NIS2 multiplies the number of organisations subject to cybersecurity obligations and, for the first time, holds management personally liable. The effect on the contracting of cyber insurance is already being felt.

Who is included

The directive distinguishes essential and important entities and extends the scope to sectors that were previously excluded: waste management, food, manufacturing, postal services, chemical and digital providers, among others. The general threshold reaches medium-sized enterprises, so companies that had never considered a formal cybersecurity framework are now obligated.

The obligations that are most difficult to implement

Documented risk analysis, incident management, business continuity and backups, supply chain security, and training. The one that generates the most work in practice is supply chain: it requires evaluating and demanding guarantees from suppliers, something that most organisations had not formalised.

Notification in very short timeframes

Early warning within 24 hours, notification with initial assessment within 72 hours, and final report within a month. These timeframes coexist with those of the GDPR when personal data is involved. Without a written protocol and a pre-identified response team, meeting them during a real incident is practically impossible.

What changes in insurance

Two effects. First, the subscription questionnaire has become stricter: dual-factor authentication for remote access, immutable backups, and managed endpoint protection are now conditions for insurability, not a premium improvement. Second, the personal liability of management introduced by NIS2 reinforces the role of D&O alongside cyber insurance, as they are covers that respond to different claims.

Compartir