The Bottom Line: NIS2 requires comprehensive cybersecurity upgrades — many enterprises are falling behind schedule in implementation.
The implementation of the NIS2 Directive is putting enterprises under pressure — reports indicate that numerous businesses have not yet completed the measures required to meet the new cybersecurity requirements.
The NIS2 Directive (Network and Information Security) requires enterprises to significantly expand their cybersecurity protection measures. For CISOs, this concretely means: comprehensive inventory of critical assets, implementation of minimum standards for access control, incident response and regular security assessments are no longer optional.
Many organisations, particularly in the mid-market, have not yet completed the necessary restructuring of their security architecture. The time pressure results from specific implementation deadlines and threatened sanctions for non-compliance.
For CISOs, the task now is to conduct a gap analysis, prioritise implementation roadmaps and request budgets from management for missing controls. A pragmatic staggering based on asset criticality and existing security gaps is essential to avoid binding all resources at once.
Source: news.google.com · Published 22 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.