COMMUNICATIONS & NETWORKS
TAKE FOUR CYBER RESILIENCE STEPS
Chris Whyborn, Head of Cybersecurity Services (UK & Europe), TÜV SÜD Business Assurance, explains how to navigate the NIS2 Directive for network and information system security
O
rganisations across the EU must now meet the cybersecurity requirements of the European Directive – Network & Information Systems 2 (NIS2). UK-based companies are also
legally required to comply with NIS2 if they provide services within the EU. The Cyber Security and Resilience Bill (CSR) is set to become UK law in late 2026. Organisations that comply with the CSR are likely to have addressed a substantial proportion of NIS2 obligations. NIS2 requires businesses to protect their own systems, as well as assess supply chain risks. It splits businesses into two categories – “essential” or “important”. Essential entities are in sectors like energy, health and banking, while important entities include those such as waste management, postal services or manufacturing. Both must implement the same baseline security measures, but how regulators deal with them differs. Regulators have the power to regularly inspect and audit essential entities at any time, while important entities are only approached by regulators if they have evidence of non-compliance, an incident or complaint.
Whether they are considered essential or important entities, companies can take the following four cyber resilience steps:
1. Risk assessments and gap analysis Risk assessments and gap analysis reveal weaknesses in existing cybersecurity measures. The impact of data loss by a service provider or encryption of a specific system with ransomware is analysed. The differences between security measures and the ideal target state are identified, as well as an action plan address potential security risks. Companies can then focus resources on the most critical areas, optimise their cybersecurity investments, and minimise financial losses and reputational damage.
2. Cyber awareness
NIS2 emphasises accountability of senior management, who are expected to have an awareness of cybersecurity risks and enforce their treatment through processes, controls, documentation and training.
3. Supply chain Vulnerabilities in suppliers’ systems enables cybercriminals to exploit the supply chain. For example, the injection of malware into legitimate software updates can compromise third-party
18
providers with access to a company’s networks, resulting in an insider attack or infected hardware. Companies should therefore examine these interfaces and other possible points of entry so they are secured thoroughly. They must demonstrate that third parties with IT access are integrated into a robust security management system.
4. Building trust and continuous improvement Regular internal audits and penetration tests provide insight into emerging vulnerabilities, support ongoing regulatory compliance and improve incident response capabilities. They also offer a systematic way to adapt security practices and maintain effectiveness and resilience across different types of facilities. Any gaps and vulnerabilities that are discovered must be addressed immediately and company-specific guidelines and processes adapted.
International standards Internationally recognised cybersecurity standards ISO 27001 and IEC 62443 are a useful basis for NIS2 compliance. An information security management system (ISMS) certified according to ISO 27001 covers some of the key requirements of the NIS2 Directive, which must be supplemented by appropriate measures. The IEC 62443 series of
PROCESS & CONTROL ENGINEERING | SEPTEMBER 2026
standards cover all phases of industrial cybersecurity and underpin NIS2 in that environment.
Executive responsibility
A big shift in Management Responsibility and Accountability is reflected in NIS2. At its core, Article 20 requires that: • Management bodies approve cybersecurity risk management measures
• Management bodies oversee their implementation
• Management bodies can be held liable for failures • Management bodies must undertake cybersecurity training
Cohesive cybersecurity NIS2 is a significant step in a cohesive cybersecurity framework, with it its implications extending beyond the EU. Sound cybersecurity practice, the UK’s CSR and other international standards offer a practical starting point for a structured compliance path. Organisations that comply with NIS2 requirements will strengthen their resilience, build trust with stakeholders, and gain a competitive advantage in a cybersecurity- conscious marketplace.
TÜV SÜD Business Assurance
www.tuvsud.com/en-gb/cybersecurity
Page 1 |
Page 2 |
Page 3 |
Page 4 |
Page 5 |
Page 6 |
Page 7 |
Page 8 |
Page 9 |
Page 10 |
Page 11 |
Page 12 |
Page 13 |
Page 14 |
Page 15 |
Page 16 |
Page 17 |
Page 18 |
Page 19 |
Page 20 |
Page 21 |
Page 22 |
Page 23 |
Page 24 |
Page 25 |
Page 26 |
Page 27 |
Page 28 |
Page 29 |
Page 30 |
Page 31 |
Page 32 |
Page 33 |
Page 34 |
Page 35 |
Page 36 |
Page 37 |
Page 38 |
Page 39 |
Page 40 |
Page 41 |
Page 42 |
Page 43 |
Page 44