If your organization is already ISO 27001 certifiied, you’re part way to becoming NIS2 compliant
Find out how Veeam can help fill the gaps in your cybersecurity and support your NIS2 compliance journey.
Understand what the cybersecurity directive means to your business, and how Veeam can help with NIS2 compliance… time is ticking
The Network Information Security Directive (NIS2) is designed to strengthen the cybersecurity posture of EU critical infrastructure entities or industries to meet basic compliance requirements.
What differentiates NIS2 from its predecessor is that compliance spans the entire third-party supply chain and most importantly, it could mandate personal liability to corporate management and executives for non-compliance.
NIS2 takes information security to the core of national security.
EU Member States have until 18 October 2024 to transpose NIS2 security requirements into their national laws, so it’s important to act now.
Whitepaper
The NIS2 directive is built on two main pillars to strengthen cybersecurity and overall resilience
Organizations are required to implement robust risk management and business continuity measures to minimize cyber risks and impact. This includes incident management, securing the supply chain, enhancing network and access control security, encryption, system recovery, emergency procedures, and establishing a crisis response team.
Essential entities are mandated to establish processes for promptly reporting significant security incidents, with specific notification deadlines, such as a 24‑hour ‘early warning’ system. NIS2 also significantly emphasises corporate accountability, requiring management to be actively involved in and knowledgeable about the organization’s cybersecurity measures.
Greater consequences
The NIS2 Directive requires companies to plan and strengthen their cybersecurity, to communicate with supervisory bodies and report breaches with greater transparency.
Fines vary depending on whether an industry or entity is defined as “Essential” or “Important”.
76%
of organizations have data protection gaps*
74%
of organisations protect their Microsoft 365 data*
3out of4
organizations suffered at least one ransomware attack in the preceding twelve months*
*Source: Veeam Data Protection Trends Report 2024
Find out how Veeam can help fill the gaps in your cybersecurity and support your NIS2 compliance journey.
Understand if your business falls under the NIS2 scope and gain clarity on the implications of non-compliance.
≥250 FTE or ≥€50M annual turnover or balance sheet of ≥€43M
Fines for non-compliance
Up to €10 Million or at least 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher
≥50 FTE or ≥€10M annual turnover or balance sheet of ≥€10M (or 2% of worldwide sales)
Fines for non-compliance
Up to €7 Million or at least 1.4% of the total annual worldwide turnover of the preceding financial year, whichever is higher
Manufacture, Production & Distribution
Production, Processing & Distribution
Remember
NIS2 not only spans the entire supply chain, but also includes additional segments. Even non-EU countries such as the UK and Switzerland, who are not implementing NIS2 or bound by EU legislation, could be affected.
Many organizations are either unaware of the pending 18 October 2024 NIS2 compliance deadline or burying their heads in the sand. Be in the know.
Overview
We enable organizations to complete their cyber resiliency strategy with the best‑in‑class data security, data recovery and data freedom.
Multi‑layered protection designed for peace of mind across the hybrid cloud.
Fast, reliable recovery when you need it, where you need it.
Protect all your data, anywhere, any way, with zero lock‑in.
Find out how Veeam can help fill the gaps in your cybersecurity and support your NIS2 compliance journey.