Read Time, 3 min.

New research: Getting NIS2 ready  

The European wide directive Network and Information Security 2 (NIS2) comes into effect on 17 October, with the aim of strengthening Europe’s ability to collectively defend against cyber-attacks and protect the region’s critical infrastructure. 

This new directive will impact upwards of 180,000 organizations, from healthcare and transport, to manufacturing and supply chain. Most organizations are aware of NIS2 and what it aims to achieve (as well as the costs), but research from IDC has shown that only 14% of organizations are fully ready for NIS2. The majority, at 77%, are partially there. 

 With so few organizations across the NIS2 finish line and the official deadline for compliance fast approaching, I wanted to share some of the findings from this research, and how you can move your organization’s transformation efforts forward. 

NIS2 Capable 

IDC has found that over 90% of organizations impacted by NIS2 are aware of it and have taken first steps in taking action to align with the directive. 

About one in five (17%) are categorized as IDC as being NIS2 ‘capable.’  

 Organizations at this level of readiness have a long way to go however, with the need for many to implement all necessary compliance procedures and policies. 

Let’s take incident handling as an example, which is a key requirement of NIS2. With large organizations often being the target of multiple, complex cyberattacks, the rapid co-ordination of multiple stakeholders and timely reporting of incidents is what allows for quicker response and recovery, as well as minimizing the impact on essential services and the wider economy. Having robust technical protection will clearly help but organizations also need to think through the complete response to a security incident. 

Technologies like Microsoft Defender and Microsoft Sentinel will help security teams handle incidents with a real time, comprehensive view of security issues. But the work on becoming NIS2 ready relies on an organization’s ability to create a fully robust set of compliance procedures and policies that engage the board and wider organization. This is what ensures that everyone is on board with how to respond to a security incident and how to keep the business going with a minimal impact on operations.
 

NIS2 Equipped

The next level of readiness IDC identified was NIS2 ‘equipped.’ About one-third (33%) of organizations fall into this category, and are characterized as being able to address most NIS2 requirements.  

The way to move beyond this level of readiness is to conduct a gap analysis of your security measures, and also what’s needed to meet NIS2 requirements or security standards such as ISO 27001.

Let’s consider supply chain security as an example, which is another key NIS2 requirement. When organizations enhance the security and resilience of their own organizations, cyber-criminals will look for other routes to compromise security via weaknesses in an organization’s supply chain. 

Addressing supply chain vulnerabilities is key to ensuring your own assets remain secure. Microsoft tools like Compliance Monitoring, Security Posture Management and Conditional Access Policies can help you control and manage the external access of organizational assets and customer tenants, but your security will still be dependent on your ability to identify gaps and challenges in your security posture.  

All organizations impacted by NIS2 should be in the process of identifying the challenges they have and develop action plans now.
 

Are you NIS2 ready? 

According to the IDC, organizations at the ready level for NIS2 (14%) exhibit the highest degree of preparedness for incident handling, have business continuity measures in place and deploy robust technology to ensure supply chain security and advanced encryption or cryptography. 

At Microsoft, we stand ready to help organizations of all kinds use  NIS2 as an opportunity to advance their cybersecurity posture. Our unique perspective in the security market and comprehensive suite of secure cloud-based solutions can help you identify, prevent, and mitigate against the cyberthreats we are facing today and in the future.   

Source: IDC Infobrief, Sponsored by Microsoft, NIS2 Readiness: A Guide for Organizations in Europe, #EUR252440224, July 2024 

> Read the IDC report in full 

Join us: Microsoft Discover Hour: Prepare for the new AI and regulatory landscape with Microsoft Purview

Our leading experts will show how Microsoft Purview can help you adopt AI securely, use AI to improve your data compliance, and deploy a data security program successfully. We will also share the findings of the latest IDC research on how prepared the European markets actually are for the NIS2 countdown.

Discover more related articles per industry:

Education

  • a group of people sitting at a table using a laptop computer

    4 reasons Citrix and Windows Virtual Desktop are better together for education

    Educational institutions all over the world experience a huge transformation. We are all familiar with the impact of COVID-19 on digitization in education, but there are more challenges. The digitization challenges faced by educational institutions   Because of the measures against the COVID-19 pandemic, like lockdowns and social distancing, the trend of online or blended […]

  • Unlock the potential of your students with Microsoft’s new Learning Accelerators

    Unlock the potential of your students with Microsoft’s new Learning Accelerators

    Personalized learning is a goal that educators everywhere have been trying to achieve for years. But the pandemic shone a light on the complexity of that challenge for teachers, who face a more diverse set of student needs than ever before.  Because delivering a truly personalized learning experience for every student has traditionally required lots […]

Finance & Insurance

Government

  • Citizen-Experience-Image

    A focus on Citizen Experience drives public sector transformation

    In recent times, providing a responsive and efficient service that meets citizens’ expectations has become a priority for public sectors across the EU. But as citizen experience (CX) – such as improving citizen satisfaction and providing efficient digital services – takes center stage, many national, regional and local government organizations are falling behind. Governments must […]

  • a display in a building

    How public health and social services can deliver better care with secure digital solutions

    The mission of Public Health and Social Services organisations is to provide the right services to the right citizens at the right time. But how can that be achieved against a backdrop of increasing regulation, growing demand for services and shrinking budgets? That’s the challenge that the IDC white paper ‘Transforming Public Health and Social […]

Healthcare

  • Two people working together

    Making Every Day Better with Microsoft Teams

    Finland’s second-largest public sector employer, HUS Helsinki University Hospital, deployed Microsoft Teams extensively in its organization of 27,000 employees. Microsoft Teams provides HUS with a foundation for customer-oriented digital transformation, which acts as a part of its vision to be a trendsetter in healthcare. The deployed Microsoft services offer an easy-to-use solution for remote appointments […]

  • a doctor wearing a white coat and smiling at the camera

    How technology is revolutionising care for patients with chronic conditions

    “I could never have imagined that the monitoring system I had developed for patients with chronic heart disease would one day play a role in the war against a global pandemic.” José Paulo Carvalho, Founding Partner of Portuguese telehealth company Hope Care, explains how technology he has been developing for more than six years – HCAlert […]

Manufacturing

  • Guy standing next to plane looking at Smartwatch to check reporting.

    Air France and KLM subsidiary EPCOR predicts future failures with data and AI

    EPCOR provides maintenance, repair and overhaul services, including state-of-the-art test facilities for aircraft pneumatic components and Auxiliary Power Units (APU). The APU is responsible for starting the main engines and provide power to essential aircraft functions. By harnessing cloud-based APU data using innovative analysis and machine learning, EPCOR is helping airlines meet their cost, safety […]

  • 9 ways to turn your field service centre into a profit centre

    9 ways to turn your field service centre into a profit centre

    A service that generates more profit than cost: it’s the ultimate goal for any organisation. We’ve listed a few tips below to help you make this dream a reality. 1. Know what you’ve got to offer Knowing what you’ve got to offer and knowing how (potential) customers view your story are important elements in marketing […]

Retail

Discover more related articles per dossier:

Customer Stories

  • How to transform banking with Personetics’ revolutionary app

    How to transform banking with Personetics’ revolutionary app

    A new generation of customers now expects much more from banking. The customer journey, not the product, needs to be the focus for financial services. And the key to enhancing it is data.   Personetics is responding to this demand with its white label solution that allows any bank to start to maximize the benefits of […]

Digital Transformation

  • An illustration of a girl with headphones

    The Artificial Intelligence podcast: Setting the scene

    In this episode of The Artificial Intelligence Podcast, we take a bird’s eye view of AI in Western Europe. Hear Thomas Holm Møller, partner at EY’s digital strategy practice, elaborate on the new ground-breaking AI report – a study commissioned by Microsoft in collaboration with EY. The report is based on interviews and surveys with […]

Security & Privacy

Tips

  • Male store associate helping female customer in tech shop

    Creating great experiences for employees and the customers they serve

    Retail is experiencing ongoing labor shortages in the aftermath of the pandemic. Many people have retired early, found new jobs, or have simply decided to leave the labor market. As competition for skilled and experienced staff has become fiercer, attracting talent and retaining staff is crucial for survival and success.  While increasing wages and benefits […]