' di lettura

NIS 2: From Regulation to Opportunity for Businesses


18 November 2025
Foto di Alessandro Scognamiglio
Alessandro Scognamiglio
Compliance Consultant Specialist
CATEGORIA
Compliance
Approfondimenti
colleghi a lavoro

Is cybersecurity just a technical issue?
Today, it represents a strategic asset for resilience, reliability, and business competitiveness. The NIS 2 Directive raises the level of responsibility in cybersecurity, turning regulatory requirements into a governance challenge for many organizations. Why is compliance essential? Because data and digital services are at the core of business operations: protecting them is critical to ensuring continuity, market trust, and competitive advantage.

 

Which Organizations Are Affected by NIS 2?

The new Directive significantly expands the scope of impacted entities. It no longer applies only to critical infrastructure and large operators, but also to SMEs in essential sectors such as energy, healthcare, transportation, manufacturing, and digital services. The regulation explicitly recognizes the role of ICT providers within digital supply chains. This category, in particular, greatly increases the number of organizations involved, as ICT services are now an integral part of operational continuity for many businesses.

What Changes for Companies Adopting NIS 2?

Cybersecurity is no longer solely an IT responsibility—it becomes a shared responsibility across the organization, involving top management, partners, and suppliers. Key priorities now include training, risk management, incident response planning, reporting to leadership, and supply chain controls. Failure to comply exposes organizations to significant penalties.

NIS 2 as a Strategic Asset

Forward-looking companies are turning compliance into a strategic lever by investing in training, prevention, and continuous monitoring. This approach reduces the risk of operational disruptions, protects reputation, and strengthens trust among customers and stakeholders.

At Deda, we have already launched a structured plan: we are registered with the ACN portal, have conducted internal assessments, and strengthened our monitoring systems, incident management processes, and employee awareness initiatives. We are ready to meet this challenge with an integrated and sustainable approach, with a constant focus on continuous improvement. The real question is: are we ready to see cybersecurity as an investment? At Deda, the answer is yes.

Explore Punto’s latest stories.