CyberEssentials is becoming a requirement for more businesses - News item

Cyber Essentials is becoming a requirement for more businesses.

The growing global cyber threat of hacking and data security has seen the UK Government follow in the footsteps of the European Union, by requiring more businesses to meet the standards set out in the Cyber Essentials certification.

"At this stage, it is a requirement for businesses that are in, or contracted to, the national supply chains," explains Rebecca Richards, Compliance Specialist at Strident. "However, I can see this being rolled out to more and more businesses over time."

What is NIS2?

The NIS2 directive is the most comprehensive European cybersecurity directive yet. Although no longer part of the EU, the UK has chosen to adopt these policies to maintain 'adequacy' with other Europeans Countries.

NIS2 is designed to develop "a culture of security across sectors that are vital for our economy and society and that rely heavily on ICTs, such as energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure."

Key digital service providers, such as search engines, cloud computing services and online marketplaces, will have to comply with the security and notification requirements under the Directive.

You can discover more about the NIS2 directive here.

Does my business need to comply with NIS2?

If you are a supplier to a national infrastructure customer, then your business must also have the 10 minimum security measures in place, plus those that fit the risk profile of your business. And this must be checked by those who use your services.

The 10 measures include risk assessments and security policies for information systems and a plan for handling security incidents. Cybersecurity training and a practice for basic computer hygiene, security procedures for employees with access to sensitive or important data, backups and business continuity and the use of multi-factor authentication.

What should my business do?

At the moment, these requirements are only for businesses identified in the named sectors. However, we believe that many of these security measures can be met by smaller businesses without significant problems. This leads to a culture of cybersecurity that will protect your business and customers.

To find out more about improving the data security of your business, please get in touch.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection