Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Preparing For The Next European Union Directive: Eu Nis
Articles

Preparing For The Next European Union Directive: Eu Nis

ISBuzz TeamBy ISBuzz TeamJune 20, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It’s fair to say the General Data Protection Regulation (GDPR) has received attention in recent months. It’s only a matter of time until the first major breach occurs, and then we’ll see how things shake out from an enforcement standpoint. Meanwhile, there’s exciting news for compliance jockeys. Another directive from the European Parliament and the Council of the European Union is ramping up: Directive (EU) 2016/1148, also known as the “Directive on Security of Network and Information Systems (NIS).” The Directive was originally issued a few years ago and focused on measures for a “high common level of security of network and information systems across the Union.”

The effect the NIS Directive has on industry sectors is wide ranging, from energy and banking to air transport and drinking water suppliers. Implementation of the Directive is well underway. Key dates also extend out for nearly five years after the transposition. The 27 articles within the Directive are riddled with compulsory legal jargon and will likely not make the list of 2018 summer beach reads. However, the European Commission released a summarised memorandum highlighting the three core objectives:

  • Improved cybersecurity capabilities at the national level
  • Increased EU-level cooperation
  • Risk management and incident reporting obligations for operators of essential services and digital service providers

Improving Cyber Security at the National Level

Upon going through all of the various articles and definitions, the one word that continues to come to mind is access.  Per the NIS Directive, a security network and information system is defined by:

“..the ability of network and information systems to resist, at a given level of confidence, any action that compromises the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, those network and information systems..”

As organisations within the member states mould their security strategies to align to the Directive, incorporating the security and management of privileged access as part that strategy is critically important in the protection of networks and information systems. Unsecured secrets, privileged accounts and their associated credentials can provide an attacker with the ability to take complete control over an environment, disable systems and take down services that can impact an entire city’s population – hundreds of thousands of civilians – as shown in the Ukrainian power grid attack.

Placing controls on privileged users – both humans and machines – is a crucial step in mitigating risk against a security event that impacts critical services. Introducing the principle of least privilege, enforcing things such as multi-factor authentication and segregation of duties (SoD), and locking down the privileged access pathway to systems and applications are fundamental measures that can be implemented to resist the compromise of critical services and systems, upon which EU citizens and businesses rely.

Taking it one step further, the application of threat detection and analytics on privilege-related activity will help to prevent an attacker from comfortably navigating the network, performing reconnaissance and gaining access to the Domain Controllers where they can harvest the accounts and credentials that provide privileged access – which is exactly what the attackers did in the Ukrainian attack. Improving cyber security at the national level does not happen without the implementation of some of these security controls.

Cooperation amongst Union Member States

This part of the Directive is instrumental in successfully developing trust and confidence throughout the Union. This section defines a ‘Cooperation Group’ requiring member states to jointly implement planning, steering, share best practices, and report and assess the overall experience gained through cooperation. Of course, consistency in the interpretation of this legislation across all member states is ideal for success. The facilitation of cross-border communication and cooperation will be implemented more effectively if each member state is on the same page.

Member states such as France and Germany have already begun to release local legislation, while many others are slowly working out the final details before the transposition goes into national law later this year. Unlike GDPR, penalties for non-compliance will not be enforced at the EU level, rather directly from the member state, specifically they “shall be effective, proportionate, and dissuasive.”

In the recent CyberArk Threat Landscape Report, only about one-third of respondents from organizations based in France (29 percent) and Germany (33 percent) said they have an understanding of the Directive, which types of security incidents should be reported, and that their organisation currently meets local legislation.

Similarly with GDPR, these stats are a clear indicator that organisations are not fully prepared.  The likelihood of many organisations being in a comfortable state to avoid non-compliance may be bleak.

Risk Management and Incident Reporting

Digital Service Providers (DSPs) and operators of essential services will be required to put in place technical and organisational measures to prevent risk, ensure the level of security of the network of information systems is appropriate to said risk, and effectively handle incidents to prevent and minimise the impact on the IT systems used to deliver services.

Whether data and applications are cloud native, running in a traditional on-premises environment or a combination of the two, nefarious characters and nation-state attackers continue to find ways to compromise the infrastructure and gain access to top tier resources.  Some of the definitions within the Directive are deliberately ambiguous for local interpretation – but the one thing that remains crystal clear is the management and prevention of risk begins and ends with protecting access to an organisation’s most critical assets and resources.

Like GDPR, doing nothing in preparation for EU Directives is not only considered regulatory blasphemy, but it has the potential to result in serious reputational and financial repercussions.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}