Scritto da Filadelfio Emanuele
NIS2 has officially come into force and imposes specific obligations on organizations operating in critical sectors to raise their level of security. In this article, we summarize the main technical and organizational guidelines that companies are required to follow.
In a continuously evolving geopolitical landscape, Europe’s cyber defense system must adapt and strengthen. In the digital world, there are no borders and no peace treaties: this is the context in which NIS2, the European directive on IT security requirements, operates. The directive aims to strengthen cyber defenses by introducing specific cybersecurity obligations for thousands of organizations operating in critical sectors across the European Union. Key sectors include energy, transportation, healthcare, manufacturing, digital infrastructure, and public administration.
Obbligations for Italian Companies
In Italy, the National Cybersecurity Agency is responsible for coordinating and overseeing the implementation of NIS2. It has the authority to conduct inspections and impose penalties of up to €10 million or 2% of annual global turnover.
2026 is the year in which the directive becomes fully operational: since January, it is mandatory to report significant incidents to ACN, while October marks the deadline for implementing the baseline compliance measures.
Let’s take a closer look at the guidelines established by the directive.
Organizational Strategy and Management
To ensure effective cybersecurity governance, it is essential to involve boards and senior executives and assign clearly defined responsibilities. Start by appointing a dedicated person with a formal mandate and direct access to top management. Establish roles and responsibilities within a supervisory committee that actively involves management in security-related decisions. This approach ensures that cybersecurity is not merely an IT department responsibility, but becomes an integral part of the company culture.
Incident response
Documenting the entire operational workflow is now mandatory. Among the information to be defined are who detects incidents, who makes decisions, and who is responsible for notifying ACN within the required 24-hour timeframe.
To ensure an effective response when needed, regularly test your incident management process through exercises and simulations before a real event occurs.
Security Awareness Culture
Employee training isOne factor that should not be overlooked when strengthening corporate defenses. Provide your staff with the tools needed to recognize and defend against phishing attacks through dedicated training programs and simulated phishing campaigns. Equal attention should be given to internal procedures and policies. Employee awareness is the first line of defense and an explicit requirement of NIS2.
La gestione delle identità
A stronger identity management is one of NIS2's key priorities. Recommended measures include implementing multi-factor authentication (MFA) across all critical systems and adopting centralized identity management solutions (IAM/PAM). In addition, particular attention should be paid to privileged access accounts, which must be continuously monitored, restricted where necessary, and promptly revoked when no longer required.
Continuous Monitoring
Continuously monitoring IT activities makes it possible to detect anomalies early and respond promptly to incidents. Collect and correlate security events through a SIEM platform, ideally managed by a 24/7 Security Operations Center (SOC). This should be complemented by an ongoing vulnerability management process, keeping in mind that what truly matters is remediating vulnerabilities—not simply identifying them.
Business Continuity and Disaster Recovery Plans
Business continuity and rapid recovery capabilities are explicit requirements of NIS2. Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for critical systems, regularly test backup procedures, and keep disaster recovery plans up to date.
Practical Recommendations for NIS2 Compliance
If your organization falls within the scope of NIS2, or if you are part of a regulated supply chain, adopt the “Start from where you are” approach:
-
Verify that your company’s registration process has been completed correctly and that clear points of contact have been designated to keep information up to date.
-
Conduct a gap analysis to identify existing security measures and develop a multi-year roadmap for improvement.
-
Launch training programs for board members and other key stakeholders, and establish a reporting framework to provide them with regular updates.
Rather than viewing NIS2 compliance solely as a legal obligation, consider it an opportunity to strengthen your organization’s cybersecurity posture. Investing in security practices, employee training, and continuous monitoring helps create a stronger and more secure European digital ecosystem.
And if you would like to explore the topic further, Elmec Vision offers a dedicated video focused on NIS2. Watch it here.