The Brief/Guide

NIS2: Key Points for Understanding the European Directive

The NIS2 Directive, a new European regulation, mandates vulnerability monitoring measures. Let's dig the implications!

Mickaël Walter
Logo de NIS2

Directive (EU) 2022/2555, better known as NIS2 (Network and Information Security 2), marks a revolution in the European cybersecurity regulatory landscape. Adopted on December 14, 2022, and published in the Official Journal of the European Union, it repeals and replaces the first NIS Directive to address evolving cyber threats and the limitations of its predecessor.

As cyberattacks become more frequent and information systems remain all too often vulnerable, NIS2 establishes an ambitious common framework to raise the level of cybersecurity throughout the European Union. Its goal is to protect essential services (energy, healthcare, transportation, etc.) and strengthen the resilience of critical infrastructure against increasingly organized malicious actors.

A Broader Scope: Many Organizations Are Affected

NIS2 significantly expands the scope of application compared to NIS1, moving from a limited sectoral scope to nearly comprehensive coverage of vital and strategic sectors. Eighteen sectors have thus been classified into two categories:

  • Highly critical sectors. For example: public administrations, energy, digital infrastructure;
  • Other critical sectors. For example: manufacturing, postal services, research.

In addition, NIS2 introduces a classification of entities based on their size and potential impact:

  • Essential entities: ≥ 250 employees or annual revenue > 50M€ and balance sheet total > 43M€;
  • Important entities: ≥ 50 employees or annual revenue/balance sheet total > €10 million.

This brings the number of entities subject to the regulation in the European Union from a few thousands to several tens of thousands.

Key Requirements Imposed by NIS2

NIS2 introduces three key requirements for affected entities.

Registration with the National Authority

Each Member State designates a competent national authority that maintains a registry of affected entities and intervenes in the event of cross-border incidents.

Any organization that meets the scope criteria must register with this authority.

Cyber Risk Management

All affected entities must implement cyber risk management processes. These measures apply at several levels: legal, organizational, and technical.

Incident Reporting

All affected organizations must report significant cyber incidents to the national authority and keep it informed of any developments in the situation.

Penalties and Oversight

NIS2 significantly strengthens penalties for noncompliance with obligations. The maximum amounts are:

  • Up to 2% of global revenue for essential entities;
  • Up to 1.4% of global revenue for important entities.

National authorities have supervisory powers and may impose corrective measures, such as compliance implementation subject to a penalty payment.

Implications for Vulnerability Management

Implementing active vulnerability monitoring is a prerequisite for essential entities and important entities. Implementing a comprehensive vulnerability management process is a prerequisite for critical entities.

Thus, all entities subject to NIS2 must establish a protocol for monitoring application vulnerabilities, particularly through national CSIRTs and CERTs or a service provider designated for this purpose. In the latter case, the service provider generally conducts an assessment and ongoing monitoring to enable the entity to adapt its response.

A Legal Obligation to Proactively Manage Vulnerabilities

This has a direct impact on vulnerability management.

Indeed, the monitoring and response requirements outlined in the framework necessitate a well-established process between security managers and digital infrastructure teams.

Depending on the nature of the vulnerability, the organization must:

  • Immediately: prepare to implement a patch or risk mitigation measures;
  • Without undue delay: implement the patch in its information system.

This requires a rigorous and documented process covering the entire lifecycle of a vulnerability:

  • Detection: Active monitoring of vulnerabilities (scanners and threat intelligence);
  • Assessment: Analysis of severity (CVSS, potential impact on services) and actual risk level;
  • Prioritization: Ranking by actual risk level;
  • Remediation: Application of patches or implementation of mitigating measures;
  • Follow-up: Verification of the effectiveness of patches and updating of systems.

The ReCyF requirements framework describes the obligation to monitor security intelligence feeds, which include, in particular, alerts from national CSIRTs. Our vulnerability intelligence layer, VulnPilot, automatically prioritizes vulnerabilities that are the subject of such alerts, such as those from CERT-FR:

A vulnerability sheet describing a vulnerability on WordPress and described as actively exploited by the CERT-FR national CSIRT

Contact us to learn how VulnPilot can help you ensure NIS2 compliance while strengthening your response to application vulnerabilities.


Proactivity is particularly important: authorities require rapid detection and action to address vulnerabilities before they are exploited by a threat actor.

Collaboration with CSIRTs and Authorities

NIS2 strengthens cooperation between private entities and public authorities.

Entities must collaborate with national CSIRTs (Computer Security Incident Response Teams) to report incidents to them. This process is formalized in three steps:

  • Early warning: To be sent within 24 hours of detection, this notifies the national CSIRT of an incident;
  • Incident notification: This must be sent within 72 hours and updates the information from the early alert as well as the indicators of compromise;
  • Incident report: This must be submitted within one month of detection and provide a detailed account of the incident’s progression and the resulting remediation measures.

It is clear that the level of detail in an incident report may involve disclosing details of the exploitation of zero-day vulnerabilities, if such exploitation occurred. It is therefore, among other things, a tool for European national CSIRTs to obtain privileged information regarding vulnerabilities unknown to the public as well as those being widely exploited.

We can therefore expect more comprehensive information at the European level regarding the extent to which vulnerabilities are being exploited. This is all the more true given that the NIS2 Directive provides for collaboration among Member State authorities and, consequently, the sharing of intelligence within a broader community.

Conversely, national CSIRTs can also cooperate with the relevant entities:

  • They may provide these entities with early warnings regarding a cyber incident;
  • They can assist the entities in incident response;
  • They may also, at the request of the relevant entity, scan the information system for significant vulnerabilities.

Conclusion

NIS2 imposes information security obligations on the entities concerned.

Among these is the obligation to establish a process for gathering intelligence on application vulnerabilities that goes beyond simply collecting vulnerability data. A thorough assessment of the actual risks to the information system is required.

Furthermore, NIS2 requires a high degree of responsiveness in the processes for applying patches and implementing risk-mitigation measures by introducing the concept of “unjustified delay”. These measures are in line with the “time-to-exploit” metrics now widely accepted.

Achieving compliance may represent a substantial undertaking for organizations that are currently ill-prepared, especially given the directive’s very broad scope. It is therefore advisable to plan ahead and not wait until the directive takes effect to implement these processes.

Share

Stay informed

Receive our latest articles and analyses directly in your inbox.

NIS2: Key Points for Understanding the European Directive | Sentibee