๐Ÿ“ Europe ยท NIS2 Directive (EU) 2022/2555 ๐Ÿ‡ฎ๐Ÿ‡น Italian Version
๐Ÿ“š Simplified Guide

NIS2 for European SMEs

A practical guide to understand and apply the cybersecurity requirements of the NIS2 Directive. Simple explanations, concrete examples, links to official documents.

โš ๏ธ Important Disclaimer

This guide is an informal summary created by Infodiz to facilitate understanding of the NIS2 Directive for European SMEs. It has no legal value. For the official and binding text, always refer to the original ENISA documents and the national transposition legislation in your Member State.

1

Your Security Policy

โ“ What the law says (in simple words)

The NIS2 Directive states that every company must have a "cybersecurity policy" โ€” a document explaining how the company protects its systems and data.

The policy can be brief, but must contain this information:

๐Ÿ“ What you must do (practical list)

๐Ÿ“‹ Practical example for an SME

"Our company is committed to protecting customer data and IT systems through: monthly software updates, quarterly training on cyber risks, weekly backups of critical data, and annual security review. The responsible person is John Smith (security@company.com)."

๐Ÿ”— Article 1.1.1 โ€” ENISA Guidance
2

Roles and Responsibilities

โ“ What the law says

You must assign specific roles for cybersecurity. Even a single person can be enough, but it must be clear who does what.

๐Ÿ“ What you must do

๐Ÿ“‹ Minimum roles for an SME

RoleWhat they do
Security ManagerCoordinates everything, reports to management
Backup ContactVerifies that backups work
Updates ContactApplies security patches
๐Ÿ”— Article 1.2.1 โ€” 1.2.6 โ€” ENISA Guidance
3

Risk Management

โ“ What the law says

You must carry out a risk assessment โ€” understand what could go wrong (hacker attack, data loss, hardware failure) and how serious it is.

๐Ÿ“ What you must do

๐Ÿ“‹ Practical example

RiskLikelihoodImpactAction
RansomwareHighHighAntivirus + Backup
Customer data lossMediumHighDaily backup
Website downMediumMediumHosting with 99% uptime
๐Ÿ”— Article 2.1.1 โ€” 2.1.4 โ€” ENISA Guidance
4

Incident Management

โ“ What the law says

If a cyber incident occurs (attack, data breach), you must:

๐Ÿ“ What you must do

๐Ÿ“‹ Quick checklist for incidents

๐Ÿ”— Article 3.1.1 โ€” 3.6 โ€” ENISA Guidance
5

Business Continuity and Disaster Recovery

โ“ What the law says

You must have a plan to keep running if something serious happens (flood, fire, hacker attack).

๐Ÿ“ What you must do

๐Ÿ“‹ Backup example for SMEs

TypeFrequencyWhere
Customer databaseDailyCloud + Local
DocumentsWeeklyCloud
ConfigurationsMonthlyEncrypted local
๐Ÿ”— Article 4.1.1 โ€” 4.3 โ€” ENISA Guidance
6

Supply Chain Security

โ“ What the law says

Your suppliers (cloud provider, software house, hosting) are a risk. If a supplier is hacked, it can compromise you too.

๐Ÿ“ What you must do

๐Ÿ”— Article 5.1.1 โ€” 5.2 โ€” ENISA Guidance
7

Security in Acquisition and Development

โ“ What the law says

When you buy software or IT services, you must verify that they are secure. Don't buy just because it's cheap.

๐Ÿ“ What you must do

๐Ÿ”— Article 6.1.1 โ€” 6.10 โ€” ENISA Guidance
8

Cyber Hygiene and Training

โ“ What the law says

The human factor is the leading cause of incidents. You must train employees.

๐Ÿ“ What you must do

๐Ÿ”— Article 8.1.1 โ€” 8.2.3 โ€” ENISA Guidance
9

Encryption

โ“ What the law says

Sensitive data must be encrypted โ€” both in transit (HTTPS) and at rest.

๐Ÿ“ What you must do

๐Ÿ”— Article 9.1.1 โ€” 9.3 โ€” ENISA Guidance
10

Human Resources Security

โ“ What the law says

Employees are a risk โ€” when they join and when they leave.

๐Ÿ“ What you must do

๐Ÿ”— Article 10.1.1 โ€” 10.4.3 โ€” ENISA Guidance
11

Access and Authorisations

โ“ What the law says

Not everyone needs access to everything. Least privilege principle.

๐Ÿ“ What you must do

๐Ÿ”— Article 11.1.1 โ€” 11.7.3 โ€” ENISA Guidance
12

Asset Management

โ“ What the law says

You need to know what you have โ€” hardware, software, data. You can't protect what you don't know.

๐Ÿ“ What you must do

๐Ÿ”— Article 12.1.1 โ€” 12.5.3 โ€” ENISA Guidance
13

Physical Security

โ“ What the law says

Servers in the garage with the door open are not acceptable.

๐Ÿ“ What you must do

๐Ÿ”— Article 13.1.1 โ€” 13.3.4 โ€” ENISA Guidance