Green CrowGreen Raven has discovered that compliance with the EU’s NIS2 directive is still patchy. Some respondents to its survey didn’t know if NIS2 applied to them. Meanwhile, 10% of those to who it did apply admitted they were not compliant by the October 17 deadline. That is despite being given almost two years to get their act together.

The findings should shock no one. When new compliance comes out, it is not unusual for regulators to give companies time to comply. However, there is an expectation that they will do so. This level of failure is something that regulators need to take a stronger stance over. If not, it raises the question of how much time organisations need to become compliant.

Morton Steen Mjels, CEO Green Raven Limited
Morton Steen Mjels, CEO Green Raven Limited

Morten Mjels, CEO of Green Raven Limited, said, “NIS2 came into force in January 2023 – almost two years ago – so for senior cybersecurity professionals at the companies most likely to be impacted to not know if it even applies… wow.

“Saying yes, we’re compliant may be acceptable; admitting that no, we’re not compliant but we’re working on it may also be acceptable– assuming there may be a grace period when new regulations come into force.

“But, eventually, failure to be compliant is going to significantly impact the ability of these organisations to do business in Europe, or is going to attract a significant fine for doing business in Europe without being compliant. And saying ‘we weren’t sure’ is unlikely to be much of a defence.”

Will UK companies be more compliant with new UK bill?

This research, which Green Raven plans to release at Black Hat, involved 200 companies with over 1,000 staff. That makes up just over 10% of that size of business in the UK. This makes the research important and gives a realistic view of organisations’ current state.

Having established the compliance issues with the EU NIS2 directive, the survey asked about the UK Cyber Security and Resilience Bill. It was announced in the July 2024, King’s Speech. While it has been trailed as the UK’s NIS2 equivalent, it won’t be introduced to Parliament until 2025.

The survey asked participants to react based on what they had heard or read about the new Act. Some of the responses are concerning. It seems from the responses that some see legislation and compliance as a burden and not something they want to do. Yet, at the same time, the vast majority agree that the bill will improve the UK’s overall resilience.

Green Raven provided three stats from the upcoming research :

  • 37% of respondents hope that the new Cyber Security and Resilience Bill won’t apply to their organisation, but almost 80% expect that it will.
  • 46% of respondents expect the bill to make unwanted demands of UK businesses, but over 82% expected the bill to make reasonable demands of UK businesses. A similar proportion agreed that the bill would make necessary demands of UK businesses.
  • Almost 88% of respondents agreed with the statement, “The UK Cyber Security and Resilience Bill will improve the UK’s overall cyber resilience.” Not a single respondent disagreed with this statement, despite the acknowledgement of the additional demands and overheads the new bill is likely to bring.

Enterprise Times: What does this mean?

This release raises many concerns. It is shocking that so many large companies are still not compliant with NIS2 despite having almost two years to do so. Worse, many think the UK equivalent will make unwanted demands.

If large organisations cannot or will not become compliant, they cannot expect the rest of their supply chain to do so. Their attitude towards compliance puts their business partners at risk, as they become the weakest link.

How to get companies to be more compliant is difficult. Regulators tend to have very blunt tools at their disposal. But, they cannot allow large companies to ignore their responsibility and still target mid to small-sized businesses. It will be interesting to see how the cyber insurance industry treats this report when it is published.

Cyber Insurers are already making it hard for businesses by raising the bar and denying them insurance. Maybe a joint response by insurers and regulators will effect change. I’m not holding my breath.

Previous articleTA Associates invests in Certinia
Next articleBlackLine launches Studio360 to empower the Office of the CFO
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here