The NIS2 Directive: why companies need to act now
From 17 October 2024 the new EU regulation also applies in Germany - with personal liability for management and fines of up to 10 million euros. Who is affected and what needs to happen now.
Cybersecurity was long a matter for the IT department. With the NIS2 Directive, that picture shifts fundamentally. From 17 October 2024 the new EU regulation also applies in Germany - and it affects far more companies than many currently assume.
A law that changes the rules of the game
What is special about it: responsibility no longer lies solely with specialists in the background. Managing directors and board members are directly obliged to act. Anyone who neglects security measures risks not only attacks, but also fines of up to 10 million euros.
Who is affected?
The directive is aimed at companies in critical sectors - from energy, health and finance through to transport, postal services, waste management and digital services. As a rule, businesses with more than 250 employees or more than 50 million euros in turnover are affected. However, smaller companies can also be included if they are part of a sensitive supply chain.
In other words: from autumn 2024, many German companies face entirely new security requirements.
What changes
NIS2 is not a "nice-to-have" but a mandatory programme. In future, companies will have to report security incidents within 24 hours, examine their supply chains closely and integrate cybersecurity into their processes from the outset.
Above all: management itself is responsible. Company leaders must not only sign off on security measures but actively monitor them. Anyone who is negligent here is personally liable.
Why waiting is risky
A breach of the directive can not only become expensive. It also endangers the trust of customers and partners. Increasingly, clients demand proof that their business partners are NIS2-compliant. Anyone who cannot provide it risks losing contracts and cooperations.
The directive therefore makes visible what has long been reality: cybersecurity is a competitive factor.
What companies should do now
The good news: there is still time to prepare. The first step is a clear stocktake. Where do we stand? What gaps are there? Which measures do we have to take by October 2024?
A structured audit uncovers these points and provides the basis for a roadmap. This makes it possible to define responsibilities, budgets and deadlines clearly - and companies are on the safe side before things get serious.
Sheriff Security helps companies in Germany implement the NIS2 requirements pragmatically and efficiently. From the first analysis through to the finished security concept.
Let us examine together how well prepared your company is. Arrange a no-obligation initial consultation now.
Conclusion: obligation and opportunity at the same time
The NIS2 Directive brings stricter rules and higher requirements. But it also opens up opportunities: those who act in good time demonstrate digital strength, gain trust and protect themselves against damage that goes far beyond financial penalties.
Frequently asked questions about the NIS2 Directive
What is the NIS2 Directive?
The NIS2 Directive (Network and Information Security 2) is an EU-wide requirement for higher cybersecurity standards. It obliges companies to implement technical and organisational measures in order to protect themselves better against cyberattacks.
When does the NIS2 Directive apply in Germany?
Germany must transpose the NIS2 Directive into national law by 17 October 2024. From that date, the companies concerned are obliged to comply with the requirements.
Which companies are affected by NIS2?
Medium-sized and large companies with 250 or more employees or more than 50 million euros in turnover are affected. This includes essential entities such as energy, health or finance, as well as important entities such as postal services, waste management, medical technology, electronics or digital services. Smaller companies can also be included if they are part of a critical supply chain.
What penalties apply for violations?
Companies that fail to meet the NIS2 requirements must expect substantial fines - up to 10 million euros or 2% of global annual turnover. In addition, management and board members face personal liability.
How can companies implement NIS2?
The first step is to take stock by means of an audit. This is followed by an action plan with responsibilities and deadlines. Sheriff Security supports this with hands-on solutions - from gap analysis and awareness training through to technical security concepts.
The Invisible Threat: AI Fraud in 2024
Read articleLet's talk about your security, before someone else does.
Request via a short form, prioritised and answered promptly.