The EU NIS Directive: In case you missed it...
In all the publicity leading up to GDPR across the EU last year, you may have missed the introduction of another EU-wide cyber-security initiative that came into force on the 9th of May 2018. It is the EU Network and Information Security directive (NIS), and it is the first EU-wide cyber-security measure designed to enhance cyber-security across all member states. As citizens data can move freely within the EU, it is essential that all member states operate at an agreed level of cyber-security.
What Does NIS cover?
Whereas GDPR focused on the proper handling and protection of EU citizens data, the NIS is part of the EU Digital Single Market and is focused on raising the overall security of essential information systems. With no focus on specifics like GDPR, but to increase the security across the board.
NIS has three areas of focus:
- Ensure that national capabilities are in place for all EU member states and that they are adequate. Each member state has to have a framework in place to oversee the implementation of the NIS directive and manage cyber-security incidents that have a broad impact. This has to include a Computer Security Incident Response Team (CSIRT), and a national NIS competent authority. In Ireland, the authority is The National Cyber Security Centre (NCSC), and in the UK it is a separate body with the same name. Each agency also provides a single point of contact for any NIS related queries and is tasked with submitting reports and statistics on incidents.
- Setup cross-border cooperation bodies and mechanisms to ensure the flow of knowledge. This is a network that brings together each national CSIRT to promote cross border action and swift responses to any emerging cyber-attacks and threats.
- Ensure that the cyber-security for sectors designated as critical is in place and kept up to date. Critical areas include energy generation and distribution, public transport systems, water distribution systems, public healthcare delivery, and finance systems. Recognising the digital world we all now live in the core internet infrastructure components that provide the backbone for the networks within member states and across the EU are also designated as critical: Internet exchange points, core network links, DNS systems, and large Cloud Service providers.
Who does NIS apply to?
There are two main areas that NIS covers. They are:
- Operators of Essential Services (OES) - providers who deliver energy services, water services, healthcare services, transport networks, and digital infrastructure providers.
- Digital Service Providers (DSP) - includes three groupings: online search engines, online marketplaces, and Cloud computing providers. Small DSPs (who employ less than 50 people and with turnover less than €10M are excluded).
That’s a pretty wide net that covers a lot of public and private sector organisations who provide these services across the EU. All organisations covered by the NIS directive are required to:
- Implement necessary and appropriate cyber-security protections for their network and information systems.
- Ensure continuity of service by having proper measures in place to respond to any cyber-attack incidents.
- Notify their CSIRT of any security incident that has a significant impact on any of the designated essential sectors. This has to be done no later than 72 hours after an incident has occurred.
For organisations that are Operators of Essential Services (OES) under NIS, then the following factors feed into whether they need to declare an incident significant enough to notify. Consultation with the relevant CSIRT would be prudent to ensure alignment on what significant means:
- The number of people affected by any disruption.
- The duration of the interruption.
- The geographical area that the outage will impact.
Digital Service Providers (DSPs) designated under NIS need to report a significant incident if any of the following apply:
- Service availability is disrupted for more than 5 million combined service hours. Across all users.
- If more than 100,000 users suffer a loss of confidentiality, integrity, availability, or authenticity of their data.
- There is a risk to public safety, security or life.
- Material damage to at least one user that is greater than €1M.
OES compliance with NIS is monitored via audits by each member states designated authority, which then reports to the central EU NIS body. DSP’s are not audited, but they are investigated if there are any incidents they need to report.
Penalties for NIS non-compliance
Unlike GDPR, the penalties for a compliance breach under NIS are not set at the EU level, but rather the sanctions are passed back to each national regulator to set. The UK has set a maximum fine of £17M or 4% of turnover for severe breaches. In Ireland, the regulations say that an individual can be fined a maximum of €50,000, and in the case of non-individuals, the maximum fine is €500,000.
In addition to any financial penalties incurred, there will also be reputational damage to any organisation that has to report an incident.
Conclusion
NIS is a welcome initiative that will harmonise and raise the level of cyber-security preparedness in essential physical and virtual infrastructure providers. Most organisations who provide these essential services should have robust and current cyber-security protections in place already.
However, the threat landscape is constantly changing and staying up to date with emerging threats and changing best practice is a full-time activity - what you thought was once secured in your industrial or critical infrastructure environment may indeed have new threats that you were unaware of.
Renaissance and our industry-leading partners such as Indegy are ideally placed to ensure all types of organisations stay up to date with their cyber-security provision, and thus meet the compliance requirements of NIS and other EU and national security directives. Join Indegy on the 25th of June at 5pm for the How Healthy Is Your OT Environment webinar to gain control of your industrial or critical infrastructure, more details and registration Here.

