Phil Lee’s Post

View profile for Phil Lee, graphic

Managing Director, Digiphile - Data advice that is Simple. Strategic. Actionable.

A couple of days ago, I posted about incident reporting rules under the AI Act but, as Carey Lening, CDPP pointed out in a comment, it’s just one of a suite of new EU laws with incident reporting requirements. There’s also #NIS2, which - from October - will impose its own cyber threat and incident reporting requirements. If you’re looking to understand those a bit better, then check out this excellent post from Digiphile’s Marco Piana 👇

View organization page for Digiphile, graphic

3,873 followers

Today’s post is a deep dive into the key requirements of #NIS2 and how they impact your business. 🔐 Cybersecurity 🔐 #NIS2 mandates a comprehensive risk management strategy that requires Essential and Important entities to assess cyber risks, run cybersecurity audits, have a business continuity plan to mitigate potential disruptions, verify the security of their supply chain, and much more. 📣 Incident reporting 📣 #NIS2 requires Essential and Important entities to be on the lookout for ‘significant incidents’ and ‘cyber threats’. The former must be reported to competent authorities within 24h by submitting an early warning, and from there there is a strict timeline to follow to keep the authorities apprised. 📬 Customer Notifications 📬 #NIS2 also requires to promptly inform their customers of both significant incidents and cyberthreats without undue delay. If you’re new to #NIS2, then be sure to also check out our earlier #NIS2 posts, which provide a brief overview of #NIS2 and its aims here: https://lnkd.in/eMkkWt8C and explain the types of entities it applies to here: https://lnkd.in/eJRyP6P5 Thanks to our #NIS2 expert Marco Piana for his insights in preparing this post!

Openly

Like
Reply

To view or add a comment, sign in

Explore topics