The NIS2 Directive has introduced new, binding cybersecurity requirements for organizations across the European Union, emphasizing that cybersecurity is a core business risk requiring executive-level oversight. The directive mandates enhanced risk management, supply chain security, incident response, and reporting measures, as well as increased management accountability. In Spain, NIS2 became binding in January, prompting organizations to adopt modern security technologies and integrate comprehensive strategies to protect sensitive data and ensure regulatory compliance. Industry leaders highlight the need for systematic approaches to compliance and stress that IT risks must be managed as business risks under the new regulatory landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The Finnish Transport and Communications Agency awarded €1.65 million to 35 applicants to help small and medium-sized organizations covered by the Cybersecurity Act improve cybersecurity and risk management. The grants support 2026 projects aimed at meeting statutory requirements for essential and important communication networks and information systems.
France’s cybersecurity agency ANSSI opened a pre-registration portal to support organizations preparing for NIS2 compliance and identification under the national implementation process. The move marked a new operational step in France’s rollout of NIS2 obligations.
Initial story creation
Traficom’s Cyber Security Centre said implementation of Finland’s Cybersecurity Act was underway and that incident notifications under the new NIS2-based reporting obligations had started well after the law took effect in early April. It urged covered organizations to register in the operator register by 2025-05-08 and announced a 2025-05-12 webinar on implementation and supervision.
Finland's Parliament approved the Cybersecurity Act implementing NIS2 Directive obligations, and the new requirements took effect on 2025-04-08. The law introduced new risk management and incident reporting obligations across multiple sectors, with affected entities required to register in the operator registry.
Traficom announced it was preparing a recommendation to support implementation of the NIS2 Directive’s cybersecurity risk management measures in Finland. The guidance was intended to help supervisory authorities and covered sectors interpret baseline obligations during national legislative drafting.
The European Commission published proposal 52022PC0454 on 2022-10-21, setting out EU-wide horizontal cybersecurity requirements for products with digital elements. The proposal marked an earlier policy development in the broader regulatory story preceding Finland’s later national implementation measures.
18 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcecio.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcezdnet.fr
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceeur-lex.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.