Drinking water companies, like other vital companies, are preparing for IEC 62443, the international cybersecurity standard for Operational Technology.
The NIS2 Directive (Directive on security of networks and information systems) is an important step by the European Union to combat cyber threats and raise the level of cybersecurity within the EU. Organisations covered by this directive will have to comply with new cybersecurity requirements.
NIS2 (also known as EU directive 2022/2555), came into force on 16 January 2023 and replaces the previous EU directive 2016/1148. All EU member states must transpose the directive into national law by 17 October 2024 at the latest.
This directive focuses on:
The NIS2 legislation is going to apply to many organisations and certainly to companies that are part of the various vital sectors.
Drinking water companies and water boards are part of the vital infrastructure. To be prepared for NIS2 and to be demonstrably in control, drinking water companies and other vital companies need to comply to IEC 62443, the international cybersecurity standard for Operational Technology.
We were recently contacted by a drinking water company to assist them with compliance.
‘We did not know exactly where we stood with our digital resilience,’ says the company's CIO. With a baseline measurement, we helped them determine where they currently stand in order to create a plan to get in line with the NIS2 requirements.
‘After the baseline measurement, we not only know where we are,’ the CIO continued, ‘but also have a plan to take the right additional measures to further secure our OT environment.’
Using the plan provided, we helped this drinking water company to:
Vinçotte understands the crucial importance of cybersecurity. In our case studies, you will therefore not find any client names. This is because of:
Contact us to learn more about NIS2 and how we can help you make your organisation compliant.