NIS2 and KRITIS: who actually falls under the new EU security rules
The EU’s NIS2 directive and Germany’s KRITIS rules cast a much wider net than many decision-makers assume. It’s no longer just power utilities and large data centres: hospitals, emergency services and plenty of mid-sized suppliers now have to bring their IT security up to the required level.
Organisations in scope must run proper risk management, report incidents within tight deadlines and keep an eye on the security of their supply chain. Management is personally liable for compliance — a detail that is getting boardrooms moving.
Smaller companies should check whether they are indirectly affected as a service provider to a regulated business. These obligations tend to travel down the supply chain through contracts.
Source:
heise online