Group Purchasing
Group Purchasing

NIS2 Directive Readiness: Compliance, Challenges, and Recommendations

NIS2 Directive Readiness: Compliance, Challenges, and Recommendations (PDF, 0.72MB)Published: 17 Oct, 2024
Created by:
Dean Parsons
Dean Parsons

The NIS2 Directive Readiness: Compliance, Challenges, and Recommendations survey, published by SANS Institute in September 2024, measured how organizations across the EU and beyond are preparing to comply with the NIS2 Directive ahead of its October 2024 transposition deadline. The survey drew on approximately 500 responses from security roles including security administrators, CISOs, CTOs, security architects, and ICS/OT cybersecurity analysts, spanning IT and industrial control systems environments.

Key findings:

  • Despite widespread readiness efforts, only 35% of organizations have started implementing NIS2 requirements, while 50% are still in process
  • Nearly 50% of respondents cite lack of resources as one of their biggest compliance challenges
  • 45% lack current resources to implement newly defined NIS2 controls, more than any other single obstacle
  • 60% of organizations view NIS2 as very positive and well needed, while 38% feel neutral about its impact
  • 37% rate current cyber threats as severe or critical, and another 47% rate them as high
  • Supply chain security is the compulsory measure organizations are most concerned about implementing, cited by 25%
  • Only 41% of organizations have already implemented supply chain security measures, the lowest implementation rate of any NIS2 requirement
  • Just 38% of organizations have assessed their ICS/OT environments for security in the past year, compared to 75% for IT environments
  • 33% of organizations have experienced at least one incident resulting in unauthorized access, data loss, or engineering system disruption
  • Spearphishing attachments are the top initial attack vector, cited in 36% of incidents
  • Energy, healthcare, and public administration are ranked as the three EU sectors most likely to suffer a successful, high-impact compromise
  • 61% of respondents say the CISO holds primary responsibility for setting IT security policy within their organization

The findings show organizations broadly endorse NIS2's goals but remain constrained by resourcing gaps rather than awareness gaps, particularly around supply chain security and ICS/OT assessment cadence. The disparity between IT and ICS/OT assessment frequency is a notable risk given that Essential Entities in critical infrastructure sectors carry the directive's strictest obligations, and the data suggests many organizations are further along in policy and planning than in the operational controls NIS2 actually requires. Respondents operated primarily in Europe, with meaningful representation from North America and Asia, and were concentrated in information technology, financial services, and government sectors, with participation also drawn from energy critical infrastructure and healthcare.

FAQ

Meet the expert

Dean Parsons
Dean Parsons

Dean Parsons

Principal Instructor

Dean Parsons, CEO of ICS Defense Force, teaches ICS515 and co-authors ICS418, emphasizing ICS-specific detection, incident response, and security programs that support OT operations—aligning practitioners and leaders on clear, defensible action.

Read more about Dean Parsons