Industry News

Understanding NIS2: Essential Cybersecurity for Transport Companies

November 13, 2024

Understanding the Impact and How to Comply

The EU's Network and Information Systems Directive (NIS2) is a cybersecurity regulation designed to protect critical infrastructure and essential services. For a business operating in the EU, understanding NIS2 is crucial to ensure your organization remains compliant and resilient against cyber threats.

What is NIS2?

The Network and Information Security Directive (NIS2) aims to enhance the security of network and information systems within the EU by requiring operators of critical infrastructure and essential services to implement appropriate security measures and report any incidents to the relevant authorities.

Quote from nise2directive.eu

NIS2 is a directive that requires EU member states and associated countries, including Ireland, to establish national cybersecurity frameworks. These frameworks aim to manage the growing risk of cyberattacks and ensure that essential services continue to operate smoothly.

In Ireland this is managed by www.ncsc.gov.ie

Who is affected by NIS2?

NIS2 primarily applies to Essential Service Providers (ESPs). These include organizations in sectors they define as “critical”. This, of course, includes transport.

They say the directive only extends to companies that have at least 50 employees or achieve an annual turnover of over €10 million, however if you come below this size threshold but are a vendor to a larger organisation they may request your compliance and readiness statement from you.

A huge focus of NIS2 is about safeguarding supply chains and “essential” businesses, therefore its important for everyone in the industry to consider wider impacts.

What does NIS2 mean for transport companies?

NIS2 introduces a number of new requirements for transport companies, including:

  • Risk assessment and management: Companies must identify and assess the cybersecurity risks they face and implement appropriate controls to mitigate those risks.
  • Incident reporting: Companies must report cybersecurity incidents to the relevant authorities within a certain timeframe.
  • Supply chain security: Companies must take steps to ensure that their suppliers are also implementing appropriate cybersecurity measures.
  • Cybersecurity awareness and training: Companies must provide their employees with cybersecurity awareness training.

What that means, pragmatically speaking, is that you need to have a conversation with your IT team or provider about your cybersecurity. This will involve finding gaps in your own cybersecurity and implementing more robust measures - like stricter access control, secure storage/backups and creating a plan in the case of a breach of security.

How can Stratum help your transport company comply with NIS2?

Stratum is a leading provider of transport management software (TMS) that can help your company comply with NIS2 in a number of ways:

  • Audit trails and logging: Stratum's platform provides comprehensive audit trails and logs that can help you track activity and identify potential security incidents.
  • User management and access control: All our software for transport, garage and warehouse management allow you to control access to your data on a user-by-user basis.
  • Move to a secure cloud: We offer cloud hosting for your database in Microsoft Azure, allowing you to utilize their world class infrastructure for advanced security features, including encryption, monitoring and threat detection, with incredible resilience.
  • Regulation ready data transmission and communication: Our app for drivers, InCab, as well as our Customer Web Portals allow for sharing sensitive data like PODs, WACs, and other customer site in a modern, seamless and secure way.
  • Regular security updates: Stratum is committed to providing regular security updates to its platform to address the latest threats.

Conclusion

NIS2 and the path to compliance can be daunting, but it doesn’t have to be. Most changes required under the new directive are cyber-security best practices and would need to be implemented even without NIS2 as your company grows. By adopting strong cyber strategies, effective governance, and robust information security management, organizations can confidently work towards regulatory compliance.

Technology solutions like Stratum can play a vital role in this process, simplifying data protection and meeting regulatory requirements - however, it is crucial to be in contact with your IT provider and ensure you have a plan for your data.

NIS2 compliance is not just about avoiding fines; it's about protecting your business from the ever-growing threat of cyberattacks.

Expect to have a problem, 95% of all business have interruptions to their IT systems every 3 years.

Contact Stratum today to learn more about how we can help you comply with NIS2. Or, read more on our website about our modern transport solutions.

Contact us

Let's find the right solution for you

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.