How to be prepared for NIS2 directive
One of the most important changes is the expansion of the list of sectors in which companies are subject to stricter cybersecurity requirements. It is estimated that at least 22,000 Lithuanian companies operating in the energy, transport, banking, financial market infrastructure, healthcare, drinking water supply, wastewater treatment, digital infrastructure, public administration, space, food production, processing and distribution sectors will have to comply with NIS2. In addition, regardless of the sector, the directive will also affect all companies in our country with more than 50 employees and a turnover or assets exceeding EUR 10 million.
The Pareto principle will help
According to Marijus Strončikas, CEO of IT services company Altic IT, only about half of the companies affected by the directive have started preparing for NIS2 so far. "Preparations for the NIS2 directive can take from several months to a year, depending on the management's attitude towards security, the perception of risks to the activity and the current cybersecurity situation. However, the implementation of basic measures can be done much faster. Nevertheless, companies are not advised to look at the implementation of requirements only as a formality - NIS2 is a reminder that cybersecurity should become one of the main business priorities," says M. Strončikas. According to him, the Pareto principle also applies in the field of cybersecurity: by implementing 20% of the most important security measures, 80% of the most crytical cybersecurity issues and threats will be solved. Therefore, organizations preparing for NIS2 should start with basic steps.
"Companies should implement automated cybersecurity measures that will continuously scan the company's systems for vulnerabilities and help to 'patch' them. It is also necessary to ensure that regular backups of data are made to hard-to-reach and secure locations. Of course, organizations must ensure that software is regularly updated - it is often the 'holes' in software that become the gateway to internal company systems," notes M. Strončikas.
Hackers access to internal company systems can also be obtained due to employee negligence or carelessness. Therefore, companies must ensure that all passwords are managed centrally and that employees connect to company systems using a two-factor authentication system.
Read more: https://www.delfi.lt/verslo-poziuris/naujienos/ekspertai-pataria-kaip-pasiruosti-simet-isigaliosianciai-kibernetinio-saugumo-direktyvai-120000204