Home / Business and Politics / What obligations and opportunities does the new NIS2 directive on cybersecurity bring for entrepreneurs

What obligations and opportunities does the new NIS2 directive on cybersecurity bring for entrepreneurs

The new Cybersecurity Act, aligned with the European Commission’s NIS2 Directive, will affect three to four times more companies in Croatia than has been the case so far, which means that entrepreneurs will need to invest more resources in ICT security. As business digitalization increases, so do the threats from cyberattacks, but in addition to adapting to the new law, it also means new opportunities for Croatian companies. As highlighted today during a panel discussion at the conference on the new law held at Algebra University, the increased demand for cybersecurity solutions will also boost demand for companies specializing in this area, presenting an opportunity for the development of the Croatian economy.

Investment will be necessary, but it is difficult to estimate how much, as it depends on how much individual companies have already invested in cybersecurity, said Boris Bajtl, Vice President of the Croatian Institute for Cybersecurity, Head of the Cybersecurity Department at Atos Croatia, and a member of the Executive Board of HUP-ICT. There is room for improvement in cybersecurity within companies even without investments, Bajtl noted, and economic opportunities include the creation of new jobs and drawing funds from EU sources.

– The new law will increase demand for these services, which will automatically increase supply, and that is an opportunity – said Bajtl, adding that the Croatian Employers’ Association will be involved in consulting during the drafting of regulations, thus having the opportunity to convey employers’ requirements and participate in that process.

Market Gap

Compliance audits with NIS2 laws will be conducted by legal entities approved for this purpose, explained Dr. Aleksandar Klaić from the Cybersecurity Center of the Security and Intelligence Agency (SOA), referring to hundreds of entities and a large number of such activities for all companies that decide to go in that direction. All companies in the ICT sector will have to comply with the NIS 2 law, regardless of size, and they also have an additional opportunity to certify their cybersecurity services in a certain way and apply them as such through the EU register not only in Croatia but also beyond.

– This is a significant change because today you cannot offer these services in a standardized way as they do not exist – Klaić explained, adding that compliance with the NIS2 directive will also bring better competitiveness in tenders for EU funding.

– At the EU level, there are not many companies that can provide advanced services, and this area is relatively free both at the level of large and small states – Klaić said.

image

Aleksandar Klaić, SOA

Companies will gradually implement the directive, Klaić noted, and the entire process should take place over a year from the adoption of the law.

– Only upon receiving notifications should individual entities from any sector take action and align their cybersecurity systems, for which they have one year. Thus, in that notification, entities will also receive technical information – Klaić added.

Companies and state bodies that already apply the ISO/IEC 27001 international standard for information security management will be at an advantage as they will have little to adjust according to NIS 2.

– In any case, all those who implement some standard, whether it is an industrial or business security standard, will be at a certain advantage because a large number of things will be adjusted and organized by the time they are obligated to do so – Klaić explained, adding that each employer will conduct a cybersecurity risk assessment on three levels – management, independent audits, and oversight.

New Technologies as an Additional Reason for Caution

Every new technology can be used for good, but also for bad, noted Marko Gulan, a cybersecurity consultant at Schneider Electric SEE. Artificial intelligence tools, Gulan warned, can tell you what to do to break into a system, not directly, but if you ask them what you need to do to avoid being a victim, you get the answer in reverse. However, attacks do not come only from the internet but also through deep fake technology, so companies must be cautious about who they allow access to their systems, Gulan warned, who is convinced that Croatia can effectively implement new regulations and thus strengthen the economy and make it more resilient.

Regarding Croatian banks, the money of Croatian savers is safe, emphasized Milan Parat, Chairman of the Security Committee of the Croatian Banking Association, as all banks were obligated to the NIS 1 directive and will be obligated to the NIS 2 directive, but not much will change except that the security of financial institutions in Croatia will be further enhanced.

– Banks strive to prevent fraud. They have systems for monitoring unusual transactions and prevent the vast majority of those transactions, and users need to report unusual transactions as soon as possible – Parat said, noting that banking processes are highly digitalized, so digital money will not bring significant changes, but it is an additional reason to increase investments in cybersecurity.

People are Key

Food production is not exempt from cyberattacks, said Dario Rajn, Chief Information Security Officer at Podravka, noting that companies are divided into those that have been attacked and those that will be.

– Digitalization is something we cannot avoid. With every investment in production lines, we expose ourselves more and more. Today, the production line monitors efficiency and is connected to the ERP system that tracks production – Rajn explained, noting that Podravka was not obligated to the NIS 1 directive but will be to the NIS 2 directive.

That we are never completely safe was emphasized by Stjepan Jambrak, Coordinator of Information and Cybersecurity at JANAF.

– We have realized that sometimes technology is not everything, but it is more about people. The awareness of the staff managing oil transport must be at a high level because through people, something can be resolved that technology cannot solve – Jambrak said.

All participants in the discussion agreed that, along with technical tools, educating employees about cybersecurity will play a key role in defending against cyberattacks in the future.

Tagged: