Introduction
NIS2 – what is it, who does it apply to and what does it mean for companies?
Cybersecurity increasingly directly impacts business operations. A ransomware attack, employee account takeover, server failure, or loss of access to an ERP system can disrupt a company's operations for hours or days.
That is why the European Union introduced the directive NIS2, which aims to increase the level of cybersecurity of organizations that are of significant importance to the economy and society.
In Poland, NIS2 requirements were implemented through amendments to the National Cybersecurity System Act. For some companies, this means new responsibilities not only related to securing IT infrastructure but also to risk management, incident response, and management accountability.
In this article, we explain the most important information without going into technical details.
What is NIS2?
NIS2 is a European Union directive on the security of networks and information systems.
Its main task is to increase the resilience of organizations to cyber threats and unify the basic principles of cybersecurity in European Union countries.
However, this is not a guide specifying what firewall, antivirus program or server a company should purchase.
NIS2 introduces primarily an approach based on risk management.
A company should know:
- • what systems and data are most important to him, • what threats may affect the business,
- • what security measures have been implemented,
- • who is responsible for cybersecurity,
- • how the company will respond to a serious incident,
- • how quickly she will be able to return to normal operation.
Cybersecurity shouldn't be limited to the IT administrator. It's becoming part of enterprise-wide management.
Why NIS2 is being implemented
The scale of cyber threats has increased significantly in recent years. Companies rely on email, ERP systems, cloud services, network infrastructure, business applications, and data access.
A problem for one organization can simultaneously impact its customers, suppliers, or other businesses that use its services.
Therefore, the aim of NIS2 is to increase the resilience not only of individual companies, but of entire sectors of the economy.
NIS2 also aims to change the way we approach security. Companies shouldn't just react when a problem occurs. They should identify risks in advance, prepare safeguards, and know how to respond during an incident.
The new regulations are intended to make organizations better prepared for, among other things:
- • cyberattacks,
- • ransomware,
- • data leaks,
- • takeover of user accounts,
- • infrastructure failures,
- • problems on the part of IT service providers.
Who does NIS2 apply to?
One of the most common questions entrepreneurs ask is: does NIS2 apply to our company?
Not every company operating in Poland is automatically covered by the new requirements.
The regulations distinguish, among others: key entities and important entities.
Regulations may cover companies operating in areas such as energy, transport, healthcare, banking, digital infrastructure, telecommunications, selected IT services, manufacturing, the chemical and food sectors, and waste management.
In practice, the list of activities is much more extensive. Therefore, a company shouldn't judge its status solely on its industry or number of employees. It's essential to verify the criteria set forth in the Polish Act on the National Cybersecurity System.
The first step for a company should therefore be to determine, whether it is subject to NIS2 requirements. Only then can the scope of actions needed to adapt the organization be determined.
The following are of primary importance:
- • type of business activity,
- • economic sector,
- • size of the enterprise,
- • the importance of the services provided.
What must a company covered by NIS2 meet?

NIS2 does not require one specific product or a single IT solution.
A company subject to regulations must, above all, properly manage cybersecurity. In practice, this means streamlining several fundamental areas.
Risk management: An organization should know what threats may impact its systems, data and business continuity.
Securing IT infrastructure: Computers, servers, networks, user accounts and systems used should have appropriate security measures.
Backups and business continuity: A company should be prepared for a situation in which it loses access to data or one of its most important systems.
Incident response: It is necessary to define what should be done in the event of a cyberattack, who is responsible for the response and how the incident should be handled.
Supplier Security: The security of external companies with access to the company's infrastructure, systems or data is also important.
Employee training: Even well-secured infrastructure can be attacked by user error. Therefore, employees should know, among other things, how to recognize phishing and other common threats.
The NIS2 requirements therefore cover both technology, procedures and people.
This doesn't mean, however, that every company needs to completely rebuild its infrastructure. Some companies already have many of the necessary solutions, but they aren't properly organized, documented, or monitored.
Therefore, it is worth starting preparations by checking the current environment and identifying the actual deficiencies.
How to start preparing your company for NIS2?
Your first step should not be purchasing new security systems.
First, two basic questions must be answered: Is our company subject to NIS2? If so: what is the current level of security and what are we missing?
Only on this basis can a plan for further action be prepared.
In practice, it may include, among other things, a review of infrastructure, user accounts, backups, network security, cloud services, procedures and vendors with access to company systems.
In such projects, we can help analyze the existing IT environment and prioritize areas requiring change. However, it's crucial that the security measures implemented are based on the company's actual needs, not on a pre-defined list of products assigned to the "NIS2" umbrella.
NIS2 – what is worth remembering?
For businesses, this means a more structured approach to security – from infrastructure protection, through backups and access management, to incident response procedures and employee training.
The most important first step is checking whether a given company is subject to new regulations.
If so, the next step should be to determine the current level of security and prepare a plan to adapt the organization.
However, NIS2 is a very broad topic. Risk analysis, ISMS, cybersecurity auditing, incident reporting, and specific technical security measures require separate discussion.
Therefore, in the following articles we will explain in detail the individual elements of preparing your company for the new requirements.



