Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

New Nozomi Networks Study Finds EU Critical Infrastructure Companies Are Not Ready for NIS2 Compliance

80% of organisation are lacking in programs associated with vulnerability mapping and threat hunting – Only half conduct regularly scheduled risk analysis exercises

by The Gurus
September 4, 2023
in Featured
Smart city
Share on FacebookShare on Twitter

Nozomi Networks has released the results of a new study highlighting an immediate need for EU critical infrastructure organisations to revise their operational technology (OT) security and risk management priorities to meet NIS2 compliance.

The report “Driving cyber resilience: the impact of the NIS2 Directive” found that the legislation appears to be a substantial challenge for most critical infrastructure organisations. Many still do not have visibility of all assets and networks to ensure full compliance and effective cyber protection.

With the Network and Information Security Directive (NIS2) to be incorporated in national laws by September 2024, EU critical infrastructure companies need to focus on risk management beyond IT to include OT. This makes it crucial for them to have greater visibility of all assets and networks, which requires regular risk analysis of operational networks.

The study amongst 300 IT security decision makers in large organisations across Germany, France, Sweden and the Netherlands, was conducted by Vanson Bourne and found that for critical information systems, only 50% of organisations follow a schedule in terms of conducting and updating a risk analysis. 34% do so on an ad-hoc basis and 15% of companies across Europe do not currently conduct any risk analysis at all, with an even higher number in France (29%) and Sweden (22%).

Andrea Carcano, CPO and Co-founder of Nozomi Networks commented on the findings: ““With NIS2 around the corner, critical infrastructure organisations across Europe need to take immediate action. By 2024, many will be required to revise security and risk management priorities, particularly for OT. The good news is effective technologies and deployment options are available to help organisations cover their bases. The key to effective network monitoring and risk management lies in using real-time information to inform an accurate risk view.”

The research also found that many organisations either only understand what threats or risks they face when they are forced into action, or do not understand them at all. Most lack programs associated with asset identification and inventory management (81%), vulnerability mapping / threat hunting (80%) and situational awareness / data analytics (75%).

The survey also reveals that while 35% of organisations give ultimate responsibility for securing OT and IoT devices and networks to the CISO, many others rely on the IT department (24%) and/or OT operators (18%), amongst others.

And while the CISO has greater responsibility in Sweden (44%), France (43%) and the Netherlands (40%), in Germany only 21% of organizations rely on their CISO to secure OT, IoT devices and networks.

The survey underpins that role of the CISO clearly differs country-to-country, but with NIS2 coming into effect in 2024, organizations need to ensure they understand their OT and IoT assets, and perform asset inventory and vulnerability management for OT and IoT assets to perform root cause analysis and review events and activities during incident response.

ShareTweet
Previous Post

JUMPSEC research reveals UK ransomware attacks rose by 87% in the first half of 2023

Next Post

3 out of 4 cyberattacks in the education sector are associated with a compromised on premises user or admin account

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol