Cybersecurity

NIS 2 and local authorities: what the directive changes

Risk management, event monitoring, continuity, audits — the minimum the directive expects, and how to get ready for it.

European Union flag in front of a modern institutional building

The European NIS 2 directive tightens the cybersecurity obligations of organisations classed as essential or important. As it is transposed into French law, it widens the range of bodies covered — including some local authorities and the services they run.

The minimum the directive expects

Leaving the legal detail aside, it comes down to a baseline of measures:

  • Risk management: identify your assets, the threats against them and your vulnerabilities, then decide what to tackle first.
  • Event monitoring: log it, watch it, and triage the incidents.
  • Business continuity: backups, recovery plans, and testing that they work.
  • Regular audits: measure the gap between where you are and where the rules say you should be.
  • Incident reporting: major incidents notified to the authorities, within set deadlines.

Where to start

  1. Map the information system: equipment, flows, remote access, suppliers.
  2. Audit the architecture and the configurations: firewall, segmentation, backups, directory.
  3. Sort out governance: appoint a security lead, write the security policy down, plan for a crisis before you’re in one.
  4. Get monitoring in place: infrastructure monitoring and security incident detection.
  5. Train your staff: compromised mailboxes are still one of the most common incidents in local government.

The overseas context

Local authorities here face constraints of their own: connectivity that isn’t always reliable, small teams, and residents who expect services to simply work. That argues for a step-by-step approach, with partners who can actually turn up on site.

We work with local authorities on audits, infrastructure hardening and monitoring. For governance and the virtual CISO role, we partner with TAVITA Cybersécurité.

Want an expert view on this?

Our engineers can audit your infrastructure and hand you a prioritised action plan.

Or call us: 0596 09 09 38