Analysis, strategy, and implementation
PwC’s team of cybersecurity, legal, digitization, and other specialists will help you meet all your NIS2-related obligations, including security, legal analysis, strategy, financing, design, and implementation. We can also provide outsourcing of information security management system (ISMS) operation and employee training.
NIS2 is the updated version of the EU Network and Information Security Directive issued in 2016. It significantly extends the scope of the current legislation and is designed to strengthen and secure European cyberspace. EU member states are obliged to transpose this directive into national legislation.
On 30 May 2024, the Slovak National Security Agency initiated an interdepartmental commenting procedure for the submitted draft amendment to the Cybersecurity Act. This amendment is transposing NIS2 into Slovak law. The amendment is effective from 1 January 2025. Currently, the Ordinance on Security Measures is being prepared, and its effectiveness is expected from 1 July 2025.
NIS2 identifies 18 sectors of the economy (compared to 7 sectors in NIS1), whose entities (private or public) will be required to implement enhanced cybersecurity requirements. The new sectors include, among others:
electronic communications providers
food sector
electronic communications providers
public administration entitie
waste management
manufacturers, e.g., of computers
chemical manufacturers
NIS2 takes a proactive approach to risk management. Essential and important entities are required to implement appropriate security policies to ensure systematic and in-depth risk analysis. These policies should be based on an all-hazard approach, considering all possible risks, including those related to physical security. Risk management measures (technical, operational, and organizational) should be proportionate to the assessed risk. Monitoring and responding to potential threats must cover at least the following areas:
NIS2 will increase the level of security not only in the ‘VIP club” environment, but also as regards the most significant elements of national infrastructure and services. The amended act will apply to new regulated entities and will also extend the scope of the law to a greater number of systems and services within organizations already subject to the current act effective since 2018.
Regulated service areas include public administration, power, manufacturing, food, and chemical industries, water and waste management, rail, water, and road transport, digital infrastructure and digital services, financial markets, healthcare, science, research and education, postal services, and military and space industries.
Similar to the current act, the draft amendment to the Cybersecurity Act is based on the internationally recognized standards of the ISO 27000 family, so only a few new concepts and measures are introduced which would not be standard at most companies.
Team of PwC’s cybersecurity experts, lawyers from PwC Legal and public sector specialists will provide you with a complete package of services to meet your NIS2 obligations.
To handle the impacts of NIS2 requirements on a company’s operation, PwC recommends the following approach:
We will help you analyse your organization’s position as regards NIS2 requirements and identify the mode you fall under. We will do this by determining the scope of cybersecurity management in relation to the managed services we identify.
We will help you identify deficiencies as regards requirements and recommended corrective actions to ensure compliance.
We will help you analyse funding options for your organization from the EU subsidy programme.