• Current students
      • Student centre
        Enrol on a course/exam
        My enrolments
        Exam results
        Mock exams
      • Course information
        Students FAQs
        Student induction
        Course enrolment information
        F2f student events
        Key dates
        Book distribution
        Timetables
        FAE elective information
        CPA Ireland student
      • Exams
        CAP1 exam
        CAP2 exam
        FAE exam
        Access support/reasonable accommodation
        E-Assessment information
        Exam and appeals regulations/exam rules
        Timetables for exams & interim assessments
        Sample papers
        Practice papers
        Extenuating circumstances
        PEC/FAEC reports
        Information and appeals scheme
        Certified statements of results
        JIEB: NI Insolvency Qualification
      • CA Diary resources
        Mentors: Getting started on the CA Diary
        CA Diary for Flexible Route FAQs
      • Admission to membership
        Joining as a reciprocal member
        Admission to Membership Ceremonies
        Admissions FAQs
      • Support & services
        Recruitment to and transferring of training contracts
        CASSI
        Student supports and wellbeing
        Audit qualification
        Diversity and Inclusion Committee
    • Students

      View all the services available for students of the Institute

      Read More
  • Becoming a student
      • About Chartered Accountancy
        The Chartered difference
        Student benefits
        Study in Northern Ireland
        Events
        Hear from past students
        Become a Chartered Accountant podcast series
      • Entry routes
        College
        Working
        Accounting Technicians
        School leavers
        Member of another body
        CPA student
        International student
        Flexible Route
        Training Contract
      • Course description
        CAP1
        CAP2
        FAE
        Our education offering
      • Apply
        How to apply
        Exemptions guide
        Fees & payment options
        External students
      • Training vacancies
        Training vacancies search
        Training firms list
        Large training firms
        Milkround
        Recruitment to and transferring of training contract
      • Support & services
        Becoming a student FAQs
        School Bootcamp
        Register for a school visit
        Third Level Hub
        Who to contact for employers
    • Becoming a
      student

      Study with us

      Read More
  • Members
      • Members Hub
        My account
        Member subscriptions
        Newly admitted members
        Annual returns
        Application forms
        CPD/events
        Member services A-Z
        District societies
        Professional Standards
        ACA Professionals
        Careers development
        Recruitment service
        Diversity and Inclusion Committee
      • Members in practice
        Going into practice
        Managing your practice FAQs
        Practice compliance FAQs
        Toolkits and resources
        Audit FAQs
        Practice Consulting services
        Practice News/Practice Matters
        Practice Link
      • In business
        Networking and special interest groups
        Articles
      • Overseas members
        Home
        Key supports
        Tax for returning Irish members
        Networks and people
      • Public sector
        Public sector presentations
      • Member benefits
        Member benefits
      • Support & services
        Letters of good standing form
        Member FAQs
        AML confidential disclosure form
        Institute Technical content
        TaxSource Total
        The Educational Requirements for the Audit Qualification
        Pocket diaries
        Thrive Hub
    • Members

      View member services

      Read More
  • Employers
      • Training organisations
        Authorise to train
        Training in business
        Manage my students
        Incentive Scheme
        Recruitment to and transferring of training contracts
        Securing and retaining the best talent
        Tips on writing a job specification
      • Training
        In-house training
        Training tickets
      • Recruitment services
        Hire a qualified Chartered Accountant
        Hire a trainee student
      • Non executive directors recruitment service
      • Support & services
        Hire members: log a job vacancy
        Firm/employers FAQs
        Training ticket FAQs
        Authorisations
        Hire a room
        Who to contact for employers
    • Employers

      Services to support your business

      Read More
☰
  • Find a firm
  • Jobs
  • Login
☰
  • Home
  • Knowledge centre
  • Professional development
  • About us
  • Shop
  • News
Search
View Cart 0 Item

Knowledge Centre

☰
  • Home/
  • News/
  • Knowledge centre news item
☰
  • News
  • News archive
    • 2024
    • 2023
  • Press releases
    • 2025
    • 2024
    • 2023
  • Newsletters
  • Press contacts
  • Media downloads

Securing cyber resilience: understanding and complying with NIS2

Mar 22, 2024

The new EU Directive NIS2 requires meticulous compliance strategies to improve cybersecurity resilience, explains Puneet Kukreja

The intense uptake of digital solutions and innovative technologies over the past four years has changed the way we socialise, work, shop, bank, and receive necessary services, such as health.

As sectors and services increasingly become interconnected and interdependent, the cybersecurity threat landscape continues to grow in sophistication and focus.

Safeguarding critical infrastructures and services is paramount to protecting society and economies from these actors.

In response, EU lawmakers have introduced several interconnected EU-wide laws to improve the digital and operational resilience of the sectors and services we rely on most.

The second Network and Information Systems Directive (Directive (EU) 2022/2555 (NIS2)) is one of these EU-wide laws. It comes into effect on 18 October 2024 and will have a compliance impact on many public and private sector organisations across 18 sectors, similar to that experienced under the GDPR.

The regulatory supervision and enforcement measures under NIS2 bear similarities to the GDPR. However, direct accountability and liability for upper management and possible suspension of CEO duties brings this squarely into the board room.

NIS2 is an evolution from its predecessor, NIS-D (Directive (EU) 2016/1148), extending the legislative scope to capture entities in several additional sectors and subsectors, including public bodies and a wider range of digital service providers, as well as covered entities’ information and communications technology (ICT) supply chains.

NIS2 sets out the minimum powers of supervision and enforcement that Member State competent authorities must have.

Administrative fines can be imposed on essential and important entities for breaches of obligations relating to cybersecurity risk management measures and incident notification.

For ‘essential entities’, the maximum fine is at least €10,000,000 or at least 2 percent of the total worldwide annual turnover in the previous financial year, whichever is higher. For ‘important entities,’ these figures are €7,000,000 and 1.4 percent.

Irish legislation must be enacted before 18 October 2024 to transpose NIS2.

Consistent with its treatment of NIS-D, the transposing legislation will provide that breaches of certain provisions of the same will be a criminal offence.

We expect that a person found guilty of any of these offences will be liable on conviction to a fine and/or imprisonment.

It is vital that CEOs, CFOs, CIOs, CISOs and board members understand not only the financial, personal, and reputational consequences of non-compliance – which underscores the urgency of pursuing NIS2 compliance now – but also the role that NIS2 will play in safeguarding their organisation’s cybersecurity and operational resilience.

Navigating NIS2

There are several steps an organisation can take to navigate the NIS2.

1. Legal analysis

Assess whether NIS2 applies to your organisation or whether any of the statutory exemptions will apply.

To the extent NIS2 applies, it will be necessary to understand its requirements, including any cross-border implications and the steps necessary to secure ICT supply chains.

2. Strategic planning of compliance navigation

Identify cybersecurity risks and set clear targets to assist in allocating resources and creating strong governance for resilience and regulatory adherence. This will also ensure operational integrity and informed decision-making.

3. Technology procurement

Align chosen technologies with organisation needs and regulatory requirements.

4. Implementation strategy

Develop a robust plan covering technology integration, employee training, and monitoring mechanisms.

5. Technology implementation

Explore partnerships with organisations experienced in technology transformation. This will help you enable the full lifecycle of capability from analysis to managed services.

6. Employee training and awareness

Champion comprehensive training programmes to instil a culture of cybersecurity within the organisation.

7. Managed services for continuous compliance

Explore partnerships with experienced service providers for ongoing monitoring and response capabilities.

8. Budgeting and resource allocation

Collaborate on budgeting to align finance planning with strategic cybersecurity objectives.

9. Documentation and reporting

Oversee the creation of comprehensive documentation, ensuring transparency and accountability.

Your NIS2 journey

Organisations will differ in their level of compliance or maturity across the key control areas that are required under NIS2.

However, one thing is certain: all in-scope organisations should now consider the implications of NIS2 to ensure they have sufficient time to assess, design, and implement their compliance plans before the legislation comes into effect.

Organisations operating in the sectors defined in NIS2 will need to assess whether they fall within its scope, the availability of any exemptions, their categorisation as ‘essential’ or ‘important’, their NIS2 obligations, and the impact of and interplay with other EU cybersecurity and operational resilience laws.

NIS2 requires organisations to address cybersecurity risks in their own ICT supply chains. In practice, this will require a risk-based assessment of ICT supplier relationships, enhancing contracts and securing inspection and other rights to ensure supply chain security. Early supplier engagement will be essential.

To the extent certain in-scope organisations are established and/or providing their services in more than one EU Member State, they may be subject to implementing laws in more than one jurisdiction or the EU Member State where their cybersecurity risk management decisions are predominately made. The NIS2 jurisdiction rules require careful consideration and may cause certain entities to rethink the geographic positioning of cybersecurity decision-making.

To successfully achieve and sustain NIS2 compliance, an organisation must commit to continuous improvement as well as the adoption of proactive measures. Both are key in this evolving digital landscape.

Beginning a compliance journey with a legal analysis of the new directive will ensure you start on the right path and your organisation not only avoids substantial financial penalties but also becomes more resilient to evolving cyber threats.

Puneet Kukreja is Cyber Security Leader at EY

The latest news to your inbox

Please enter a valid email address You have entered an invalid email address.

Useful links

  • Current students
  • Becoming a student
  • Knowledge centre
  • Shop
  • District societies

Get in touch

Dublin HQ

Chartered Accountants
House, 47-49 Pearse St,
Dublin 2, D02 YN40, Ireland

TEL: +353 1 637 7200
Belfast HQ

The Linenhall
32-38 Linenhall Street, Belfast,
Antrim, BT2 8BG, United Kingdom

TEL: +44 28 9043 5840

Connect with us

Something wrong?

Is the website not looking right/working right for you?
Browser support
CAW Footer Logo-min
GAA Footer Logo-min
CCAB-I Footer Logo-min
ABN_Logo-min

© Copyright Chartered Accountants Ireland 2020. All Rights Reserved.

☰
  • Terms & conditions
  • Privacy statement
  • Event privacy notice
  • Sitemap
LOADING...

Please wait while the page loads.