# 27 NIS2-direktivet – Högre krav på cybersäkerhet
14m 31s
The NIS-2 directive, a revised version of the NIS directive, has been introduced in the EU to address increased digitalization and cybersecurity threats. It includes requirements for incident reporting, stronger sanctions, and education on cybersecurity for management. The directive aims to ensure a high level of cybersecurity across member countries. However, the Swedish implementation of the directive has been delayed, with proposals for implementation expected soon. The delay in implementation means that the directive's requirements do not apply until Swedish legislation is in place. Despite the delay, it is crucial for companies to start preparing for compliance with the directive to avoid cybersecurity risks and potential sanctions. Stay tuned for updates on the Swedish implementation process.
Transcription
1917 Words, 11009 Characters
[Music]
Different networks and information systems
produce an increasingly important impact in society.
And they are often completely debatable
because basic social functions should work.
For example, energy supply, transport and bank services.
Often there is also an internal relationship
between both different sectors and over land borders.
But a lot has happened in our environment
and developments have also been easily changed towards the picture.
Before the EU, it has therefore chosen to introduce
the so-called NIS-2 directive,
which introduces new demands that aim to raise
a comprehensive and high security level
in all the member countries.
And just like in the previous episode,
we will also talk about a new IT-related EU rule rule,
but this time one that aims to increase
the digital resistance and security.
But what does the NIS-2 directive mean?
Who will be met by it?
And what demands will be met by involved actors?
And last but not least,
how does it actually work with the Swedish implementation?
[Music]
Hello and welcome to the IP-compass.
The pod for you who is responsible for IP,
a lawmaker or simply interested in material rights.
In this pod, we would like to invite you
to new cases, our own experiences
and share our knowledge in the area of material rights.
My name is Mikaela Uttberg
and I work as a lawyer in the material rights
and IT law here at Vinge.
And with me today I have my colleague, Lisa Burgart,
who also works as an advocate in the material rights
and market law at Vinge.
Hello Lisa and warmly welcome back to the IP-compass.
Thank you, Kola and Harry again.
If we start talking a little about why the directive was introduced,
it is called the NIS-2,
since it is a revised version of the earlier NIS directive.
But why have you reviewed this review?
Well, it is an updated version,
a NIS-2 or 2.0.
And it actually depends on two things.
The first thing that happened,
things like the previous directive,
the NIS directive was introduced in 2016,
and since then it has become quite a powerful increase in digitalisation.
There is also a threat of security of other countries,
in Europe today.
We see increased security attacks.
And because of the digitalisation,
they also get much greater consequences in society.
So that is one thing.
And the other thing is that
it was thought that there was a problem with the previous directive.
The directive was too boring when it came to sanctions.
And the implementation of the directive was for different countries.
Which made it difficult for the company to keep up and know what was going on,
especially if you have worked in several countries.
Okay, I understand.
But what are the differences between the NIS-2 directive
in relation to this time?
Some of the most important differences are that the directive
is a big challenge for the sectors of the directive.
That means that more companies will be replaced by the new rules.
Then there is also a requirement to report to the respective authorities
that you have a so-called NIS-2 business.
There is also a requirement for incident reporting.
About as in GDP, there is GDP reporting.
If you do not want to intervene, you should report it to the authorities.
And the NIS-2 directive also contains more powerful sanctions
just to get to the point with the problem I mentioned earlier.
Yes, okay.
But if we start with the first point you mentioned,
the implementation of related sectors,
would you like to tell a little more about what that means?
Yes, but it is simply a challenge that means
that companies that have real estate in some of the 18 given sectors
will be replaced by this new rule,
if they are also counted as a large company.
So that the smallest companies will not be met by the rule as a main rule.
The suspect is that companies that are so closely related to society are so important
that they still have to be replaced by the security service.
Okay.
But regarding the implementation of related sectors,
you also mentioned that they also need to fill up certain demands
that are part of their work, and what does this increase in demand?
Yes, but they aim to ensure that a good risk handling for super-security
by implementing demands that ensure that the company takes reasonable measures
that monitor the risks that are connected to their work.
And that does not apply exactly what you are going to do.
Instead, it actually applies the goal with the security service in the directive,
because it is such a big difference between a company and a company.
A risk in a company does not look the same as in another company.
But it sounds generally like a pretty bloody demand with reasonable demands.
Is there no example of more concrete demands or concrete demands that one should take?
Both yes and no, actually.
The new directive, the second directive, is more concrete and clear than the previous one,
because it includes different factors that one should take into account
in their decisions and the risks that one has within the company.
For example, what strategies for risk analysis,
incident handling, as I mentioned earlier,
personal security, implementation strategy for emergency control and drift continuity.
So, one should map the basis of different IT systems,
what happens if a system is down.
And this is not just about the digital environment,
but there can be risks, serious risks, even in the physical environment.
It can be good to know that one should take, as you mentioned, reasonable concerns,
and the idea is that one should judge how big the risks are
and what is reasonable concern for handling that risk.
What risk should we start looking at and then quit?
Okay, but apart from the demands that are about risk handling,
you also mentioned that the second directive includes high sanctions,
and what about the demands in relation to the management, for example?
What sanctions are there for the transfer of the directive?
But that is also a new thing with the second directive.
Because it is very clear who is responsible, and that is the management.
And for an action board, it is primarily the manager, who is here,
but also the VD and vice-VD.
And this person category, then, is responsible for the security work,
both what to do, how to know what to do, analysis,
and also supervise the implementation of these regulations.
And then you also have to apply resources, the management has to do the job,
but it is also so that it is obligatory that the management
and this person category should go through education around cybersecurity.
And it is simply so that, yes, but the EU law firm thinks that if you can't do anything about this,
then you will not be able to judge which risk handling measures you should take,
and follow up on it in a way that is quite logical, actually.
But you asked the question about sanctions there.
Yes.
In some cases, there are personal sanctions against this person category,
that you can prevent the transfer of leadership functions in this company.
But then there are also sanctions in the form of, for example, sanctions on debts.
And they are much more powerful now.
So there are some GDP, again, some GDP-like levels on them.
It is a maximum of 2% of the total global year,
or 10 million euros.
So the idea is that this should be felt.
So, yes, a pretty long-term consequence, in other words, for those who do not follow the directive.
Thank you very much for this ready-to-do.
And finally, I would like to talk a little about the Swedish implementation.
Because the directive actually already has 30 power in October 2017.
But as I understand it, are the Swedish implementations delayed? Is that correct?
Yes, but it is correct, and it actually looks like that in the rest of Europe as well.
A little more generally, that many countries are involved in the implementation.
And in Sweden, in our case, an exhibition was presented,
that suggested that this directive, at least our directive,
should be implemented through a new law, the law on cybersecurity.
And therefore, after it is presented in our case, there has not been much happening.
So we do not have any proposals in advance, and since we do not have any proposals,
there is therefore no law that has been adopted by the parliament.
Okay, but what does this delay in practice mean?
Yes, but since the second directive is just a directive,
it is required that it should be implemented in the Swedish law,
and in the other countries as well.
So, there is no reason for the directive to be adopted,
it comes first when there is a Swedish law, you can say.
So, the delay means that the requirement, as a rule of thumb,
does not apply before the Swedish legislation is implemented.
But does that also mean that the effectiveness of it, which is understood by the directive,
can be removed from it, so that the Swedish law is in place then?
Yes, it has been possible, but it is not really that easy.
Partly, it is so that the effectiveness as previously understood by the NIS directive,
i.e. NIS 1, because they get the NIS 2 directive already now,
because the old directive should be removed from the new directive,
so they need to fill the requirement in the NIS 2 directive already now.
And for the effectiveness as previously understood,
but that will be done in the NIS 2 directive,
then this is right, as I said, the main rule,
that you have to wait until the Swedish rules are in place.
But, on the other hand, it is quite important that you already start spreading the work,
it is a quite comprehensive work, so there is really no reason to
invent and wait for this work to start.
And in fact, it is so that cybersecurity work,
it is not only done to avoid sanctions,
but it is also done to ensure that you can operate your business in a way
that you do not be hit by expensive cybersecurity attacks.
Kloka Råd.
But one last question, then, what is the status today regarding the Swedish implementation?
According to the latest information we have received,
a proposition was expected to be made in place during the late spring,
somewhere, and then the question is whether
Riksdagen will be able to take place before the summer,
they have a quite long semester, or if it will be after the summer.
So that is a bit of insecurity around that,
but the IMAT directive has already started to come,
and we are after the time plan, so you can think about it,
from the fact that Riksdagen will take its decision,
then there will not be so many months before the rules
take place in the Swedish team.
So you have to be a bit in tune around that.
Okay, I understand.
And with that, it was time to end today's episode.
Thank you for the Kloka Oden, Lisa,
and thank you very much for joining the IP Compass.
Thank you very much, Ella.
This was all from the IP Compass today,
and thank you very much for listening.
(upbeat music)
Podcast Summary
Key Points:
Introduction of the NIS-2 directive aims to enhance cybersecurity in EU member countries.
NIS-2 directive includes requirements for incident reporting and more powerful sanctions.
Implementation of the directive requires adherence to risk handling measures and education on cybersecurity.
Swedish implementation of the NIS-2 directive has been delayed.
Proposals for the Swedish implementation are expected to be presented soon.
Summary:
The NIS-2 directive, a revised version of the NIS directive, has been introduced in the EU to address increased digitalization and cybersecurity threats. It includes requirements for incident reporting, stronger sanctions, and education on cybersecurity for management. The directive aims to ensure a high level of cybersecurity across member countries.
However, the Swedish implementation of the directive has been delayed, with proposals for implementation expected soon. The delay in implementation means that the directive's requirements do not apply until Swedish legislation is in place. Despite the delay, it is crucial for companies to start preparing for compliance with the directive to avoid cybersecurity risks and potential sanctions.
Stay tuned for updates on the Swedish implementation process.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.