EU Council directive strengthens cybersecurity measures

29 November 2022

Elizabeth Pfeuti

New standardised ‘high level’ cybersecurity rules are being proposed for the EU by the European Council, which will bring more firms under this regulatory reach.
EU regulation

EU Council directive strengthens cybersecurity measures 

November 30, 2022

New standardised ‘high level’ cybersecurity rules are being proposed for the EU by the European Council, which will bring more firms under this regulatory reach.  

Called NIS2, this new directive will replace the current rules and create a baseline for cybersecurity risk management measures and reporting obligations.  

The new regulation will cover the same sectors as the current directive, including the energy, transport, health, and digital infrastructure industries.  

To widen the scope of rules, a size cap has been introduced. As a result, all medium and large-sized companies operating within the covered sectors will be affected. 

The widened scope means most companies within the public and private sectors as well as the EU as a whole will be covered. 

However, companies within the defence or national security, public security, law enforcement sector, judiciary, parliament, and central banks have been excluded.  

Ivan Bartoš, Czech deputy prime minister for digitalisation and minister of regional development, said: “There is no doubt that cybersecurity will remain a key challenge for the years to come. The stakes for our economies and our citizens are enormous. Today, we took another step to improve our capacity to counter this threat.” 

The legislation has also established mechanisms for successful cooperation and updated remedies and sanctions to allow effective enforcement.   

Reporting obligations have been streamlined to avoid over-reporting and creating an excessive burden for the entities.  

Additionally, the directive will establish the European Cyber Crises Liaison Organisation Network (EU-CyCLONe), which will support the coordinated management of large-scale cybersecurity incidents and crises.  

Following the introduction of NIS2, member states within the EU will have 21 months to enforce the directive into national law. 

NIS2 has been approved by the European Parliament, which recently approved the Digital Operational Resilience Act (DORA).  

This regulation is designed to mitigate ICT risks across the EU by harmonising existed rules around this.  

Specific implications for European financial services firms and their ICT providers have been integrated in this.  

Regulated entities have 24 months to implement DORA.  

Latest News

SHareholder meeting

Minerva Proxy Update: Shareholder voting signals continued executive pay, board accountability focus

SHareholder meeting

US SEC moves to rescind Rule 14a-8, risks damaging shareholder proposal process

SHareholder meeting

AI-related risks outstripping company governance practices, Railpen report cautions

SHareholder meeting

ASX governance reform: simplification must preserve decision-useful disclosure

SHareholder meeting

Accountability versus allocation: Who is corporate reporting for?

SHareholder meeting

SFDR Review Moves Forward, But Key Questions Remain for Investors

Featured Briefings

Minerva Briefing

Global IPOs: Growth, governance and risk

Minerva Briefing

Shareholder Proposal Voting Trends 2026 H1

Minerva Briefing

Virtual-Only AGMs

Minerva is a global provider of sustainable stewardship solutions with over 30 years of expertise. Minerva empowers investors by providing essential tools, including ESG research and data and expert insights, enabling them to navigate the intricate and ever-evolving landscape of stewardship and proxy voting, whilst ensuring their decisions are well-informed and aligned with sustainable principles.

Related Stories

US lawmaker drives for greater transparency at dual-class share companies

US lawmaker drives for greater transparency at dual-class share companies

August 25, 2026
Read More
SFDR

SFDR Reset Progresses, but Credibility Gaps Remain

June 24, 2026
Read More

Income “Insanity”: Sanders Lambasts Tesla CEO Musk’s U$1tn Pay Package

December 11, 2025

Jack Grogan-Fenn

Read More

Generating Guidance: UK to Set Statutory Advice for Private Pensions

December 5, 2025

Jack Grogan-Fenn

Read More

Case Closed: SEC Stops SolarWinds Data Breach Lawsuit

November 24, 2025

Jack Grogan-Fenn

Read More

Climbing Cyber Concerns: UK Government Issues Warning to Companies

October 15, 2025

Jack Grogan-Fenn

Read More