NIS2 or Cyfun: What is it and why is it important?

What is Cyfun?

NIS2 stands for the Network and Information Security 2 Directive, a European regulation. This new law is not just a response to the growing threat of cyberattacks but also a crucial step in protecting your personal data, your business, and the economy from digital risks. The NIS2 Directive follows the NIS1 Directive from 2016, which was the first European cybersecurity legislation.

Why is Cyfun important?

Cyfun is crucial because it provides a clear framework to protect your data and prepare for cyber threats. It helps you implement appropriate security measures, respond quickly to incidents, and regularly assess your cybersecurity. By adopting Cyfun, you not only enhance data protection but also strengthen customer and partner trust.

What is NIS2?

NIS2 stands for the Network and Information Security 2 Directive, a European regulation. This new law is not just a response to the growing threat of cyberattacks but also a crucial step in protecting your personal data, your business, and the economy from digital risks. The NIS2 Directive follows the NIS1 Directive from 2016, which was the first European cybersecurity legislation.

Why is NIS2 important?

European organizations are increasingly targeted by cyberattacks. Every day, numerous companies in Europe are hacked, and with recent developments in Ukraine, this threat appears to be growing. It is essential that Europe strengthens its cybersecurity standards to protect organizations from serious risks such as data breaches, financial losses, and reputational damage.

NIS2 is important because it establishes strict standards that help organizations better defend against these threats. It provides guidelines for reporting cyber incidents and helps companies minimize the impact of attacks. This is crucial for ensuring business continuity and maintaining customer trust. By complying with NIS2, you invest in a safer digital future for your organization.

What are the key differences between NIS2 and NIS1?

NIS2 has introduced significant changes compared to NIS1. Directive 2022/2555 ("NIS2") is a revision of Directive 2016/1148 ("NIS1") (Network and Information Security).

Stricter requirements now apply to digital service providers, and the directive has been expanded to cover more sectors. This means you now need to consider a broader set of security measures. Do you want to know how NIS2 differs from NIS1 and what you need to do to comply?

What do you need to do?

Belgium has already started implementing NIS2. The new rules, which came into effect on October 17, 2024, require organizations to prepare for the European directive's requirements. It is important to note that a 6-month grace period has begun, during which organizations will not be penalized for non-compliance with the new requirements. This gives you the opportunity to prepare without immediately facing financial penalties.

Here are the steps you need to follow:

  1. Registration: Register with the CCB (Safeonweb@work).
  2. Security measures: Implement appropriate cybersecurity measures.
  3. Incident reporting: Report major cyber incidents to the CCB.
  4. Compliance assessments: Conduct regular compliance assessments, supervised by an official authority (for essential entities).

What happens if you do not comply?

The implementation of NIS2 involves strict controls. EU member states, including Belgium, will monitor compliance through audits, inspections, and documentation requests. For essential sectors, fines can reach up to 10 million euros in extreme cases. This makes cybersecurity an absolute priority.

Making your business NIS2 compliant?

At Cresco Cybersecurity, we can help your business comply with NIS2.

Contact us