NIS2
In the words of Julia Lopez MP, "Cyber security threats facing the UK are evolving all the time. What was not even considered a risk five to six years ago is now a potential threat. We need to be adaptable in the face of this changing threat landscape and our legislation needs to be adaptable too." This statement underscores the urgency of staying ahead in the cyber security game.
The NIS2 Directive, the latest iteration of the Network and Information Security Directive, is a testament to the European Union's commitment to fortifying cyber defenses. This directive is a call to action for organizations to bolster their cyber security measures and to prepare for the integration of its provisions into local legislation by 17 October 2024.
As Dutch MEP Bart Groothuis aptly put it, "This European directive will help around 160,000 entities to strengthen their grip on security and make Europe a safe place to live and work. The law should also allow for the sharing of information with the private sector and partners around the world. If we are attacked on an industrial scale, we have to react on an industrial scale."
Free assessment
Ensure your organization is prepared for the upcoming NIS2 regulations with our complimentary compliance readiness assessment. Our expert team will evaluate your current measures, identify potential gaps, and provide actionable recommendations to help you meet the new standards. Don't wait until it's too late—take advantage of this free assessment to safeguard your business and stay ahead of regulatory requirements. Contact us today to schedule your assessment and secure your organization's future.
So, what does the NIS2 Directive mean for you?
The NIS2 Directive represents a significant step forward in the European Union's efforts to safeguard against cyber threats. It extends its protective reach to include medium and large entities across a variety of critical sectors, enforcing uniform rules to enhance cybersecurity. While initially focused on sectors such as healthcare and transport, the directive's scope now also covers banking, digital infrastructure, and even sectors deemed 'very critical' like water supply and ICT management.
Entities that are considered 'essential' due to their societal impact, including public communications networks, fall under the directive's purview. Small and micro-enterprises are generally exempt from these regulations, except in cases where they are of significant societal or economic importance. In such instances, member states are tasked with ensuring these enterprises comply with the directive.
This broadened scope is designed to improve the resilience of organizations in the face of increasing cyber risks, particularly as businesses continue to digitize their operations and assets. The NIS2 Directive is not just a regulatory framework; it's a commitment to a safer, more secure digital Europe for all.
Expert Panel Discussion
Join us for an insightful on-demand panel discussion where industry experts delve into the critical aspects of the NIS2 directive. Discover the differences between NIS1 and NIS2, the impact on businesses within and outside the EU, and the key cybersecurity requirements introduced by the new directive.
Learn about the steps for compliance, the penalties for non-compliance, and the implications for SMEs. Gain an understanding of how NIS2 enhances the cybersecurity posture of critical service providers and the role of national authorities in enforcement.
Explore how NIS2 contributes to the resilience of cross-border digital services and addresses the evolving cyber threat landscape. Hear from Eviden ServiceNow Practice on how they ensure compliance with NIS2's enhanced security requirements and the role of automation in maintaining compliance through ServiceNow solutions.
Don't miss the opportunity to learn from the best and stay ahead in the cybersecurity game. Watch the on-demand panel now and equip yourself with the knowledge to navigate the complexities of NIS2 compliance.
Partnering with the right experts to achieve and maintain NIS2 compliance is crucial. Make sure you enjoy peace of mind with tailored solutions, risk assessments, and training programs to meet the unique needs of your business
Digital Fortitude
Enhancing Resilience in the
Age of Cyber Evolution
Empower Compliance
with Eviden's Secure Horizons, Built on ServiceNow
The Challenges of Compliance
In the realm of cybersecurity, compliance presents a multifaceted challenge that organizations must navigate with diligence and foresight. Here are some of the hurdles that entities may face:

Viability of Assets / IT Infrastructure
Ensuring that the IT infrastructure is robust and capable of withstanding cyber threats is paramount

Communication between Risk, Security, and TPRM
Often, security and risk management functions operate in isolation, leading to potential blind spots. Moreover, the compliance status of third and nth parties may remain elusive, adding to the complexity.

Proactive Resilience and Continuity Management
The use of disparate systems can result in delays when collating data related to services, operations, risk, and security. Additionally, the dependencies of services, processes, and systems might be poorly understood or outdated.

Stricter Reporting Requirements
For instance, the new Security Incident reporting notification timeline will be a stringent new requirement with mandatory legislation.

Complexity of Regulatory Compliance
As each country may interpret regulations differently, navigating the compliance landscape becomes increasingly intricate.

Organizational Complexity
Enterprises are not monolithic; they often operate across different countries and must align with existing frameworks, further complicating compliance efforts.

Manual Nature of Current Approaches
Many compliance processes today still rely heavily on manual intervention, which can be time-consuming and prone to errors.
Addressing these challenges requires a strategic approach that integrates risk management, security, and third-party risk management (TPRM) into a cohesive framework. By doing so, organizations can foster a culture of proactive resilience and ensure continuity in their operations, all while meeting the stringent demands of regulatory compliance and reporting.

The Answer to NIS2 Compliance: A Collaborative Approach
At Eviden, in partnership with ServiceNow, we are uniquely positioned to revolutionize your business's strategy for managing and assessing NIS2 compliance with the Now Platform®. Our approach is to foster collaboration and innovation, interlinking individuals, operations, and systems within your organization. Utilizing the NIS2 Workspace, we provide a visual representation of data related to the Common Security Principles (CSPs) and facilitate compliance assessment with the Directive through Integrated Compliance Management.
Our top-tier implementation and guidance integrate digital, cloud, big data, and security business segments to deliver a swift and robust NIS2 management solution. Eviden's extensive experience in working with Essential Services ensures that your compliance strategy is not only aligned with industry best practices but also maintains that alignment from the project's inception through to operational launch and beyond.
Join us in setting a new standard for NIS2 compliance management, where innovation meets efficiency, and resilience becomes a reality.

NIS2 Compliance Management with ServiceNow: Automation Meets Efficiency
The NIS2 Compliance Management (N2CM) solution, powered by ServiceNow, is a comprehensive toolset designed to facilitate the policy-based and automated upkeep of continuous compliance for customers across various geographies and industries governed by the NIS2 regulation. Built upon a unified platform for orchestration and action, N2CM empowers customers to identify, document, and report cyber incidents to the appropriate regulatory authorities, enforce compliance policies throughout hybrid and multi-cloud environments, and utilize intelligent automation to pinpoint and rectify non-compliant assets and functions.
At the heart of N2CM lies a commitment to automation and simplification, driving efficiency and replacing cumbersome, manual processes that are often slow and error-prone. Automated workflows not only provide greater assurance but also mitigate risk, streamlining compliance management for customers, especially those operating across national borders where NIS2 compliance requirements may diverge due to specific national laws and regulations.
Leading the charge with our risk advisory experts and supported by an enterprise platform for implementation and scalability, we ensure that businesses not only achieve robust compliance management but also reduce the total cost of compliance and circumvent revenue-based regulatory fines. With N2CM, complexities are diminished, assurance is heightened, and compliance becomes a seamless part of the business operation.
Securing Your Compliance Journey: The Final Step
With a ServiceNow and Eviden-led health check, your IT landscape undergoes a thorough examination, including the current functionalities of ServiceNow, to determine the alignment and quality of data with respect to NIS2 requirements. Eviden will conduct a meticulous gap analysis to compare your current capabilities against the stipulations of NIS2 article 21.
The outcome is a collaborative effort to create a roadmap to compliance that demands minimal effort. Once the primary compliance measures are in place, Eviden will recommend a review to explore opportunities for automation, integration, and consolidation, aiming to maximize value by:
- Protecting critical assets and processes from cyber threats.
- Strengthening controls on high-risk vendors.
- Reducing operating costs to enhance efficiency.
What's Next?
Take the next step towards fortifying your digital infrastructure and achieving compliance. Get in touch with us. Book your assessment with one of our experts today and learn how we can work together to accelerate your journey to compliance and digital resilience.
Get in Touch

Richard Motteram
Global Head of Product & Portfolio, Eviden ServiceNow Practice
+44 7824846965
Dalveer Basi
Advisory & Pre-sales Solution Consultant, ServiceNow Practice

Mark Gustovich
Global Head of Sales, ServiceNow Practice
+1 8183244845