19 June 2024
The growing global cyber threat of hacking and data security has seen the UK Government follow in the footsteps of the European Union, by requiring more businesses to meet the standards set out in the Cyber Essentials certification.
"At this stage, it is a requirement for businesses that are in, or contracted to, the national supply chains," explains Rebecca Richards, Compliance Specialist at Strident. "However, I can see this being rolled out to more and more businesses over time."
The NIS2 directive is the most comprehensive European cybersecurity directive yet. Although no longer part of the EU, the UK has chosen to adopt these policies to maintain 'adequacy' with other Europeans Countries.
NIS2 is designed to develop "a culture of security across sectors that are vital for our economy and society and that rely heavily on ICTs, such as energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure."
Key digital service providers, such as search engines, cloud computing services and online marketplaces, will have to comply with the security and notification requirements under the Directive.
You can discover more about the NIS2 directive here.
If you are a supplier to a national infrastructure customer, then your business must also have the 10 minimum security measures in place, plus those that fit the risk profile of your business. And this must be checked by those who use your services.
The 10 measures include risk assessments and security policies for information systems and a plan for handling security incidents. Cybersecurity training and a practice for basic computer hygiene, security procedures for employees with access to sensitive or important data, backups and business continuity and the use of multi-factor authentication.
To find out more about improving the data security of your business, please get in touch.