The NIS2 directive is unavoidable – by spring 2025, most German companies must secure themselves against IT attacks in accordance with the European cybersecurity regulation. Find out how easy it is with the ISMS in our Aeneis GRC software.
Why the NIS2 directive is critical for affected companies
The new European cybersecurity directive, NIS2, was originally scheduled to come into force in October 2024. This landmark regulation requires companies in the EU, as well as those doing business with EU member states, to implement comprehensive measures to improve their cyber defenses. The requirements are strict and aim to significantly reduce the risk of cyberattacks and raise the overall level of security.
The implementation date has been pushed back by a few months, according to the Federal Office for Information Security (BSI). Other sources point to spring 2025. For companies, this means they likely have until March at the latest to implement NIS2 requirements and ensure compliance. Is your company ready for NIS2?
In our webinar last June, we discussed how you can successfully implement these guidelines in your company. You can request the recording of the webinar here .
Increased responsibility for management
The new requirements of the NIS2 directive mean that companies must not only introduce stricter IT security measures but also face increased accountability for management. In the future, company leadership could be held directly liable if security breaches occur due to a lack of proper measures. This underscores the necessity of complying with the requirements of the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) and ensures that both executives and employees develop a deep understanding of the new requirements.
Surprisingly, a study by Zscaler showsas of June 2024, less than half of IT leaders believed their executive management fully grasped the scope and details of NIS2. The situation is similar among employees: only slightly more than half are clear about their responsibilities. This lack of understanding can lead to serious security risks that not only endanger the affected companies but could also result in severe legal and financial consequences.
Do you understand the new NIS2 guidelines?
The same Zscaler survey also found that 62 percent of companies felt the new NIS2 directive deviates significantly from their previous security approaches. This perception is surprising, as the new directive is merely an extension of the existing NIS framework. These results suggest that many organizations have not invested sufficiently in modern security technologies to date. Zscaler and heise.de point out that numerous companies may only be implementing basic security measures.
For affected companies, this is a warning sign. Security incidents are no longer a rarity in the digital economy, and compliance with the NIS2 directive is crucial to minimizing the risk of such incidents.
To bridge these knowledge gaps, we hosted a free webinar that provides a sound introduction to best practices according to ISO 27001 and explains the specific requirements of the NIS2 directive. A special focus was placed on how IT security can be implemented in a way that is understandable and actionable for both executives and employees.
The recording of the webinar is now available for you to download for free. The content provides you with the necessary tools to elevate your corporate security to a new level and meet the requirements of NIS2.
What does cyber hygiene look like in your company?
According to the Zscaler survey, only 32 percent of the companies surveyed rated their current cyber hygiene as "excellent." To make matters worse, two-fifths of companies had not yet implemented a Zero Trust architecture, which is considered critical in today's digital landscape.
In view of this situation, we designed our webinar specifically to provide you with field-tested methods and templates that ensure security from day one. In the webinar recording, you can also learn about the importance of business continuity management, which prepares you as best as possible for emergencies.
Our goal is to help you strengthen your IT security strategies and effectively meet the requirements of NIS2.
Don't wait too long – get informed now!
The introduction of the NIS2 directive brings serious risks, especially if companies try to implement the requirements just before the deadline. Heavy fines await those who act too late. According to heise.de information security consultant Ulrich Plate emphasizes in an iX interview that more companies than previously assumed need to prepare adequately for the new regulation. Therefore, it is crucial that you act quickly to avoid legal consequences later on.
7 steps to implementing NIS2 requirements.
Download our free guide!
How an Information Security Management System (ISMS) can help meet the NIS2 directive
Before implementation, it is crucial to thoroughly understand the requirements of NIS2. An Information Security Management System (ISMS) aligned with the ISO 27001 standard provides an ideal foundation. This system is not just about meeting auditor expectations; it also drives the ongoing development of your company. By implementing a process-oriented management system, you ensure the sustainable protection of your IT landscape.
In our recorded webinar, we explored how risk management strengthens your security strategy through transparency and effective handling. We also discussed how process management and information security work together.
Master ISO 27001 and NIS2 with our free webinar recording!
Take the opportunity to learn all about the requirements of ISO 27001 and NIS2. You can access our free webinar recording, "Revolutionary Paths: Mastering ISO 27001 and NIS2," here to download.
The recording also includes the live Q&A session, where our experts answer questions from webinar participants. With our practical solutions, you can successfully master the challenges of the NIS2 directive.
Who is our webinar for?
Our free webinar is designed for the following target groups:
- Process managers and process owners
- Managing directors
- IT directors and IT managers
- Process consultants
Our webinar agenda
Our webinar covered the following topics:
- ISO 27001 best practices
- Key aspects of the NIS2 directive
- Process management and information security – how do they fit together?
- Employee-oriented IT security
- Protection from day one with proven methods & templates
- Risk management: Transparency & handling
- Securing operations in emergencies: The role of Business Continuity Management
These questions were answered:
- Which processes and IT systems are truly critical for your company?
- What are the benefits of a process-oriented ISMS approach?
- How do your employees benefit from the implementation of a risk management system?
- What should you do if something happens? What precautions can be taken?
- How can the NIS2 directive be easily implemented using the GRC and BPM software Aeneis?
As a bonus, you can also download the free guide to ISO 27001 here .
.avif)

