ESET

EU NIS2 Directive – Cybersecurity Is Now a Management Responsibility

The European NIS2 Directive is intended to significantly strengthen cybersecurity in the EU – and in future it will affect far more organisations than before. IT security is therefore no longer an optional IT issue, but an integral part of responsible corporate governance. NIS2 has become binding through its national implementation. In Germany, this has been in force since 6 December 2025; affected companies were required to register with the Federal Office for Information Security (BSI) by March 2026.

NIS2 Becomes Mandatory: Why Companies Must Act Now

Irrespective of NIS2, the following applies: companies must be aware of their risks and manage them appropriately. This also includes protecting their own IT systems. Those who fail to take action here are not only taking an economic risk but are also exposing themselves to significant legal consequences.

Added to this is growing pressure from the market. Clients, business partners and insurers are already aligning themselves with the new requirements and passing these on along the supply chain. Anyone currently involved in projects that extend beyond national borders is already facing these expectations. The crucial question is therefore not whether NIS2 is formally in effect yet – but whether their own IT systems would withstand a targeted attack.

IT security begins with the question: Which systems are truly critical to our operations? In construction companies, these are often project platforms, cost estimation software, email systems, document management systems or ERP solutions. If any of these systems fails, it has a direct impact on workflows, schedules and payment processes.

On this basis, responsibilities must be clearly defined. Who is accountable for IT security? Who makes the decisions in an emergency? And who takes charge of coordination when rapid action is required? Equally crucial is a robust assessment of the actual risks. Which systems are particularly vulnerable? Which data is indispensable? And what specific consequences would a failure have?

Technology: Less Is More – if Done Right

From a technology perspective, it is not about deploying as many solutions as possible, but the right ones – consistently and reliably. Key to this is ensuring that systems are up to date. Outdated software remains one of the most common targets for attacks. Regular updates are therefore essential.

The decisive factor here is not achieving a certain level of protection once and for all, or purchasing individual products, but rather their continuous review and adaptation. This is the only way to ensure that protection remains effective even under changing conditions. Clearly defined access rights are equally crucial. Not every employee needs access to all systems or data. Making a clear distinction here significantly reduces the risk.

Another key area is data backup. Backups must be in place – and, above all, regularly tested and accessible in an emergency. In such cases, this is precisely what determines whether a company can resume operations within hours or remains at a standstill for days.

End-user devices also play a greater role than is often assumed. Laptops, smartphones and mobile devices are frequently the gateway for attacks – particularly when used outside the company network.

IT Security Is Not a Project, but a Process

If a security incident occurs, preparedness determines the extent of the damage. Companies should not wait until an emergency arises to consider how they will respond. One of the most important initial measures is to quickly isolate affected systems to prevent the threat from spreading further. At the same time, it must be clarified which systems are affected and how operations can be stabilised.

Specialised IT security service providers are often indispensable in this regard. Many companies do not have the necessary resources to manage complex incidents on their own. Added to this are reporting obligations that must be met within short timeframes. Without prepared procedures, this can quickly become an additional burden. Communication is equally crucial – both internally and externally. Unclear or delayed information can significantly exacerbate the damage.

IT security cannot be “implemented” once and for all. The threat landscape is constantly evolving – and so are the requirements. Companies should regularly review their security measures and adapt them to changing threat landscapes. This includes clear processes, defined responsibilities and recurring tests.

Liability: Inaction Becomes a Risk

IT security has become a matter of corporate responsibility. Directors are obliged to organise their companies in such a way that foreseeable risks are managed – and today, this explicitly includes IT.

If an incident occurs and it becomes apparent that fundamental measures were neglected – such as a lack of backups, inadequate access controls or outdated systems – this may be deemed organisational negligence. Appropriate protective mechanisms and software solutions, such as those offered by the international cybersecurity company ESET, are now widely available, economically viable and considered state of the art. However, many companies are still not using them consistently.

The crucial factor is not whether NIS2 has already been formally implemented, but whether a company has responded appropriately to identifiable risks. Anyone who remains inactive in this regard faces a twofold risk: financial – and personal.

Eugen Schmitz

x

Related articles:

Issue 01/2024

Risk Management and Contract Models in Tunnel Construction – Part 1: Basics of Risk Management

1 Introduction Risk management is a project management task in which the opportunities and risks of a project are identified, analyzed, evaluated and monitored. Project-specific risk management is...

more
Issue 02/2014 Monitoring

Data management and risk analysis for tunnelling projects

The execution of underground works requires an assessment of all risks during the planning phase and its comprehensive control during construction to establish acceptable levels of security. This is...

more
Issue 03/2024 Risk Management and Contract Models in Tunnelling – Part 3

Basics of Risk Mitigation

1 Introduction Following the explanation of the basics of risk management [1] and the integral consideration of costs, time and risks [2], the focus is now on risk mitigation. Risk mitigation focusses...

more
Issue 03/2009 Conferences

High Guarantee Performances for major Projects – Safety at any Price?

In an opening address the FGU president Felix Amberg dealt with the introduction of the current safeguarding instruments roughly 15 years ago in conjunction with the major construction projects for...

more
Issue 02/2021

Risk Management in Major Tunnelling Projects – Part 1: Basics and Success Factors

1 Introduction In Germany, the Reform Commission on the Construction of Major Projects already presented its final report in 2015 [1]. A central recommendation is the implementation of systematic...

more