ISO 27001 – Cyber Security not just for IT
ISO 27001 - The IT standard that’s not just for IT
3 min read
Aine Murphy : Jun 25, 2026 4:23:18 PM
Most organisations think they have more time. They don't. NIS2 is not approaching — it is here. The EU transposition deadline passed in October 2024, and Irish organisations are now expected to demonstrate readiness. Enforcement is the next step.
If your board hasn't discussed NIS2, if your incident response plan hasn't been tested, and if your supply chain hasn't been assessed — this article is for you. The good news: there is a clear, proven path to compliance. The challenging news: the window to act without regulatory exposure is narrowing fast.
The Network and Information Security Directive 2 (NIS2) is the EU's landmark cybersecurity regulation, designed to raise the baseline of cyber resilience across critical and important sectors. Unlike its predecessor, NIS2 dramatically expands scope, stiffens penalties, and — most significantly — introduces direct personal accountability for senior leadership.
This is not an IT team problem. This is a boardroom problem.
Under NIS2, senior management can be held personally liable for cybersecurity failures. Approval, oversight, and understanding of cyber risk exposure are now legal obligations — not optional best practices.
NIS2 applies to medium and large organisations across two tiers of regulated sectors. If you operate in any of the following areas, you are almost certainly in scope.
NIS2 Regulated Sectors — Essential vs Important
|
ESSENTIAL ENTITIES Up to €10M or 2% global turnover |
IMPORTANT ENTITIES Up to €7M or 1.4% global turnover |
|
● Energy |
● Manufacturing |
|
● Healthcare |
● Food Production |
|
● Banking & Financial Markets |
● Waste Management |
|
● Transport |
● Postal & Courier Services |
|
● Digital Infrastructure |
● Managed Service Providers |
|
● Public Administration |
● Digital Service Providers |
Even if you believe your organisation falls outside these categories, consider your supply chain. If you supply or support an entity in scope, their NIS2 obligations flow directly to you through supplier security requirements.
The penalty regime under NIS2 is designed to compel action. Fines are not symbolic — they are calculated to hurt at the scale they apply to:
Financial penalties, however, are only part of the exposure. Regulatory investigations, mandatory remediation orders, reputational damage, and loss of client trust are outcomes that no fine calculation fully captures.
NIS2 mandates a structured, time-bound incident reporting process. Organisations that are unprepared — or who discover they have no documented process — will struggle to comply under pressure.
Mandatory NIS2 Incident Reporting Timeline
|
INCIDENT OCCURS T = 0 |
EARLY WARNING Within 24 Hours |
INCIDENT NOTIFICATION Within 72 Hours |
FINAL REPORT Within 1 Month |
This is not a reporting process you can build in the middle of a crisis. It must exist, be tested, and be owned — before an incident occurs.
Here is where many organisations discover a significant shortcut. ISO 27001 — the internationally recognised Information Security Management System (ISMS) standard — was built to address exactly the governance, risk management, and control requirements that NIS2 demands. An organisation with a mature ISO 27001 implementation has already done much of the heavy lifting.
How ISO 27001 Maps to NIS2 Requirements
|
NIS2 Requirement |
ISO 27001 Coverage |
Aligned |
|
Risk Management |
Clause 6 & Annex A |
✓ |
|
Governance & Leadership |
Clause 5 |
✓ |
|
Incident Management |
Annex A.16 / A.5.24 |
✓ |
|
Supply Chain Security |
Annex A.5.19–5.22 |
✓ |
ISO 27001 is not a silver bullet — NIS2 has sector-specific and regulatory requirements that go beyond the standard. But for most organisations, it provides the framework and the evidence of governance that regulators will want to see.
The Irish regulatory approach is progressive — guidance, then remediation, then escalation, then financial penalties. The organisations that will face the sharpest enforcement scrutiny are those that have done nothing, documented nothing, and demonstrated nothing.
You don't need to have solved NIS2 by next week. But you do need to have started — and to be able to show that you have.
To learn more about how CG Business Consulting can help your organisation speak with a member of our team:
From the consultation you will:
Visit: Reach Out to Ireland's Top Information Security Consultants
💬 Contact us now to begin your journey
ISO 27001 - The IT standard that’s not just for IT
It’s been another busy month for the world’s ‘professional’ hackers. Since the beginning of 2023, they founds gaps in the cyber security of the UK’s...
Every first Thursday of May, this year falling on May 1, 2025 we mark World Password Day, a global reminder of the crucial role strong passwords play...