Overview of the NIS 2 Directive
The NIS-2 Directivewhich entered into force on October 17, 2024builds on the original NIS Directive from 2016 and significantly expands its scope. It concerns Public and private companies in the EU that provide services - in particular companies with more than 50 employees and an annual turnover of more than 10 million euros. The new regulation focuses on companies that are part of the critical infrastructure (KRITIS). These companies play a crucial role in public safety and the functioning of society, which is why their failure could have serious consequences. In addition, the NIS 2 Directive now extends its scope to other "essential" and "important" facilities. The relevant sectors and areas are illustrated in the following diagram.1

A The central element of the directive is the Risk management for cyber security. Companies must take technical, operational and organizational measures to minimize security risks and prevent incidents. It is particularly important to consider the supply chain, as potential vulnerabilities can arise not only within the company, but also with partners or suppliers.2
NIS-2 in focus: What companies need to know now
In Germany, around 30,000 to 40,000 companies will be affected by the NIS 2 Directive in the future. For these companies, this means introducing comprehensive measures in the areas of risk management, security incident management and documentation. The specific steps that affected companies should take include3
- Examination of the impactCompanies must clarify whether they fall under the scope of NIS-2. For this purpose, platforms such as bund.de can be used to obtain an initial assessment.
- Introduction of risk managementIt is important to identify the critical systems and processes and to include the entire supply chain in the analysis.
- Documentation and reporting channelsCompanies must establish clear reporting channels and document the security measures introduced in order to comply with reporting obligations.
- Coordination with service providers and authoritiesCooperation with IT service providers and industry associations is essential in order to identify the need for security technologies and stay informed about industry-specific developments.
IoT and NIS-2: requirements and measures for cyber security
The NIS 2 directive brings significant requirements for companies that offer IoT services. Particularly in critical sectors such as energy, healthcare or finance, IoT systems must be designed in such a way that they comply with cybersecurity requirements. The NIS 2 Directive places specific requirements on IoT projects, which include both technical and organizational measures.4
Technical measures:
- Secure architecture: A secure IoT architecture that takes data protection and security standards such as security by design and security by default into account must be developed as early as the planning phase.
- Strong encryption: Communication between IoT devices should be secured with modern encryption protocols (e.g. TLS) to protect data from manipulation and eavesdropping attempts.
- Access controls: Strict authentication and authorization (e.g. through multi-factor authentication) is essential to prevent unauthorized access to devices and networks.
Organizational Measures:
- Risk management: Companies must regularly assess security risks and initiate appropriate protective measures. This applies in particular to networked devices in critical infrastructures.
- Reporting obligations: Security incidents must be reported immediately to the relevant authorities so that they can be responded to quickly. In addition, all incidents must be carefully logged.
- Penetration tests and audits: These measures are crucial for identifying vulnerabilities, reviewing the security situation and ensuring continuous improvements in security processes.
NIS-2 in practice: How to make IoT projects secure and compliant
The implementation of IoT projects offers companies the opportunity to meet the requirements of the NIS 2 directive. Targeted measures can minimize security risks and strengthen the security of the IT infrastructure.
Edge
- Secure device configuration → Devices should be configured with secure default passwords that are changed immediately. Regular Software updates are essential.
- Access permissions → Implement strict access permissions to ensure that only authorized users can access IoT devices
- Data encryption → Encryption of sensitive data both during transmission and at rest to prevent unauthorized access
- Network segmentation → Separation of IoT devices and critical IT systems using VLANs or firewalls to minimize security risks
Cloud
- Access controls → Use of multi-factor authentication (MFA) to prevent unauthorized access to cloud services
- Security standards → Implementation of recognized standards such as ISO/IEC 27001 (requirements for an information security management system) or ISO/IEC 62443 (specific security requirements for industrial automation and control systems)5
Comprehensive
- Zero-trust approach → Every device and every user is considered a potential risk, which requires strict authentication procedures
- Regular risk analysis → Carry out regular analyses to identify and assess potential vulnerabilities in the IoT infrastructure
- Develop incident response strategy → Companies must be prepared for security incidents and develop appropriate response strategies, including emergency plans and employee training
Conclusion: The NIS-2 directive as an opportunity for greater security and a competitive advantage
The NIS 2 Directive brings with it significant cyber security requirements, but also opportunities for companies that act early. Those who are able to offer comprehensive security solutions that cover both technological and organizational aspects can position themselves as a reliable partner in the implementation of the directive. Ultimately, the NIS 2 Directive will permanently change the cyber security landscape in Europe - and companies that adapt to the new requirements at an early stage will benefit from this. benefit.
Co-author: Niclas Wölfle



