News

NIS2 and the amendment to the KSC Act: cybersecurity is the responsibility of the management board

The NIS2 Directive is revolutionising the protection of information systems. The NIS2 Directive amends the rules introduced by the NIS Directive several years ago. Digital security is becoming an integral part of compliance, risk management and the direct responsibility of board members. For many businesses, implementing the new requirements will be similar to the earlier implementation of the GDPR; similarly, in this case, formal documentation will be necessary but insufficient without effective oversight and the application of procedures.

Scope of regulation and self-identification

The first significant change introduced by the NIS 2 Directive is the expansion of the scope of entities subject to these obligations. In addition to sectors traditionally regarded as critical, such as energy, transport, banking, healthcare and digital infrastructure, the regulation also covers additional sectors, including waste management, food production and distribution, chemicals, postal services, selected areas of industrial production and digital service providers.

The model for determining which entities are covered by the regulation has also changed – instead of the previous model of awaiting an administrative decision, a self-identification mechanism has been introduced – businesses must themselves determine whether they fall within the scope of the new regulations.

The NIS2 Directive applies predominantly to medium-sized and large enterprises operating in the sectors specified in the legislation, although exceptions to this are provided for. The obligations may also apply to smaller entities if they perform particularly important tasks, such as providing DNS services, trust services, managed cybersecurity services, or carrying out specific public tasks.

Responsibility of the management board

The NIS2 Directive designates board members as the persons responsible for putting in place regulations to ensure cybersecurity. The board does not have to configure firewalls or analyse logs itself, but it should approve risk management measures, oversee their implementation, ensure adequate resources are provided, and hold those responsible for security to account. Delegating tasks to the IT department, the security officer or an external provider does not remove responsibility for the choice of organisational model or for a lack of oversight.

It must not be forgotten that, in the event of an audit, it will be important not only to have adopted policies and procedures in place, but also to be able to demonstrate that the board acted with due diligence. Risk analysis reports, meeting minutes, budgetary decisions, incident logs, corrective action schedules and training certificates will all serve as evidence. Documentation in this area will therefore be the first step towards fulfilling the legal obligation, but not the last. The risk of sanctions encompasses not only penalties for the incident itself, but also the consequences of a lack of procedures, late reporting, incorrect classification of an entity, or failure to register.

Risk, incidents and the all-hazards approach

The new regulations require the use of measures proportionate to the risk, without specifying a single required product or supplier. The starting point should be an inventory of assets, the identification of threats, an assessment of probability and impact, and a risk management plan. Of particular importance is defining the entity’s risk appetite, i.e. the level of service disruption, data loss or financial loss that the entity is prepared to accept.

However, the NIS2 Directive takes a broader view of information security. An ‘all-hazards’ approach requires that risk assessments and operational procedures take into account not only cyber-attacks, but also technical failures, human error, fires, power cuts, the unavailability of key personnel, and supply chain issues.

Effective protection against risks requires the preparation of an information security policy, incident response procedures, business continuity and disaster recovery plans, and rules for performing and testing backups.

It is worth noting that, under the new regulation, every serious incident must be promptly detected, classified, documented and reported within the relevant timeframes, including a 24-hour report, a 72-hour report and a final report following an in-depth analysis.

The supply chain as an area of legal liability

NIS2 significantly strengthens the importance of supplier oversight. A regulated entity cannot limit itself to its own infrastructure if key processes depend on a cloud, software or hosting provider, a system maintenance provider, or a data processing subcontractor. Contracts should set out minimum security measures, information obligations, incident reporting, auditing, SLA levels, access to data and the procedure for terminating the relationship. The NIS2 Directive goes further than previous regulations in this area and means that a supplier’s operational risk can become a regulatory risk for the contracting authority, thereby making the entire supply chain more secure.

Conclusion

The correct implementation of NIS2 should take place in stages. This requires the organisation’s eligibility assessment, an initial audit, a risk analysis, management decisions, documentation, technical and organisational measures, training and testing. In the event of an inspection, the most important thing is to demonstrate that the organisation is aware of its obligations, manages risk proactively and is able to trace the decision-making process. The NIS2 Directive makes cybersecurity an essential part of running a business.

 

Authors

Katarzyna Hiller, legal adviser

Dorota Brzęk, trainee legal adviser

Author

Katarzyna Hiller

Partner, Attorney at Law, Compliance Officer, LL.M. in International Commercial Law

Katarzyna Hiller

related posts

All