ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The final countdown to NIS2

Paul Wild at Daisy Corporate Services describes how to prepare your business for NIS2

 

As businesses plan for 2025, cyber-resilience remains at the top of the agenda for many. Recent research shows that 71% of UK organisations believe cyber-security threats are the biggest networking challenge they currently face. As rapid technological advances like AI accelerate the rate of attacks, it’s no surprise that regulatory bodies are taking action to keep businesses protected.

 

To ensure businesses are equipped to handle increasing security threats, the European Union (EU) is introducing the Network and Information Security 2 (NIS2) Directive. NIS2 builds on its legislative predecessor, NIS, by encompassing more businesses in its scope to raise the regulatory level across Europe. The EU has set the compliance deadline for January 17, 2025, meaning organisations must now prioritise their preparation to ensure they can achieve compliance.

 

NIS2 – the key details

The regulation will apply to both businesses inside the EU, and non-EU businesses that provide services within the EU. A particular focus of the directive is to increase the cyber-resilience of critical sectors such as energy, transport, healthcare and digital infrastructure. Stringent supervisory measures, strengthened security requirements and streamlined reporting obligations will also be introduced to bolster supply chain security across these key sectors.

 

To ensure the directive is adopted by businesses, the EU will introduce financial fines and legal implications for non-compliance. From the deadline, non-compliance with NIS2 could result in fines of over £8 million, or 2% of the total worldwide annual turnover of the preceding financial year. Senior management could also be held personally accountable for failures in compliance, adding another layer of risk for UK businesses.

 

With significant financial ramifications looming, understanding how to begin the compliance process will be the key to success for businesses in the coming year.

 

Comply with confidence

To achieve cyber-resilience and regulatory compliance ahead of the directive’s deadline, businesses should start by focusing on three key areas: 

  1. Understand your risks: businesses should first look to adopt a risk-based approach, comprehensively understanding their assets and the threats they face, then implementing countermeasures appropriate to their own risk profile. Countermeasures such as multi-factor authentication, continuous threat monitoring, regular patching and vulnerability management are key, alongside effective processes to detect, respond to and manage incidents.
  2. Invest in employees: secondly, business leaders must begin to foster a security-first culture by educating employees on potential threats like phishing and social engineering, as human error often plays a significant role in breaches.
  3. Fortify, back up, bounce back: businesses should then look to secure their supply chain, regularly back up and test the restoration of critical data/systems, and engage in continuous improvement to adapt to the evolving threat landscape. By focusing on both prevention and response, businesses can enhance their overall resilience and minimise the impact of potential cyber-attacks.

 

Future-proof cyber-security

NIS2 compliance shouldn’t be treated as a one-off, tick-box exercise, but rather a continuous evolution and improvement of a business’s cyber-resilience. Without it, businesses put themselves at risk of costly fines and significant reputational damage.

 

By ensuring compliance with NIS2, businesses will be able to put their best foot forward and help to mitigate against potential security threats both now and in the future. 

 


 

Paul Wild is Cyber Assurance Resourcing and Product Manager at Daisy Corporate Services

 

Main image courtesy of iStockPhoto.com and designer491


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543