Impact on management
A crucial element of NIS2 is the impact on the management level of organizations. The directive requires executives to be actively involved in cybersecurity and take responsibility for the security of their information systems. This includes ensuring adequate resources and implementing an information security management system (ISMS).Understanding the chain
NIS2 emphasizes the importance of understanding the supply chain, holding organizations accountable for the security of their entire chain, including suppliers and partners. Hackers who target large companies often first attack small companies that are in connection with those large companies. This undermines the chain and affects both large and small companies.Duty of Care, Duty to Report and Supervision
The duty of care under NIS2 means that organizations must take appropriate technical and organizational measures to manage the risks to their network and information systems. This requires continuous risk analysis and taking preventive measures. The reporting obligation requires organizations to report serious incidents to the relevant national authorities within 24 hours. Compliance monitoring under NIS2 is strengthened, with the possibility of audits and inspections by regulators.Become demonstrably compliant
To become demonstrably compliant with NIS2, we advise organizations to implement an ISMS based on recognized standards such as the ISO 27001 or the NEN 7510 part 1. Implementing an ISMS provides a structured and cyclical framework for managing these risks and demonstrating compliance. An effective ISMS includes policies, procedures and proper organizational embedding of measures and controls, and this system should be regularly audited to ensure compliance. Performing a gap analysis to determine where the organization stands in relation to NIS2 requirements is an essential first step. Plans should then be developed and implemented to address any deficiencies in the control measures.Requirements for management measures
The control measures required under NIS2 must be based on a risk assessment and must protect the availability, integrity, and confidentiality (AIC) of data. To work effectively and efficiently, we recommend relying primarily on standards that include control measures, such as ISO 27002, NEN 7510 Part 2, or the Government Information Security Baseline (BIO). Organizations must reevaluate and adapt their existing cybersecurity practices to meet the new requirements. This includes, for example, conducting risk assessments, updating incident response plans, and ensuring the continuity of critical services. The Perium platform gives organizations a head start, beginning with a gap analysis to assess the current state of cybersecurity measures and identify areas for improvement.The importance of understanding the overlap between NIS2 and other standards
Organizations that already comply with ISO 27001/2, NEN 7510, or the BIO will find that there is significant overlap with the NIS2 requirements. It’s important to understand this overlap and take advantage of it to avoid duplicating efforts. In the Perium platform , this overlap has already been mapped out to help you get off to a flying start.Key measures explained
The NIS2 lists the following topics for which organizations must implement appropriate measures:- Risicomanagement Breng je digitale risico’s in kaart en beoordeel deze regelmatig. Met de risicobeoordelingen kun je onderbouwde beslissingen nemen op welke beheersmaatregelen je in gaat zetten.
- Bedrijfscontinuïteit Op basis van je risicobeoordeling en eisen voor continuïteit maak je een continuïteitsplan en test je deze regelmatig.
- Veiligheid in de keten Beoordeel de veiligheid van je ketenpartners om potentiële risico’s van externe leveranciers en dienstverleners te identificeren. Neem passende maatregelen om je bedrijfscontinuïteit te garanderen.
- Beveiliging van netwerk- en informatiesystemen Ga aan de slag met een uitgebreide aanpak voor de beveiliging van netwerk- en informatiesystemen, waarbij systemen goed zijn ingericht en er een doeltreffend beleid is voor het identificeren en omgaan met kwetsbaarheden.
- Cyberveiligheidsbeleid Zorg voor een duidelijk informatiebeveiligingsbeleid en dat de medewerkers hiervan op de hoogte zijn en deze wordt nageleefd.
- Effectiveness of cybersecurity measures Regularly assess the effectiveness of your management measures, allowing you to make appropriate improvements.
- Cryptography and encryption implementation Ensure properly secured and correctly encrypted connections.
- Physical security Implement physical security measures, including policies related to personnel, access control and asset management.
- Multifactor authentication Deploy multifactor authentication (MFA) for relevant accounts, including those accessible from the Internet and with management rights to critical systems. This will help you best protect your organization from cybercriminals.
Proactive penalty policy
NIS2 is going to have quite an impact. Not complying with it means a risk of a hefty fine because of strict enforcement through proactive and regular inspections. Not after reports or incidents but in advance. After all, the importance is great. Among other things, our nuclear power plants, water supply and hospitals must remain safe. Everyone who supplies them must cooperate - and so must all companies in that chain.Conclusion
For organizations, NIS2 means they must expand their approach to information security, with a strong focus on management responsibility, risk management, supply chain visibility, and demonstrable adherence to proven standards. With the Perium platform , you can quickly make the necessary preparations because NIS2 and the proven standards—including insight into their overlap—are already available. In addition, Perium provides you with a reliable ISMS, including risk management, with templates and a robust automated control function (PDCA). This ensures that the right actions are taken by the right people at the right time.Start today
Is your organization ready for the future? Don’t lose customers—don’t wait any longer—and discover how Perium and the NIS2 Quality Mark can help your organization.
Together, we'll make sure your organization not only complies with NIS2, but also becomes stronger, more secure and future-proof.

Perium scores an 8.5 in a customer satisfaction survey
Perium scores an 8.5 in a customer satisfaction survey and is committed to customer-driven innovation. In its recent customer satisfaction survey, Perium received an impressive score of 8.5. The

Perium integrates the updated NEN7510:2024 standard into its platform
The latest version of the NEN7510 standard for information security in healthcare is now fully available within the Perium platform. The revision of the standard, which was published in

Perium is a member of Samenwerking Noord
We are proud to share that we have joined Collaboration North 🤩 Collaboration North connects public and private organizations around IT and digitalization, with