A wave of cyber attacks hits business. NIS2 changes the liability of entrepreneurs
Ransomware attacks, data leaks, taking over access to systems and disruptions to business continuity increasingly affect not only the largest entities, but also medium-sized companies operating in the service, industrial and technology sectors.
The growing number of cyberattacks in Poland and Europe shows that digital security has become one of the key risk areas for enterprises.
Experts emphasize that modern cyber threats are of both technological, operational and regulatory nature. The effects of incidents include not only financial losses, but also legal liability, loss of reputation and the risk of disruption of the company’s operations.
– In practice, many organizations still perceive cybersecurity as a technical problem left to IT departments. Meanwhile, current regulations and the scale of threats clearly show that this is an area of management responsibility and an element of the security of the entire enterprise– says Attorney Anna Kobylińska, Owner of the Legal Eagles Law Firm.
Hacker attack as a real business risk
In recent months, there have been numerous incidents involving customer data leaks, IT infrastructure takeovers and temporary paralysis of enterprise operations. Cybercriminals are increasingly taking advantage of not only technological gaps, but also organizational errors, lack of procedures and low level of employee awareness.
Phishing attacks leading to compromise of login credentials or installation of malware remain a typical scenario. In many cases, a single incident may result in stopping operational processes, loss of access to documentation, problems in customer service or the need to temporarily suspend operations.
Experts point out that companies often focus on technical security, ignoring organizational and procedural issues. Meanwhile, effective cybersecurity requires regular risk analysis, appropriate division of responsibility, staff training and readiness to respond to incidents.
NIS2 expands the obligations of entrepreneurs
An additional impulse for changes are new regulations resulting from the NIS2 directive and the amendment to the Act on the National Cybersecurity System (KSC). The regulations significantly expand the list of entities subject to cybersecurity obligations, including: the energy, transport, financial, health, manufacturing and digital service providers sectors.
In practice, this means that many organizations that have not yet identified themselves as critical infrastructure entities will be obliged to implement information security management systems, report incidents and conduct regular audits.
What is particularly important, the new regulations clearly emphasize management’s responsibility for supervising cybersecurity.
– NIS2 changes the way of thinking about responsibility in organizations. Regulations require conscious supervision of risk, implementation of procedures and documentation of actions taken in this area – emphasizes Attorney Anna Kobylińska.
Supply chain under special supervision
The security of suppliers and business partners is also becoming more and more important. Modern cyberattacks often exploit weaker links in supply chains, allowing access to the infrastructure of larger organizations through external service providers.
For this reason, new regulations require entrepreneurs to take into account the risks associated with IT service providers, remote service and cloud solutions. In practice, this means the need to verify contractors’ security procedures and appropriately secure contractual relations.
Cybersecurity as an element of business strategy
For many organizations, cybersecurity is becoming one of the key elements of risk management, compliance and business continuity.
In the face of the growing number of cyber threats and new regulatory obligations, entrepreneurs should now conduct a risk analysis, verify security procedures and assess whether their organization is subject to the new requirements resulting from NIS2.
Lack of adequate preparation may mean not only financial and operational risk, but also regulatory liability and loss of trust from customers and business partners.
