSIG, and set the reporting chains up so that 24 hours is enough.
Three questions decide whether it applies
Every measure comes after the classification, and that turns on three questions: does your activity fall under one of the sectors in annexes 1 and 2, do you reach the thresholds for staff and turnover, and do you supply something without which an affected customer cannot work.
From the answers it follows whether you count as essential or as important. The difference concerns supervision: essential entities are audited without a trigger, important ones only once there is one. The requirements themselves are the same.
That assessment is done in a few days and has to be documented in writing. Anyone who keeps it properly has the evidence, if it comes to it, for why they are not registered.
Ten requirements, three groups
The act lists ten points. Sorted by what they mean inside an organisation, they become three pieces of work.
Knowing what can happen
Risk analysis and a security concept, security in development and operation including vulnerability management, and the effectiveness testing that evidences that the measures work.
Being prepared
Incident response, business continuity with backup and restart, crisis management, plus the requirements on suppliers and service providers along the supply chain.
Securing technically and with people
Access control with multi-factor authentication, cryptography, security of voice, video and text communication, and training for all staff including the management.
Twenty-four hours, seventy-two hours, one month
The deadlines run from becoming aware of a significant incident, and they are staggered. After 24 hours the early warning goes to the BSI: the nature of the incident and whether an unlawful act is suspected. After 72 hours comes the interim report with a first assessment, severity and indicators of compromise. After one month, the final report with causes, sequence of events and the measures taken.
Twenty-four hours is tight if it first has to be established who may report. So implementation includes a reporting chain with names, deputies and credentials for the reporting portal, and a form that lies ready, pre-filled.
Under section 38 of the BSIG, the duty to approve and oversee the measures falls on the management personally. Carrying them out can be delegated; the responsibility cannot.
Three phases
From the classification through to running operation.
Analysis, weeks 1 to 4
The applicability assessment with written reasoning, a gap analysis against the ten requirements, and an assessment of each gap by effort and severity.
Implementation, months 2 to 6
Risk analysis, building or extending the management system, technical measures, an incident response plan and reporting processes, registration with the BSI, training.
Running operation
Effectiveness testing, keeping the management system current, preparation for evidence towards the supervisor. On request as a virtual CISO with a named contact.
NIS2 does not stop at the office network
For operators with production or control technology, implementation in the automation is the harder part. Vulnerability management that assumes patching does not work there, and evidence of intrusion detection needs different sensors.
In that case we build on IEC 62443, because it describes the state of the art for automation and can be used as evidence towards the supervisor.
Common questions about NIS2
Possibly, through the supply chain. Affected customers have to place security requirements on their suppliers and check that they are met. In practice the requirement then reaches you as a questionnaire or a contract clause.
It covers a large part of it and is a good starting point. Beyond that, NIS2 requires the reporting chains, the registration and the evidence towards the management. We map your existing evidence against the ten points rather than building a second system beside it.
The BSIG provides for fines, staggered by essential and important entity, and under section 38 the management is personally liable for approving and overseeing the measures.
Six to nine months at a mid-sized company with no management system, considerably shorter if there is one. The applicability assessment and the reporting chain belong at the start, because they take effect fastest.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.