Harmonization with the EU regulatory framework no longer includes only the legal segment, but EU Regulations and Directives have introduced the practice of multidisciplinary work of several teams within the company that is obliged to be compliant. This includes the legal segment, process harmonization and technical-technological harmonization. The Boost team has a number of years of experience in managing projects that require a wide range of knowledge and skills and quality coordination of teams within the client’s system, as well as in working with their suppliers.

Some of the regulations that the Boost team does well are:

  • NIS2, CER and DORA (cyber regulations)
  • GDPR, UK-GDPR, AI Act, ePrivacy (privacy regulative)
  • Whistleblowing Compliance

 

EXAMPLE OF THE IMPLEMENTATION OF THE NIS2 REQUIREMENTS (EACH REGULATION DIFFERS IN THE DETAILS OF IMPLEMENTATION)

1) Determining the applicability of NIS2 and defining the scope

  • Determine whether NIS2 applies to your organization and whether you belong to the category of essential or important entities.
  • Define the scope of the deployment (organizational units, locations, information systems, networks, processes, services, and assets that fall within the scope).
  • Identify regulatory, contractual, and business requirements related to cybersecurity.
  • Identify critical business processes and services whose disruption or compromise could significantly impact the business.

2) Defining the project plan and project team

  • Define the project plan (deadlines, goals, responsibilities, resources, risks and expected results).
  • Appoint people responsible for cybersecurity management and implementation activity holders.
  • Ensure the involvement of management and key stakeholders in the process of implementing the request.
  • Educate the project team on the NIS2 requirements and obligations of the organization.
  • Assess the current compliance status (GAP analysis) in relation to NIS2 requirements.

3) Risk assessment and establishment of cybersecurity measures

  • Identify and assess risks related to information systems, business processes, and services.
  • Identify threats, vulnerabilities, and potential consequences of security incidents.
  • Define technical, organizational, and operational security measures to manage identified risks.
  • Establish processes for incident management, business continuity, and disaster recovery.
  • Define procedures for managing supplier and supply chain security.

4) Preparation and establishment of documentation

  • Create or update policies, procedures, plans, and guidelines related to cybersecurity.
  • Document risk, incident, business continuity, access management, and other relevant areas to manage your risks, incidents, business continuity.
  • Define the responsibilities, powers and obligations of key participants.
  • Ensure documentation, records, and change management.

5) Implementation of measures and employee education

  • Implement defined organizational and technical measures in business processes and information systems.
  • Conduct training and raising awareness of employees about cybersecurity and their responsibilities.
  • Organize regular safety drills, testing, and incident simulations as needed.
  • Ensure continuous monitoring of the effectiveness of the implemented measures and the level of security.

6) Monitoring, testing and incident reporting

  • Establish processes to detect, log, analyze, and resolve security incidents.
  • Define procedures for reporting incidents to competent authorities in accordance with applicable regulations.
  • Conduct regular checks, tests and analyses of the vulnerability of information systems.
  • Track performance indicators (KPIs), safety events, and implementation of corrective actions.

7) Internal review and evaluation of the management

  • Conduct an internal assessment of compliance with NIS2 requirements.
  • View the results of risk analyses, incidents, testing, and improvement activities.
  • Conduct an assessment of the management on the state of cybersecurity and the effectiveness of the implemented measures.
  • Define plans to further improve your cybersecurity management system.

 

Compliance assessment and regulatory oversight

Internal or external compliance assessment

  • Implementation of the assessment of compliance with NIS2 requirements and national legislation.
  • Verification of implemented security measures, processes and documentation.
  • Identification of deficiencies, non-conformities and opportunities for improvement.
  • Implementation of corrective actions according to the established findings.

Regulatory audit

  • The competent authority may carry out supervisions, inspections or require the submission of evidence of compliance.
  • The organisation shall be able to demonstrate the implementation of cybersecurity risk management measures.
  • If necessary, additional corrective actions shall be carried out and reports shall be submitted to the competent authorities.

Continuous Compliance

  • Conduct risk assessments and update security measures regularly.
  • Monitor changes in business, technologies, threats, and regulatory requirements.
  • Regularly educate employees and conduct awareness-raising activities.
  • Continuously monitor and improve cybersecurity management processes.
  • Conduct periodic resilience tests, incident management exercises, and system audits.

Timeframe, resources and costs (indicative)

  • Smaller organisations: 3-9 months; larger and more complex organisations: 6-18+ months.
  • Required resources: management, project team, IT and security experts, process owners, legal department, external consultants and security service providers as needed.
  • The costs depend on the size of the organization, the existing level of maturity, the required technological investments, and the scope of implementation.

The most common mistakes and what to avoid

  • Understanding NIS2 as a one-time project instead of a continuous cybersecurity management process.
  • Insufficient involvement of management and vaguely defined responsibilities.
  • Focus exclusively on technical measures while ignoring managerial and organizational requirements.
  • Incomplete risk assessment and failure to identify critical processes, systems and suppliers.
  • Insufficient employee education and lack of awareness raising activities.
  • Lack of effective procedures for managing and reporting security incidents.
  • Failure to carry out regular testing, controls and continuous improvement activities.

 

Note: Unlike ISO standards, NIS2 is not a certification scheme and does not end with the issuance of a certificate. The goal is to achieve and maintain compliance with legal requirements through continuous cyber risk management and demonstration of the application of appropriate security measures.