All Events and Webinars

What is NIS2 Compliance Webinar

Healthcare
Manufacturing
Transportation and Logistics
Leadership and Resilience
Supply Chain and Third Party Risks
Threat Actors and Campaigns
Incident Response and Recovery
April 24, 2025
NIS2 significantly expands who must take cybersecurity seriously and what “good enough” now looks like. This session explains how the directive changes scope, reporting expectations, and operational responsibilities across sectors. Viewers will learn how to build the monitoring, governance, and response capabilities needed to meet requirements and avoid treating NIS2 as just another compliance checkbox.

In-House Specialists

Ken Sheehan

Director of Operations

External Speakers

Matthias Maier

Cybersecurity Market Advisor

Key Strategic Takeaways

Does NIS2 Turn Cybersecurity Into a Business Obligation?

NIS2 was introduced to address rising systemic risk across critical sectors, driven by increasing cyberattacks, geopolitical instability, and real-world service disruptions. It expands on the original NIS Directive with broader scope, stricter requirements, and stronger enforcement, similar to how GDPR reshaped data protection. Cybersecurity is no longer a best practice, it’s a regulated responsibility tied directly to operational continuity and public impact.

Has Scope Expanded Significantly Across Critical Sectors Under NIS2?

NIS2 widens the range of organisations in scope by covering both “high criticality” and “other critical” sectors, bringing many more entities under regulatory requirements. Industries like healthcare and manufacturing are especially exposed due to their operational importance and history of disruptive attacks. More organisations must now assume they are in scope and assess their obligations rather than assuming exemption.

Is Incident Reporting Now Structured and Time-Critical Under NIS2?

NIS2 introduces a staged reporting model requiring early warning within 24 hours, detailed notification within 72 hours, and a final report within one month. This forces organisations to rapidly detect, assess, and communicate incidents with clear evidence and impact analysis. Compliance depends on having the operational capability to understand incidents quickly, not just respond to them.

Does NIS2 Compliance Require Governance and Not Just Technology?

NIS2 is not an IT project, it requires coordination across legal, security, compliance, and leadership teams. Boards are expected to take accountability, influencing funding, staffing, and overall security strategy. Organisations must align people, processes, and technology to build a repeatable and defensible security posture.

Is Continuous Security Operations Essential to NIS2 Compliance?

Meeting NIS2 requirements demands ongoing monitoring, detection, and response capabilities, often through SOC models supported by threat intelligence. Organisations must be able to identify threats, act on indicators of compromise, and maintain resilience under attack. Security operations become the engine that enables both compliance and real-world resilience, rather than a supporting function.

No items found.
  • 00:00 Introduction to NIS2 and why it matters now for critical organizations
  • 02:16 How NIS2 evolved from the original directive and the events that shaped it
  • 04:02 Which sectors are in scope and why healthcare and manufacturing stand out
  • 05:49 The 24-hour, 72-hour, and one-month incident reporting obligations
  • 07:48 What organizations should expect as member states move toward implementation
  • 09:00 How customers are translating NIS2 into practical action plans
  • 13:03 Why NIS2 is not just an IT issue but a whole-organization risk exercise
  • 15:50 Threat intelligence, sector CSIRTs, and the role of shared indicators of compromise
  • 20:20 How security operations support active cyber protection under NIS2
  • 22:22 Top advice for preparing before October instead of waiting for final local law
  • 24:19 Why legal, compliance, and technology teams must work together early
  • 25:18 Final takeaways: teamwork, time, tenacity, and the need for continuous security operations
  • Watch More
    Compliance and Risk

    Seasonal Cybersecurity Risks for Transport Webinar

    Smarttech247 leaders discuss transportation cybersecurity, focusing on OT security, digital twins, evolving threats, third-party risk, and resilience.

    HSE Ransomware Attack and the Future of Cybersecurity in Ireland

    Cybersecurity leaders discuss the HSE ransomware attack and a path forward for Ireland, focusing on resilience, regulation, maturity models, and public awarenes

    Ransomware Cyber Attack Simulation Webinar

    Attack simulation showing a multi-stage ransomware campaign and how Cybereason detects, correlates, and responds to fileless and living-off-the-land techniques.

    Ready to scale your security and compliance operations?

    We protect your on-premise/cloud/OT environments - 24x7x365