{"id":854216,"date":"2023-10-18T08:21:00","date_gmt":"2023-10-18T07:21:00","guid":{"rendered":"https:\/\/pulse.microsoft.com\/?p=854216"},"modified":"2023-10-18T11:20:42","modified_gmt":"2023-10-18T10:20:42","slug":"fa2-one-year-to-go-preparing-for-nis2-isnt-a-compliance-exercise-its-a-business-opportunity","status":"publish","type":"post","link":"https:\/\/pulse.microsoft.com\/en\/work-productivity-en\/na\/fa2-one-year-to-go-preparing-for-nis2-isnt-a-compliance-exercise-its-a-business-opportunity\/","title":{"rendered":"One year to go: Preparing for NIS2 isn\u2019t a compliance exercise \u2013 it\u2019s a business opportunity"},"content":{"rendered":"<p class=\"intro\">I recently read an insight from <a href=\"https:\/\/www.idc.com\/getdoc.jsp?containerId=US49568822\" target=\"_blank\" rel=\"noopener\">IDC<\/a> that suggests addressing cybersecurity threats is <em>the<\/em> top board priority worldwide. Further, CEOs of large firms say security is their most important expenditure.<\/p>\n<p>It was interesting to see the international consensus here. Certainly, in my work with Microsoft\u2019s customers in Western Europe, I know cybersecurity is very much top of mind among the c-suite and IT leaders alike.<\/p>\n<p>As of <a href=\"https:\/\/digital-skills-jobs.europa.eu\/en\/cybersecurity-skills-academy\" target=\"_blank\" rel=\"noopener\">2022<\/a> Europe faces a shortage of around 500,000 skilled cybersecurity professionals (up from 200,000 in <a href=\"https:\/\/media.isc2.org\/-\/media\/Project\/ISC2\/Main\/Media\/documents\/research\/ISC2-Cybersecurity-Workforce-Study-2021.pdf?rev=5ede8b928b3d43888fae31cf4424265e\" target=\"_blank\" rel=\"noopener\">2021<\/a>). What\u2019s more, the threat landscape continues to evolve. The <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/security-insider\/microsoft-digital-defense-report-2023\" target=\"_blank\" rel=\"noopener\">Microsoft Digital Defense Report<\/a> shows that nation state attacks have increase d in the region, and bad actors are increasingly targeting essential services like energy, agriculture, transportation.<\/p>\n<h2>Getting NIS2-ready is ultimately a business opportunity.<\/h2>\n<p>It&#8217;s in this context that the EU is implementing the most comprehensive EU cybersecurity legislation to date: Network and Information Systems Directive 2 (NIS2). Set to come into effect in one year from now in October 2024, the purpose of NIS2 is to establish a baseline of cybersecurity measures for organizations that provide essential services.<\/p>\n<p>160,000 companies across 18 sectors will be expected to comply. Municipalities, healthcare systems, financial services and manufacturing firms are a few examples.<\/p>\n<p>It\u2019s a comprehensive blueprint for cybersecurity resilience.<\/p>\n<p>In fact, I\u2019ve had conversations with colleagues and customers who have drawn parrels with GDPR. I think that\u2019s a fair comparison. I also think GDPR offers some lessons that are instructive as companies prepare for NIS2 over the coming months.<\/p>\n<p>NIS2 will help organizations ensure they are prepared to respond to the evolving threat landscape. That level of preparedness will only build trust among an organization\u2019s customers, partners and stakeholders. This is exactly what we saw with GDPR. Clearly people and organizations only want to do business with those they trust.<\/p>\n<h2>Preparing for NIS2 isn\u2019t a backroom IT issue \u2013 it calls for company-wide transformation.<\/h2>\n<p>Did you know that the median time for an attacker to begin moving within a corporate network after a <em>single device<\/em> is compromised is less than 2 hours? With criminals becoming more sophisticated, every person in an organization \u2013 from a factory floor manager to executives \u2013 needs the right skills and tools to recognize and effectively mitigate threats.<\/p>\n<p>That said, many cybersecurity teams I work with are currently understaffed. It\u2019s here where I see artificial intelligence (AI) tools playing an important role. This technology is augmenting the skills and experience of professionals, helping them identify and respond to threats with machine speed.<\/p>\n<p>Again, just like with GDPR, preparing for NIS2 represents a transformation challenge \u2013 and opportunity \u2013 that will be as much about people as it is technology.<\/p>\n<h2>Successful transformation takes partnership.<\/h2>\n<p>The spirit behind NIS2 speaks to a simple truth: we can\u2019t as a region address cybersecurity if we don\u2019t work together. Collaboration across public and private sector organizations will be key. In addition, businesses will need trusted partners. Just as they would with any major transformation effort \u2013 as was the case with GDPR.<\/p>\n<p>At Microsoft, the safety and security of our customers is our top priority. It\u2019s why every product and service we create is \u201csecure by design.\u201d And behind our technology, we have a world-class team of cybersecurity professionals. Using AI, our teams can analyze trillions of pieces of cybersecurity data everyday \u2013 helping keep our customers safe and their businesses resilient.<\/p>\n<p>We have a range of cybersecurity solutions that can help organizations with their NIS2 transformation journeys. With employee trainings, risk assessments, threat monitoring and incident alerts, we are committed to working with our customers to find the right tools and processes to prepare their businesses for NIS2 and beyond.<\/p>\n<p>The bottom-line: Shoring up EU\u2019s cybersecurity readiness is so much more than a compliance exercise. It\u2019s an opportunity to build trust with your customers and maintain a competitive edge.<\/p>\n<p>For more information on how Microsoft can help you get ready for NIS2 see <a href=\"https:\/\/info.microsoft.com\/WE-PGSD-CNTNT-FY24-09Sep-25-Preparing-for-NIS2-3-Guiding-Principles-for-Leaders-SRGCM10905_LP01-Registration---Form-in-Body.html\" target=\"_blank\" rel=\"noopener\">Preparing for NIS2: More than a compliance exercise: an opportunity to future proof your organization<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently read an insight from IDC that suggests addressing cybersecurity threats is the top board priority worldwide. Further, CEOs of large firms say security is their most important expenditure. It was interesting to see the international consensus here. Certainly, in my work with Microsoft\u2019s customers in Western Europe, I know cybersecurity is very much [&hellip;]<\/p>\n","protected":false},"author":60,"featured_media":854500,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1829],"class_list":["post-854216","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-privacy-en","specials-work-productivity-en","stories-how-can-i-work-secure","stories-working-secure-en","businessPriorities-digital-transformation"],"_links":{"self":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/854216"}],"collection":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/comments?post=854216"}],"version-history":[{"count":5,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/854216\/revisions"}],"predecessor-version":[{"id":854967,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/posts\/854216\/revisions\/854967"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media\/854500"}],"wp:attachment":[{"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/media?parent=854216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pulse.microsoft.com\/en\/wp-json\/wp\/v2\/categories?post=854216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}