The second EU Network and Information Security directive, NIS-2 for short, raises the required level of security across Europe noticeably. “Doesn’t concern us, we’re in Switzerland” misses the point: through supply chains, subsidiaries and services for EU customers, many companies here land squarely within its scope.
Why Switzerland isn’t off the hook
NIS-2 explicitly covers supply chains. If you provide critical services to European customers, belong to a group headquartered in the EU, or act as a supplier in regulated industries, the requirements will be passed down to you contractually sooner or later, even without an EU office of your own.
Cyber security becomes the leadership’s duty
What’s genuinely new about NIS-2 is organisational rather than technical: the directive puts the obligation directly on the leadership level. Management and the board can no longer push the topic onto IT. In practice that means:
- Identify, assess and document risks.
- Implement measures appropriately and demonstrably.
- Report incidents within the prescribed deadlines.
- Review effectiveness regularly.
Four steps, without overreacting
No one has to change everything overnight. A measured approach works best:
- Clarify exposure. Through which business relationships does your company fall within scope?
- Determine maturity. A structured assessment shows where you stand.
- Establish governance. Responsibilities, reporting lines and decision-making belong at leadership level.
- Set up a roadmap. Prioritise measures by risk and impact.
What it comes down to
NIS-2 is less an IT project than a leadership task. Acting early reduces regulatory pressure. As a side effect worth having even without the directive, it also makes the whole company more resilient.
Would you like to have your exposure and maturity assessed? Book a no-obligation intro call.