Perspective

Spotlight on NIS2 and cybersecurity in practice

Can you buy your way to NIS2 compliance?

A slightly provocative question kicked off the day when MOWE and Lakeside brought people together for the morning event X-RAY: NIS2 & Cybersecurity. And the answer? Well… it was no. But you can get a long way – if you know where and how to start.

tryk14_UB 1

Compliance starts with management

Security expert Mette Thøgersen from Lakeside opened with a sharp, practical talk in which she stressed the most important point first: NIS2 compliance is not something you can simply outsource. It is the organization’s task and responsibility – and it starts with management.

This is a cultural change in which the organization’s top management holds the ultimate responsibility. That applies whether it is a private company, a public institution or a critical supplier.

From legal requirements to concrete tasks

Mette took the participants through how working with NIS2 requirements in practice is rarely linear. Instead, it calls for an iterative approach in which you repeatedly return to the status report, adjust the strategy, assess risks and adapt procedures.

She made it clear that a risk assessment cannot stand alone. It has to be based on a solid overview of the organization’s vulnerabilities.

“Start with registers and policies. That makes it easier to prioritize and draw up an action plan. An annual cycle is not just a good idea – it is a necessity”

When incidents become serious

A central point in the NIS2 Directive is the handling and reporting of incidents. Here, the difference between an ordinary incident and a significant incident was explained.

A significant incident is defined as one that can cause severe operational disruption, substantial financial loss and/or harm to others – physical, legal or societal.

Mette pointed out that it is not necessarily only the consequences that determine how serious an incident is. It may well be the fact that an infrastructure IT system is down, in which case it must be reported within 24 hours via virk.dk, followed by an update after 72 hours. The incident must also be followed up with an evaluation report no later than one month after the system went down.

Requirements and chains: when the supplier becomes part of the solution

Attorney Kathrine Ahrenholt from MOWE then took the baton and shifted the focus from incidents to procurement and contract requirements. After all, how do you actually implement NIS2 in your supplier agreements?

Kathrine explained how an organization should set requirements for its critical suppliers – not just for technical measures, but also for incident handling, emergency preparedness exercises, involvement in supervision and ownership of data.

Kathrine gave concrete examples of how requirements can be written into tender documents – with reference to standards such as ISO/IEC 27001 and requirements for logging, backup, access control and contingency plans. She explained the difference between minimum requirements, evaluation criteria and options – and how each category affects the supplier’s responsibility:

 

“It is not about a scattergun approach, but about being precise: Which risks need to be addressed? Which incidents need to be handled? And what do we expect of our partners when the pressure is on?”

 

tryk3_UB 1

From responsibility to action

After the talks, the floor was opened for questions from the audience, and the debate was lively. Participants left with a clear picture of how NIS2 is not just an isolated legal requirement but part of a larger movement towards greater cybersecurity, resilience and accountability throughout the value chain.

And no – you cannot buy compliance. But with the right processes, the right mindset and good partners, you can build a cyber-secure foundation for your organization – one step at a time.

Featured content

News from

Sign up for our newsletter featuring professional insights and experiences from integrated construction. Choose the topics about which you’d like to receive insights and information.