Skip to main content

Implementing NIS2 in your own organisation

Establish whether it applies to you, implement the ten requirements of section 30 of the German BSIG, and set the reporting chains up so that 24 hours is enough.

Betroffenheitsanalyse nach NIS2 Drei Fragen entscheiden, ob und wie eine Einrichtung erfasst ist. Erst danach stellt sich die Frage nach Nachweisen und Massnahmen. SECTOR? SIZE? ROLE? NO NO NO ESSENTIAL OR IMPORTANT THEN: EVIDENCE, REPORTING, MEASURES NIS2 · SCOPE, THEN MEASURES
Trusted by
The first step

Three questions decide whether it applies

Betroffenheitsanalyse nach NIS2 Drei Fragen entscheiden, ob und wie eine Einrichtung erfasst ist. Erst danach stellt sich die Frage nach Nachweisen und Massnahmen. SECTOR? SIZE? ROLE? NO NO NO ESSENTIAL OR IMPORTANT THEN: EVIDENCE, REPORTING, MEASURES NIS2 · SCOPE, THEN MEASURES

Every measure comes after the classification, and that turns on three questions: does your activity fall under one of the sectors in annexes 1 and 2, do you reach the thresholds for staff and turnover, and do you supply something without which an affected customer cannot work.

From the answers it follows whether you count as essential or as important. The difference concerns supervision: essential entities are audited without a trigger, important ones only once there is one. The requirements themselves are the same.

That assessment is done in a few days and has to be documented in writing. Anyone who keeps it properly has the evidence, if it comes to it, for why they are not registered.

Section 30 BSIG

Ten requirements, three groups

The act lists ten points. Sorted by what they mean inside an organisation, they become three pieces of work.

Knowing what can happen

Risk analysis and a security concept, security in development and operation including vulnerability management, and the effectiveness testing that evidences that the measures work.

Being prepared

Incident response, business continuity with backup and restart, crisis management, plus the requirements on suppliers and service providers along the supply chain.

Securing technically and with people

Access control with multi-factor authentication, cryptography, security of voice, video and text communication, and training for all staff including the management.

Reporting duties

Twenty-four hours, seventy-two hours, one month

The deadlines run from becoming aware of a significant incident, and they are staggered. After 24 hours the early warning goes to the BSI: the nature of the incident and whether an unlawful act is suspected. After 72 hours comes the interim report with a first assessment, severity and indicators of compromise. After one month, the final report with causes, sequence of events and the measures taken.

Twenty-four hours is tight if it first has to be established who may report. So implementation includes a reporting chain with names, deputies and credentials for the reporting portal, and a form that lies ready, pre-filled.

Under section 38 of the BSIG, the duty to approve and oversee the measures falls on the management personally. Carrying them out can be delegated; the responsibility cannot.

Approach

Three phases

From the classification through to running operation.

1

Analysis, weeks 1 to 4

The applicability assessment with written reasoning, a gap analysis against the ten requirements, and an assessment of each gap by effort and severity.

2

Implementation, months 2 to 6

Risk analysis, building or extending the management system, technical measures, an incident response plan and reporting processes, registration with the BSI, training.

3

Running operation

Effectiveness testing, keeping the management system current, preparation for evidence towards the supervisor. On request as a virtual CISO with a named contact.

In automation environments

NIS2 does not stop at the office network

For operators with production or control technology, implementation in the automation is the harder part. Vulnerability management that assumes patching does not work there, and evidence of intrusion detection needs different sensors.

In that case we build on IEC 62443, because it describes the state of the art for automation and can be used as evidence towards the supervisor.

Common questions

Common questions about NIS2

Possibly, through the supply chain. Affected customers have to place security requirements on their suppliers and check that they are met. In practice the requirement then reaches you as a questionnaire or a contract clause.

It covers a large part of it and is a good starting point. Beyond that, NIS2 requires the reporting chains, the registration and the evidence towards the management. We map your existing evidence against the ten points rather than building a second system beside it.

The BSIG provides for fines, staggered by essential and important entity, and under section 38 the management is personally liable for approving and overseeing the measures.

Six to nine months at a mid-sized company with no management system, considerably shorter if there is one. The applicability assessment and the reporting chain belong at the start, because they take effect fastest.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139