![Tiernan Connolly Tiernan Connolly](https://media-cdn.kroll.com/jssmedia/kroll-images/headshots/tiernan-connolly.png?h=160&iar=0&w=140&mw=384)
NIS2 replaces the original NIS Directive from 2016, which sought to set a high level of cybersecurity across critical infrastructure across the EU. NIS2 is an important update, with the original NIS directive considered to have limited scope and lack of consistency in its application by member states. NIS2 therefore includes an expanded scope of EU impacted entities and a wider supervisory and coordinated regime from member states which entities will need to register with.
Requirements | NIS Directive | NIS2 Directive |
---|---|---|
Risk Management Requirements | Required entities to implement "appropriate and proportionate" security measures | Imposes stricter requirements, focusing on:
|
Sectors in Scope |
| Expanded scope adding the following new sectors:
|
Reporting Requirements | Reports cyber incidents to national authorities within a reasonable timeframe |
|
Penalties | Allowed member states to set penalties for noncompliance |
|
Kroll has a long track record of working with organizations across critical infrastructure sectors, enabling them to achieve their security and regulatory goals across multiple jurisdictions. We leverage agile methodologies and accelerators and frontline intelligence from thousands of incident response cases a year, to provide support and prepare your organization to meet NIS2 requirements.
Gap assessment of your NIS2 compliance maturity against specific provisions highlighting key weaknesses and key recommendations.
Clear roadmap toward NIS2 compliance with priority tasks and key milestones.
An action tracker is also provided with recommended owners to help stakeholders in effective project management.
With our portfolio of advisory, transformation and managed services, we can assist you with the implementation of NIS2-aligned policies and procedures, controls and services such as incident management, business continuity, third-party risk management.
Our three-phased approach helps organizations of all sizes address any stage of NIS2 compliance:
As part of our gap assessment, we provide a clear risk rating against NIS2 requirements, whilst giving a quantitative measure of compliance status covering:
Governance
Cyber Risk Management
Reporting and Registering Articles
Off the back of the assessment, we provide you with a roadmap report along with an action tracker for effective project management including:
Having identified NIS2 compliance key gaps, Kroll can assist with senior advisory support with regards to compliance adherence of remediation initiatives such as:
Kroll can also support with the review and development of policies, procedures, reports, mappings and risk assessments, leveraging specially-tailored templates.
Our NIS2 Compliance Assessment, along with many other cybersecurity and compliance services, can be delivered as part of Kroll’s ultra-flexible Cyber Risk Retainer. In addition to prioritized access to Kroll’s elite digital forensics and incident response team ahead of and in the event of an incident, the Retainer can also be used for services like penetration testing, risk assessments and tabletop exercises, to name just a few.
Our team consists of experts who have designed and led numerous compliance audits at large multi-jurisdictional organizations, assessing and evaluating domains across cyber strategy, governance and procedural controls in the context of regulatory requirements and industry standards including ISO27001, COBIT and NIST, DORA, NIS2, SAMA CSF and more.
700+ skilled and certified cybersecurity experts across the globe, experienced in not only helping clients comply with multiple regulations but staying resilient ahead of the changing landscape.
Our solutions can address all aspects of NIS2 compliance and maturity; from assessing all possible gaps/weaknesses and advising on remediation with our consultancy expertise to implementing the right controls and services.
With unrivalled exposure to thousands of incident response cases each year, we know what’s needed to stay resilient to cyber threats.
We leverage our NIS2-tailored policies and procedures templates to provide immediate value as we roll out your tailored program.
Incident response, digital forensics, breach notification, security strategy, managed security services, discovery solutions, security transformation.
End-to-end governance, advisory and monitorship solutions to detect, mitigate and remediate security, legal, compliance and regulatory risk.
End-to-end governance, advisory and monitorship solutions to detect, mitigate, drive efficiencies and remediate operational, legal, compliance and regulatory risk.
Manage cyber risk and information security governance issues with Kroll’s defensible cyber security strategy framework.
Proactively identify your highest-risk exposures and address key gaps in your security posture. As the No. 1 Incident Response provider, Kroll leverages frontline intelligence from 3000+ IR cases a year with adversary intel from deep and dark web sources to discover unknown exposures and validate defenses.
Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.
Kroll is the largest global IR provider with experienced responders who can handle the entire security incident lifecycle.