What are the implications of the new NIS2 directive for us? Is our company ready for NIS2? What steps do we need to take to comply with NIS2? Who will coordinate our preparation for the first NIS2 audit?
These are among the most frequently asked questions about the new rules concerning cybersecurity supervision and certification. Through our NIS2 consultancy service, will determine your company’s current level of preparedness and advise you on the necessary actions to take.
We prepare a NIS2 GAP analysis of your company
As a first step, we prepare an analysis that will give you an accurate picture of the areas that need to be improved to meet the requirements of the NIS2 cybersecurity audits that are mandatory from 2025. Our analysis will help you to accurately and responsibly identify the short-, medium- and long-term actions needed to achieve this. In addition, the analysis also provides significant assistance in obtaining stakeholder engagement.
We coordinate your preparations
To meet NIS2 requirements, but more fundamentally to operate more securely in IT, you need not only technology, but also people. The chief information security officer (CISO) is one of the key players in the preparation process. He or she is the person who coordinates NIS2 compliance at the highest level and, in doing so, increases the cybersecurity resilience of your company.
CISO as-a-service, provided by us, can be a solution for those who do not have the skills, experience or capacity in-house to fill the position. Outsourcing the tasks of the chief information security officer is a quick and cost-effective solution that also reduces the risk of dependence on a single person.
Why choose our NIS2 consultancy service?
Anyone who fails to meet the requirements of the new NIS2 cybersecurity directive could face significant penalties. The penalty can be as high as 2% of the annual turnover, and can even result in a ban on the company and its management from engaging in relevant activities.
Want to know more about our NIS2 consultancy service? Click to make an appointment with one of our experts!With decades of experience and international expertise, we provide services to our clients based on Grant Thornton International’s quality assurance and information security framework and methodologies.
We would be happy to discuss with you the legal, organisational and technological aspects of the new rules.
To whom do we recommend our NIS2 consultancy service?
Companies that fall under the scope of the law are those that provide essential or critical services to society and other business stakeholders. Companies with more than 50 employees or an annual turnover of more than EUR 10 million (approx. HUF 3.9 billion) in specific sectors are covered.
Which companies are subject to NIS2?
The NIS2 rules apply to state and public administration bodies, as well as large and medium-sized private companies, as defined in detail in the law.
Sectors of high criticality
- Electricity
- District heating and cooling
- Establishment and operation of hydrocarbon (petroleum) transmission pipelines
- Operation of petroleum processing or storage facility
- Stockholding of imported petroleum and petroleum products
- Natural gas marketing
- Hydrogen production, storage and transport
- Air transport
- Rail transport
- Water transport
- Operation of road transport system
- Public transport
- Healthcare service
- Operation of high security biological laboratories
- Managing healthcare reserves and blood supplies
- Research and development of pharmaceuticals
- Manufacturing of basic pharmaceutical products and pharmaceutical preparations
- Wholesale distribution of pharmaceuticals
- Manufacturing medical devices of critical importance
- Wholesale distribution of medicinal products for human use
- Water utility services
- Communications services
- Digital infrastructure service (cloud, domain, DNS)
- Outsourced ICT services
- Space-based services
Other critical sectors
- Postal and courier services
- Production, processing and distribution of food
- Waste management
- Manufacture, production and distribution of chemicals
- Manufacture of medical devices and in vitro diagnostic medical devices
- Manufacture of computer, electronic and optical products
- Manufacture of electrical equipment (Sector 28 in Regulation (EEC) No 3037/90)
- Manufacture of motor vehicles, trailers and semi-trailers
- Manufacture of machinery and equipment not elsewhere classified
- Manufacture of other transport equipment
- Manufacture of cement, lime and plaster
- Online marketplace service
- Digital search service
- Provision of social media service platform
- Domain name registration service
- Research site
Related Services
NIS2 mentoring
NIS2 mentoring is designed to support the responsible managers’ professional preparedness and effectiveness.
NIS2 GAP analysis
Comprehensive analysis and action plan to prepare to comply with the requirements.
NIS2 pre-audit
NIS2 internal audits are always conducted by a support team within the company.