24/7 incident response phone: 24/7 incident response · +34 902 540 891

NIS2 applied to the plant

EU Directive 2022/2555 dramatically expands both the companies in scope and what is required of them. If you operate in energy, chemicals, water, food, transport or manufacturing, it will most likely affect you.

NIS2 classifies organisations as essential or important according to their sector and size, and imposes almost the same requirements on both; the supervisory regime and maximum penalties differ. The sectors listed in its annexes cover most process and manufacturing industries from medium-sized enterprises upwards.

Two features set it apart from everything before it. First, management is accountable: it must approve and oversee the measures and receive training; Article 20 allows personal liability to be enforced. Second, reporting deadlines are fixed and short, and begin when the organisation becomes aware of an incident, not when it fully understands it.

NIS2 · Requirements from an OT perspective
RequirementWhat it means in OT
Art. 21.1 — Risk managementThe risk analysis must also cover the control network, which requires something almost no one has: an accurate inventory of OT assets and their connections.
Art. 21.2.a — Risk analysis and information system security policiesPolicies that explicitly name control systems, rather than generic “information systems”. A procedure that ignores PLCs does not cover the plant.
Art. 21.2.b — Incident handlingA response plan that knows what can and cannot be isolated. Containment without process awareness may cause more damage than the attack.
Art. 21.2.c — Business continuity and backupsIndustrial backups too: PLC configurations, SCADA projects and recipes. Restoring the ERP will not restart the plant.
Art. 21.2.d — Supply-chain securityIntegrators and manufacturers with remote access to your plant form part of your risk. You need to know who connects, how and with which permissions.
Art. 21.2.e — Security in acquisition and developmentRequire security specifications when purchasing a new control system; once it is commissioned, remediation costs ten times more.
Art. 21.2.f — Assessment of effectivenessHaving measures is not enough: they must be tested. Audits, technical tests and exercises, with evidence that they were performed.
Art. 21.2.g — Cyber hygiene and trainingTraining for operations and maintenance too, not only office staff. The contractor technician brings the USB drive through the plant door.
Art. 21.2.h/i — Cryptography and access controlMFA for remote OT access and named accounts wherever possible. The shared “maintenance” account with a password from 2009 is incompatible with this.
Art. 23 — Incident reportingEarly warning to the authority within 24 hours, notification within 72 hours and a final report within one month. Without OT detection and assigned owners, these deadlines cannot be met.
Art. 20 — Management accountability and trainingManagement bodies approve the measures, oversee their implementation and must receive training. Non-compliance may result in personal liability.
Arts. 32–36 — Supervision and penaltiesFines of up to €10 million or 2% of global turnover for essential entities (€7 million or 1.4% for important entities), in addition to inspection powers.
How to address it

There is no “NIS2 product”. Compliance comes from structured work, and almost everything the directive requires in OT corresponds to services we already provide:

  • OT assessment — the Article 21 risk analysis begins with knowing what is there.
  • IT/OT segmentation — the most significant technical measure in Article 21.2 and the first one auditors examine.
  • Managed IT/OT services — without detection, there is no way to discover an incident in time to report it.
  • IT and OT incident response — playbooks, process-aware containment and readiness for the Article 23 deadlines.
  • Training — including the training Article 20 requires for management bodies.
Titanium · Legal information
Titanium · Legal information
Titanium · Legal information