{"id":3594,"date":"2025-04-10T16:32:12","date_gmt":"2025-04-10T14:32:12","guid":{"rendered":"https:\/\/enthec.com\/?p=3594"},"modified":"2025-04-10T16:32:12","modified_gmt":"2025-04-10T14:32:12","slug":"nis-2-how-does-it-affect-companies-and-what-measures-must-be-taken-to-comply-with-the-regulations","status":"publish","type":"post","link":"https:\/\/enthec.com\/en\/nis-2-how-does-it-affect-companies-and-what-measures-must-be-taken-to-comply-with-the-regulations\/","title":{"rendered":"NIS 2: How does it affect companies, and what measures must be taken to comply with the regulations?"},"content":{"rendered":"
In an environment<\/span> where cybersecurity has become critical for business survival, <\/b> the entry into force of the NIS 2 Directive marks a before and after for hundreds of organizations in Europe. <\/span><\/p>\n This is not a recommendation or a simple guide to best practices:<\/span> NIS 2 is mandatory<\/b> and requires companies to protect their systems, data, and services against increasingly complex threats. <\/span><\/p>\n But what exactly does this directive imply? How does it affect companies in Spain, and which sectors must comply with it? Above all, <\/span>how can an organization adapt without being overwhelmed by technical complexity?<\/b><\/p>\n This article explains everything clearly and shows how tools like<\/span> Kartos<\/span><\/a> by Enthec can<\/span> help you take that step safely and effectively.<\/b><\/p>\n The NIS 2 <\/b>Directive<\/span> (Network and Information Security) is the evolution of the first NIS directive, approved in 2016. It was created to improve the resilience of essential services to cyberattacks. <\/span>resilience of essential services<\/b> to cyberattacks.<\/span><\/p>\n However, the first version was reduced due to the evolving threat landscape. That’s why the European Union published the new <\/span>NIS 2 Directive in January 2023, significantly expanding its scope and requirements.<\/b><\/p>\n <\/p>\n <\/p>\n NIS 2 regulates and<\/b> demands active company responsibility, incorporating continuous surveillance, prevention, and threat response measures.<\/span><\/p>\n One of the key points of this regulation is its<\/span> expansion of the scope of application.<\/b>. It is no longer limited to large critical infrastructures such as electricity, transport, or health. No,w it also includes medium and large companies in sectors such as: <\/span><\/p>\n According to INCIBE estimates<\/span>, more than 12,000 entities in Spain could be affected by the NIS 2 regulation.<\/b>. Many of them, especially tech SMEs, have not yet started to prepare.<\/span><\/p>\n Complying with<\/span> NIS 2 is not just a matter of software or firewalls;<\/b>it involves a comprehensive approach that affects the organization at multiple levels. Enterprises must implement<\/span> appropriate security controls<\/b>, from network segmentation and<\/span> vulnerability management<\/span><\/a> to access policies<\/span> or data encryption<\/span><\/a>.<\/span><\/p>\n Regulations require<\/span> regular analyses and assessments of risks<\/b> associated with the security of networks and systems.<\/span><\/p>\n In the event of a significant incident, the company must<\/span> inform the competent authorities within 24 hours<\/b>, which requires having effective detection and response systems.<\/span><\/p>\n Senior management must be actively involved in the cybersecurity strategy.<\/span> Responsibility cannot be delegated solely to technical teams<\/b>.<\/span><\/p>\nWhat is the NIS 2 Directive?<\/b><\/h2>\n
<\/p>\n
What changes with NIS 2?<\/b><\/h3>\n
\n
Which companies are affected by NIS 2?<\/b><\/h3>\n
\n
What does NIS 2 require of companies?<\/b><\/h3>\n
Among the main requirements, the following stand out: <\/span><\/p>\nTechnical and organisational measures<\/b><\/h3>\n
Ongoing risk assessments<\/b><\/h3>\n
Obligation to report incidents<\/b><\/h3>\n
Governance and accountability<\/b><\/h3>\n
Sanctioning regime<\/b><\/h3>\n