The European Union Agency for Cybersecurity (ENISA) periodically conducts a maturity analysis of sectors of high criticality regarding the implementation of the NIS2 Directive.

While the situation improves with each edition of the ENISA report, certain industries still remain in the risk zone.

NIS2 Sectors of High Criticality in the Risk Zone

This zone encompasses sectors that, despite their criticality, still fail to demonstrate sufficient NIS2 and cybersec maturity. Let’s look together at what drives these delays and what still requires improvement.

#1 Health

Compared to the previous report, the healthcare sector has found itself on the borderline of the risk zone. It’s largely due to progress in NIS2 implementation in the pharmaceutical industry.

The sector faces a variety of challenges, such as ongoing digitalization, dependence on service providers, and legacy technology. Other unfavorable factors include staffing constraints, a low level of cyber hygiene, and a no readiness to fend off incidents.

The most significant delays in NIS2 implementation concern areas such as risk management processes, asset tracking, and vulnerability patching. Legacy technology hinders the comprehensive deployment of threat detection solutions. Also, there are no established standards in place when it comes to assessing implementation effectiveness and incident response readiness.

#2 Space

This sector includes entities manufacturing space technologies that support ground-based activities (e.g., drone positioning systems, GPS navigation, precision observation, telecommunications).

Such an operational profile exposes these entities to attacks by groups linked to hostile intelligence agencies. Another risk factor is the strategic nature of the sector, which actively contributes to building Europe’s independence on the international stage. Added to this are varying levels of cybersecurity maturity (on the market, there are both highly mature entities and startups), a growing ecosystem of dependencies, and an ongoing migration of data to the cloud.

Regarding NIS2 implementation, information exchange, cooperation, and operational readiness remain the most problematic areas. Sector-specific knowledge-sharing mechanisms (such as ISACs) are limited. Testing of protection measures, threat detection, incident response, and data recovery is irregular and mostly ad-hoc.

#3 ICT Service Management

The managed (security) service provider industry (MSPs and MSSPs) has only recently come under EU regulation, making it difficult for authorities to exercise oversight. Similarly, the entities themselves are still finding their footing in the NIS2 reality. This lack of maturity also poses a problem for organizations that rely on MSP and MSSP services/products.

Due to the “digital” nature of the sector, the primary issues with NIS2 are technical. They mainly involve delays in vulnerability patching, a lack of network segmentation, and, in general, data protection. MSPs and MSSPs often operate internationally, falling under different legal frameworks and jurisdictions. Consequently, coordinating complex incident response and business continuity processes (Disaster Recovery) can be a significant challenge.

#4 Transport (Rail and Water)

While the road transport sector was classified as less critical, and aviation shows a high level of maturity, the remaining branches of transport have ended up in the risk zone.

Rail and water transport rely heavily on service providers, such as infrastructure operators or technology vendors. These suppliers maintain IT and industrial systems (ICS/OT) that are rarely updated. This, in turn, facilitates introducing cyber threats into the supply chain. The other major risk factor is the growing involvement of these sectors in military logistics.

In the context of NIS2, the main challenges are effective access and identity management and supply chain security (e.g., third-party ticketing and booking platforms). Incomplete cybersecurity assessments—up to 40% of organizations in the sector skip ICS/OT system evaluation—represent another hurdle. The final weak point is operational readiness, as incident response testing is rare or conducted on an ad-hoc basis.

#5 Public Administration

Low cybersecurity maturity is the primary issue within the public administration sector.

NIS2 is the first framework this comprehensive for public entities. It requires thorough implementation, which is not made any easier by limited support. What’s more, public entities vary in capabilities (big cities vs rural areas) and are limited in terms of human resources and expert knowledge.

As for NIS2 deployment, the lack of training for the management is a major hurdle. This translates into a lack of engagement and cybersecurity awareness. Poor access management practices, inadequate phishing protection, and delays in vulnerability patching constitute technical shortcomings. Finally, collaboration and knowledge exchange also need optimization.

#6 Drinking Water and Waste Water

Both sectors feature one of the lowest levels of NIS2 maturity.

The primary drivers behind this are a lack of experience with cybersecurity regulations, entity diversity, limited human resources, legacy IT/OT infrastructure, and the absence of mechanisms for sharing knowledge and best practices.

Speaking of NIS2 compliance, these sectors struggle to handle threats and attacks. Risk assessment is usually reactive, and risk management often goes unverified. Attack detection capabilities remain low, while incident response and recovery after a failure or attack are ad-hoc and untested.

💡 Looking for key information about the NIS2 Directive? Check out our comprehensive guide. Learn more

Non-Compliance with NIS2 Requirements in the Data Backup Area

As data backup specialists, we are particularly interested in the findings regarding Response & Recovery. For the sectors currently at risk, these are as follows:

  • Health—testing for incident response and business continuity varies greatly. Some organizations perform them regularly, while others do so on an ad-hoc basis. Some admit that these tests have a limited scope (e.g., testing backups only).
  • Space—attention to organizational data varies here as well. Entities possess Business Continuity & Disaster Recovery (BCDR) plans, but some fail to test them at all.
  • ICT Service Management—practices are mixed. Nonetheless, a large portion of entities admit they are not ready to fend off attacks originating in the supply chain. Half of them test incident response in a limited, reactive manner. Only 37% test data recovery.
  • Rail and Water Transport—incident response tests are conducted by 35% and 20% of organizations, respectively. When it comes to BCDR testing, the water transport sector performs quite well, whereas rail lags behind at just 25%.
  • Public Administration—despite facing the highest risk of attacks, the percentage of organizations executing testing procedures is below average. Tests are conducted rarely or solely in the aftermath of an incident.
  • Drinking Water and Waste Water—one-third of organizations either have no incident response plan or have never tested it. As for data recovery, nearly half admit they lack a BCDR strategy.

👉 The full text of the “ENISA NIS360” report (in English) can be accessed via this link.

Choose Xopero Solutions to Ensure NIS2 Compliance and Future Security

Regulations like the NIS2 Directive provide a set of guidelines and a foundation for cybersecurity. However, appropriate procedural and technical measures remain the key to protecting your organization’s data and interests.

If achieving NIS2 objectives related to data protection, incident response, and resource recovery proves difficult for your organization or is currently out of reach, we invite you to explore Xopero offerings.

As cybersecurity experts, we can deliver:

  • Modern hardware and software solutions for data backup and recovery, including for industrial environments (OT/ICS), developed in compliance with ISO 27001 and SOC2 Type II data security standards;
  • Backup testing, automated report generation, activity log, and advanced notification functionalities to meet NIS2 compliance requirements;
  • Comprehensive customer support during the deployment and use of our solutions, provided by qualified, in-house technicians working closely with product teams;
  • The option to store backups in clouds located within Europe as well as locally to help you achieve full data sovereignty and independence;
  • Over 16 years of experience in the data protection market, backed by presence in more than 50 countries worldwide;
  • Supporting expert materials in the field of cybersecurity, including reports, ebooks, a knowledge base, and expert blog articles to keep you up to date with the latest trends and threats.

You may also like

Comments are closed.