The European Union (EU) recently established a second Network Information Systems (NIS2) Directive to build on its predecessor. With the new policies, supply chain professionals must be more aware of its cybersecurity framework for proper compliance.
The first NIS law created the framework for incident reporting and basic cybersecurity for the essential sections. European leaders have included more companies under the law’s umbrella to ensure widespread supply chain compliance.
The European Union (EU) recently established a second Network Information Systems (NIS2) Directive to build on its predecessor.
Heightened cybersecurity is critical to uptime and preventing supply chain losses, considering the power of modern threats. The FBI’s Internet Crime Complaint Center (IC3) said fraud accounted for $12.5 billion in losses in 2023 — a 22 percent increase from 2022.
In 2023, the technology sector was the most frequently targeted industry for interactive intrusion activity, according to CrowdStrike’s Global Threat Report 2024. The telecommunications sector was the second most-targeted industry.
With the NIS2 Directive in place, electronics manufacturers must scrutinize their cybersecurity protocol and have holistic approaches. Extra protections are necessary, and failure to comply could result in penalties and significant losses. Here is what supply chain professionals should know about the new NIS2 rules.
The impact of the NIS2 directive
The NIS2 Directive has existed since 2023, although companies have until 2024 to comply. Increased digitization since 2016 has led the EU to update its cybersecurity policies and legal framework. Now, more sectors and entities must improve their resilience and incident response.The NIS2 rules are mandatory in 2024, so electronics companies must comply with the stricter guidelines.
The new directive includes financial market infrastructures, energy, transportation, health care and other critical organizations. These sectors are more likely to use information and communication technology (ICT), thus requiring compliance with the new EU rules.
Europe’s governing body has also expanded its scope to include waste management, food processing, postal services and other more specific sectors. When an incident arises, member states must report it to their nation’s response team for further instructions.
With the new rules in place, supply chain professionals must adhere to them and enhance collaboration with their IT teams. One of the first tasks should be improving their internal risk assessments with the national examinations.
Supply chain cybersecurity management starts with internal risk assessments, as companies must examine themselves and their vendors. Third parties could be a security liability, so examining their risk is crucial to all operations. These organizations must also comply with the NIS2 Directive to ensure maximum protection.
Risk assessments also apply on national and EU scales, with member states improving supply chain security in numerous ways. For instance, a country can perform risk assessments even if the organizations are outside the original scope. Another critical change is the EU’s ability to examine specific supply chains to determine their risk levels.
Supply chain cybersecurity has been scrutinized since 2020, considering the significant risks of outside threats. The objective of the NIS2 Directive is to fortify organizations from attacks.
Supply chain adjustments
Besides risk assessments, supply chain professionals must take other initiatives to comply with the NIS2 Directive. Manufacturers are now involved in this EU cybersecurity mandate, meaning electronics producers should implement better coding practices and frequent penetration testing.
Supply chain professionals should leverage reputable third-party sources to test product security and networks. With regular testing, electronics companies can better understand what future measures are necessary for NIS2 compliance.
These policies work alongside the EU’s General Data Protection Regulation (GDPR) of 2018 — only two years after the first NIS Directive. The GDPR mandates strong data protections and parallels the EU’s new NIS rules. Experts say 64 percent of companies handle at least one petabyte of data, so implementing strong data storage practices is critical.
Electronics manufacturers should regularly update their cybersecurity practices to include the safest and most effective methods. IT departments must also train other staff to follow these directives, considering their complex nature and advanced technologies.
While many cybersecurity tactics remain, manufacturers must evolve and keep pace with sophisticated outside threats. Artificial intelligence (AI), machine learning (ML) and blockchain technologies could be integral to the future of supply chain security, so workshopping all strategies is essential.
AI and ML apply to manufacturers because they enable faster threat detection and improve accuracy. With significant data on its side, AI can analyze unusual patterns that indicate supply chain threats are present. Electronics manufacturers should use these technologies for real-time response and NIS2 Directive compliance.
Further compliance should include incorporating cybersecurity into each electronic component. Manufacturers can implement a secure development life cycle (SDLC) at every stage of development, from original designs to deployment.
SDLs include best practices like zero-trust architecture and continuous deployment (CD) to ensure only authorized users are present.
Ensuring NIS2 directive compliance
Organizations with EU business have to follow the governing body’s regulations, such as the GDPR and the new NIS directives. The NIS2 rules are mandatory in 2024, so electronics companies must comply with the stricter guidelines. Despite not being part of the previous mandate, manufacturers are in the expanded group.
With the NIS2 Directive, electronics manufacturers must be more comprehensive about internal risk assessments to ensure supply chain security. The EU has expanded its powers to assess the risk of specific industries, so organizations must prepare for cyberattacks and fortify their systems. IT departments should adjust their practices to include the latest and best practices, such as AI and ML.
Source: epsnews.com






