The NIS2 Directive focuses on prevention, not just compliance. Whether your company is an essential or important entity, there is a set of basic technical and organizational measures (best practices) that every organization should have already implemented.
These measures are not just best practices – they are the minimum condition to reduce the risk of incidents and to demonstrate, in case of an audit, that you have taken the reasonable steps required by law.
Here are 10 essential cybersecurity hygiene measures your organization should already have in place:
1. Clearly define who has access to critical information and systems – and who doesn’t.
2. Limit employee access strictly to the resources needed for their role.
3. Remove administrator privileges for daily activities. Privileged access should be temporary and controlled.
4. Protect remote access using secure methods – multi-factor authentication (MFA) is already a standard.
5. Install and maintain firewalls in all relevant areas of the network.
6. Network segmentation and segregation help limit the impact of a potential attack.
7. Regularly apply patches and security updates – automate this process if possible.
8. Monitor activity logs and alerts – don’t just collect them for the sake of it.
9. Install and keep updated anti-malware solutions, not just basic antivirus.
10. Perform frequent backups and store them separately from the main system.
These 10 measures are just the first step. However, their lack may signal to authorities that your organization does not have even a basic cybersecurity culture.
certSIGN’s offer for fast NIS2 compliance
certSIGN can help you quickly identify the essential measures you need to implement and how to do it correctly. Through a practical approach tailored to your organization’s current level, we offer:
- Rapid assessment services to check existing security measures (gap assessment);
- Consulting for implementing the 10 essential cybersecurity hygiene and basic protection measures;
- Support in drafting policies/procedures, team training, and selecting the right technical solutions;
- Ongoing support for progressive alignment with the Directive’s requirements.