• Blog
  • NIS2 in Practice: What Companies and Public Institutions Need to Do Now

NIS2 in practice: What companies and public institutions must do now

NIS2 in der Praxis
Jonathan Bauer

Jonathan Bauer

CEO FC-X

The article analyzes why many NIS2 initiatives fall short and how companies and public institutions can strategically and sustainably anchor information security.

The article analyzes why many NIS2 initiatives fall short and how companies and public institutions can strategically and sustainably anchor information security.

At a glance

  • NIS2 significantly expands the circle of affected organizations

  • Information security becomes a management task and affects the entire organization

  • Organizations should use the time until full implementation to sustainably enhance their cyber resilience.

NIS2 is more than a new regulation

Hospitals have been investing in digitization for years – yet often struggle with the same challenges: informationWith the NIS2 directive, the European Union pursues a clear goal: to sustainably strengthen cybersecurity in Europe.
Many organizations initially focus on legal requirements and proof of compliance. However, NIS2 reveals one thing above all: Information security is no longer an isolated IT issue, but a central management task.

Cyberattacks, growing dependencies on digital processes, and increasingly interconnected supply chains continuously increase the complexity of modern organizations. This is precisely where NIS2 comes in. The directive does not demand individual security products, but robust organizational and technical structures. Information is difficult to find, processes run across multiple systems, and new regulatory requirements increase the coordination and management effort.

Hospital information systems have been modernized, patient portals introduced, electronic patient records prepared, and new requirements for information security, interoperability, and data management implemented. At the same time, topics such as artificial intelligence and digital care models are increasingly coming into focus.
The reason for the persistent challenges often does not lie in a lack of technology.
With each new application, additional interfaces, information flows, responsibilities, and dependencies arise. Complexity grows faster than the actual benefit.

The real challenge lies in the organization

Many companies already have firewalls, endpoint security, backups, or multi-factor authentication. Nevertheless, security incidents often occur not due to lack of technologies but due to unclear responsibilities, insufficient processes, or lack of transparency.

Typical challenges are:

  • unclear roles and responsibilities

  • lack of risk management

  • insufficient documentation

  • lack of transparency over critical systems and supply chains

  • insufficient preparation for security incidents


NIS2 makes these organizational weaknesses visible. Information security does not result from individual technologies but from the interaction of governance, processes, people, and technical measures.

Compliance is the result – not the goal

Many organizations view NIS2 as another regulatory project. However, compliance alone does not prevent a cyberattack. Only an integrated security strategy provides the basis for resilient business operations. This includes clear responsibilities, systematic risk management, continuous improvement, and a security culture supported by management and specialist departments.

Organizations that strategically anchor information security not only fulfill regulatory requirements more easily – they simultaneously reduce downtime risks, strengthen the trust of customers and partners, and create a robust foundation for their digital transformation.

“Technology alone does not create resilience. Only the interaction of people, processes, and technical measures enables effective protection."

What companies should do now

Even though the national implementation of the directive is still ongoing, affected organizations should already take action today. A structured start includes in particular:

Icon Suche

Check relevance

Assess requirements and need for action.

Icon Filter

Analyze maturity level

Objectively assess the security level and derive priorities.

Icon Personencheck

Establish governance

Define responsibilities, processes, and policies organization-wide.

Datenueberwachung

Manage risks

Systematically assess critical systems, supply chains, and business processes

Identity Aware Proxy

Develop technical measures

Continuously expand security architecture, monitoring, and restart concepts.

Trainingsmodel

Empower organization

Sensitize employees and regularly train emergency processes.

Conclusion

NIS2 is far more than a regulatory requirement. The directive fundamentally changes the importance of information security and makes cyber resilience a strategic management task. Organizations that view NIS2 solely as a compliance issue will primarily meet requirements. Organizations that see the directive as an opportunity, create security structures, reduce risks, and strengthen their digital future viability. Because sustainable information security does not begin with a directive – but with an organization that sees security as an integral part of its strategy.

Date 05.10.25Written by Jonathan Bauer

More On This Topic

Realise projects with us?

Speak directly with our experts.

FC-Gruppe GmbH

Administration
Contact Data

Am Storrenacker 8 76139 Karlsruhe