Talk With an Expert

We have a Code Blue on NIS2

We have a Code Blue on NIS2 (PDF, 2.57MB)Last updated: 19 Nov, 2025
Presented by:
Øyvind Toftegaard
Øyvind Toftegaard

NIS2 refers to the Network and Information Security Directive 2, which establishes a legal framework to uphold cybersecurity in 18 critical sectors across the EU. The Directive requires Member States to enhance their cybersecurity capabilities by requiring medium-sized and large entities in these sectors to take appropriate cybersecurity measures. In many contexts, especially healthcare, “code blue” signals an emergency requiring immediate attention. In this talk, the expression refers to a problem with the NIS2 Directive that may reduce, rather than improve, the security of critical entities. First, this presentation will point out gaps between regulatory compliance and cybersecurity goals. Then we will investigate the cybersecurity impact of the first NIS Directive and look into the crystal ball to predict the effect of the NIS2 directive. Finally, we will discuss how critical entities can accomplish a high level of cybersecurity while also being compliant.

SANS ICS Europe Summit 2025 (Munich)