The Cyber Security Review | Friday, October 21, 2022
Under the revised NIS-2 Directive in Europe, pharma companies must be proactive in safeguarding their digital assets.
FREMONT, CA: The amended Network and Information Security (NIS) Directive, also known as NIS-2, was approved by the European Union (EU) Parliament. It replaces and builds upon Directive (EU) 2016/1148 on the Security of Network and Information Systems (NIS Directive). The NIS Directive, implemented in 2016, is the first piece of cybersecurity legislation to apply to the entire European Union. Its specific goal was to develop a highly common cybersecurity standard among the member states.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Although the NIS Directive gave member states better cybersecurity capabilities, its implementation was challenging and caused fragmentation at many levels within the internal market. The new NIS-2 Directive is being created to modernise the current legislative cybersecurity framework to reflect the growing digital change of society and to replace the previous version released in 2016.
The COVID-19 pandemic has increased this change by introducing new threats with the potential to have cascading effects that could have a detrimental influence on the provision of essential services throughout the whole internal market. Cyberattacks are becoming more frequent and becoming more sophisticated as they originate from inside and outside the EU.
The European Parliament's Committee on Industry, Research, and Energy (ITRE) has been given responsibility for the revised NIS-2 Directive, which is meant to serve as one of the foundational principles for the European cybersecurity framework and as a key tool for advancing both the Digital Europe Programme and Europe's strategic autonomy.
Key Changes in NIS-2
Scale: One of the major modifications embodied in NIS-2 is the expansion of the original NIS legislation's purview in response to the expanding threats posed by digitisation and the spike in cyberattacks, particularly during the COVID-19 pandemic. With NIS-2, a larger group of organisations are covered, and the definition of essential services is clarified. However, this enhanced coverage suggests that cyber resilience measures will need to be implemented across the European continent on a much bigger scale due to escalating commercial interconnection, rapid digitisation, and pervasive networking across numerous sectors. As a whole, more businesses are starting to play a critical systemic role in preventing cyberattacks.
Governance: By requiring senior managers to assume responsibility for cyber resilience, the new NIS-2 regulation has made substantial advancements in security governance. It is hoped that organisations will change on a top-down basis by making this commitment. Instead of being restricted to the purview of technical teams, cyber resilience must be prioritised at the board and senior management levels.
NIS-2 requires that competent authorities be given a wider range of authority to impose penalties and fines. According to the new directive, EU member states must impose administrative penalties for cybersecurity risk management and notify the public about any obligations breaches that result in losses of up to 10 million euros or two per cent of vital businesses' total annual global revenue, whichever is larger.
It is hoped that regulatory fines of this magnitude that have occurred in other jurisdictions, such as those imposed on Uber in the United States, which was fined USD 148 million (Euro 148 million) for concealing a data breach in 2018, and British Airways in the United Kingdom (UK), which was assessed a record Euro 183 million (Euro 212 million) fine for violating General Data Protection Regulation (GDPR) rules for a breach of customer data, also in 2018, will serve as a major lever.
Obligation to Respond to Incidents: NIS-2 goes one step further by defining a substantial impact on a business organisation. Under the new advice, there will no longer be a specified criterion for the number of impacted users but rather whether there was a disruption to vital services or if a firm suffered material or financial loss. Additionally, the notification window has been shortened from 72 to 24 hours and depending on the scope and type of the assault, users of services must be reported to as well as the general public.
In general, the NIS-2 Directive aims to strengthen security requirements, address supply chain security, simplify reporting requirements, promote encryption and vulnerability disclosure, introduce stricter supervision measures, and enforce requirements, including unified sanctions across the EU. Building a more resilient digital ecosystem is now considered an absolute strategic necessity. Therefore, it is believed that such measures will encourage commercial entities to be more responsible in becoming cyber-resilient and promote better transparency to all parties affected by a potential breach.
More in News