Skip to content
Knowledge base Updated: February 5, 2026

NIS2 and competencies in cybersecurity: What roles and skills are key?

The NIS2 directive forces companies to build cyber security teams. Learn the key roles and skills identified by ENISA to meet the new requirements.

The NIS2 Directive represents a fundamental shift in the approach to cyber security across the European Union, imposing strict new obligations on thousands of Polish companies. However, implementing advanced technologies and procedures is only half the battle. The key to true digital resilience is people - skilled professionals capable of managing risks, responding to incidents and building a secure architecture. An analysis published by the European Union Cyber Security Agency (ENISA) sheds light on what roles and competencies key and important players will need to meet the demands of the new regulatory reality.

The ENISA report is not just a theoretical job listing, but more importantly a strategic roadmap for boards, IT directors and CISOs. It points to the urgent need to redefine the structure of security teams, identify competency gaps and plan development activities. In the face of a global talent shortage in the cybersecurity industry, understanding exactly who to look for, what skills to develop internally and when to reach out for external support becomes a key success factor in NIS2 implementation.

Shortcuts

What is the NIS2 directive and why is it forcing a revolution in personnel management?

The NIS2 (Network and Information Security 2) Directive is an EU regulation that significantly expands and tightens cyber security requirements for a broad spectrum of economic sectors. It aims to raise the overall level of cyber resilience across the EU by harmonizing regulations and obligations. Unlike its predecessor, NIS2 covers significantly more entities, introduces harsher penalties for non-compliance and places direct responsibility on executives.

This shift in perspective from purely technical to managerial is the heart of the HR revolution. NIS2 requires that cybersecurity become an integral part of business strategy, not just the responsibility of the IT department. This means that companies must not only implement the appropriate technical measures, but also build competent teams capable of operating, monitoring and developing them. It becomes necessary to formally define roles, assign responsibilities and ensure the continuous upgrading of personnel skills, which for many organizations means the need to create cyber security structures from scratch.

These requirements directly translate into the labor market. ENISA forecasts a surge in demand for cybersecurity professionals, which, combined with the already existing talent shortage, creates a huge challenge for HR departments and managers. Companies need to prepare for intense competition for the best experts, while also investing in the development (upskilling and reskilling) of existing employees to fill skill gaps and ensure compliance with the directive.

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

What entities are covered by NIS2 and what obligations do they have?

The NIS2 directive divides organizations into two main categories of entities: essential entities (EE) and important entities (IE). This classification depends on the size of the organization and the criticality of the sector in which it operates. Essential entities include large companies in sectors of strategic importance, such as energy, transportation, banking, financial markets infrastructure, health care, drinking water, wastewater, digital infrastructure, public administration and space.

Important entities are generally medium-sized companies in the same sectors, as well as entities in other critical industries, such as postal and courier services, waste management, chemical production and distribution, food production and processing, and manufacturing (e.g., medical devices, computers, machinery). Both groups have similar risk management and incident reporting responsibilities, but critical entities are subject to more rigorous, proactive oversight, while important entities will be inspected mainly ex-post, i.e., after an incident has occurred.

Regardless of classification, all covered entities must implement a minimum set of security measures. These include policies for risk analysis and information systems security, incident handling, business continuity management, supply chain security, security in acquiring, developing and maintaining systems, and the use of cryptography and encryption, among others. Performing these tasks requires having within the company’s structures or providing access to specialists with appropriate, diverse competencies.

What role does the board and management play in the NIS2 strategy?

One of the most important changes introduced by NIS2 is the imposition of direct responsibility for cyber security on the governing bodies of key and important entities. This means that the board of directors can no longer delegate this responsibility solely to the IT department. Executives must oversee the implementation of risk management measures, and can be held personally liable for negligence in this area.

This change is forcing managers to actively engage and understand cyber security issues. They must not only approve budgets, but also participate in strategy development, understand the threat landscape and evaluate the effectiveness of implemented safeguards. The directive also requires that members of governing bodies receive regular training to identify risks and assess cyber security management practices and their impact on the organization’s operations.

The role of the board, then, is to ensure that cyber security is treated as a strategic priority. They are the ones who need to create a culture of security within the organization, provide adequate resources - both financial and human - and support chief information security officers (CISOs) in their efforts. Without clear support and commitment “from the top,” even the best team of specialists will not be able to effectively secure the organization in accordance with NIS2 requirements.

What four key families of cybersecurity roles does ENISA identify?

To help organizations organize their staffing structure, ENISA has identified four main families of cyber security roles that are essential for comprehensive security management. Each of these families groups together positions of similar nature and responsibility, creating a logical model for team building. Understanding this division is key to properly assigning tasks and recruiting the right professionals.

The first family is Managerial (Managerial) roles, which focus on strategy, risk management, compliance and oversight of the overall security program. The second is Technical (Technical) roles, which include professionals responsible for designing, building and implementing secure systems and architecture. The third family, Operational (Operations), focuses on the day-to-day maintenance, monitoring and defense of information systems. The final, fourth group, is made up of roles

Analysts (Analyst) who are involved in data analysis, incident investigation and threat intelligence (threat intelligence).

This division allows for a more precise definition of staffing needs. A small company may need a single specialist who combines tasks from several families, while a large corporation will build specialized teams within each family. Regardless of scale, any organization covered by NIS2 must ensure competency coverage in all four areas, whether through internal resources or support from external service providers.

Four families of cyber security roles according to ENISA

Role familyMain objectiveExamples of positionsManagerialStrategy, risk, compliance, oversight.CISO, Risk Manager, Auditor. TechnicalDesign, Build, Implement.Security Architect, Security Engineer.OperationalMaintenance, monitoring, defense.Security Administrator, Pentester.AnalyticalData analysis, incident investigation.SOC Analyst, Threat Analysis Analyst.

Who are the specialists in the management role family and what are they responsible for?

The family of management roles is the strategic heart of cyber security operations. Professionals in these positions don’t necessarily need to have the deepest technical knowledge, but they must have an excellent understanding of the business and be able to translate digital risk into management language. Their main task is to create and oversee a security strategy that is consistent with the organization’s business goals.

The most important figure in this family is **Chief Information Security Officer (CISO). **. He or she is responsible for the entire cyber security program, from policies and procedures, to budget management, to communication with management and regulators. The CISO must ensure that the organization complies with all regulatory requirements, including those under NIS2. Another key role is the IT Risk Manager

, which focuses on identifying, assessing and mitigating risks associated with information systems.

This family also includes **Internal Security Auditors. **, who verify the effectiveness of implemented controls and compliance with policies, and Specialists in the field. Compliance, ensuring that regulatory requirements such as RODO or just NIS2 are met. These individuals act as a bridge between technology and the business, ensuring that investments in cyber security are appropriate to the organization’s risk appetite and deliver measurable value.

What tasks do technical experts such as a security architect perform?

Specialists in the technical family are the engineers and designers of digital fortresses. They are the ones who are responsible for ensuring that information systems are built secure from the ground up (security by design) and that they have adequate defense mechanisms. Their work is the foundation on which all other cyber security activities are based.

A key role in this group is the Security Architect. His or her job is to design the organization’s overall security architecture so that it is resilient to attacks, scalable and compliant with policies and standards. The Architect decides what security technologies (e.g., firewalls, SIEM systems, WAF) will be deployed and how they will be integrated with each other to create a coherent, multi-layered defense system.

Next to the architect is the Security Engineer, who is responsible for implementing, configuring and maintaining specific technology solutions designed by the architect. This may include configuring intrusion prevention systems (IPS), identity and access management (IAM) or implementing data encryption mechanisms. It is the work of engineers that translates strategic plans into security measures that work in practice.

What is the work of operational specialists, including pentesters?

While technical roles focus on building defenses, operational roles are on the front lines of defense, ensuring daily security and response readiness. These professionals are responsible for the ongoing monitoring, maintenance and testing of security systems to make sure they are working properly and able to fend off ongoing attacks.

One of the most important operational roles is the Security Administrator, who manages the day-to-day operation of security tools such as antivirus systems, firewalls and intrusion detection systems (IDS). He takes care of updates, responds to alerts and manages user privileges. His work is crucial to maintaining a sanitary and orderly IT environment.

This family also includes the Pentester, or ethical hacker. His job is to launch controlled attacks on a company’s systems to find and document security vulnerabilities before the real criminals do. Penetration testing is one of the NIS2 requirements for verifying security effectiveness. The pentester’s work provides invaluable feedback to tighten defenses and improve overall security.

Who is a security analyst and why is his role crucial?

Security analysts are the detectives of the digital world. Their job is to collect, correlate and analyze vast amounts of data from various systems to detect patterns that may indicate an attempted attack or an incident already underway. In the age of Advanced Persistent Threats (APTs), the role of the analyst is absolutely crucial for early detection and response.

The most common position in this family is the SOC (Security Operations Center) Analyst. He works with SIEM systems that aggregate logs from across the IT infrastructure. His job is to review alerts generated by the SIEM, separate false alerts from real threats and escalate the latter to the Incident Response Team. It is the SOC analysts who are the eyes and ears of the organization in the cyber world.

Another important specialization is **Threat Intelligence Analyst. **. It does not wait for alerts, but proactively seeks information about new threats, tactics and tools used by cybercrime groups. He analyzes darknet reports, monitors malware campaigns and provides the organization with information to prepare for future attacks. His work makes defense proactive, not just reactive.

What technical skills (hard skills) are most in demand?

Successful cyber security roles require a wide range of specialized technical skills. ENISA points out that regardless of the family of roles, there is a core of competencies that are absolutely fundamental. These include, first and foremost, an in-depth knowledge of network security, operating systems (Windows, Linux) and communication protocols.

Depending on the specialization, more advanced skills are desired. For technical and operational roles, familiarity with security tools such as SIEM, IDS/IPS or WAF is key, as is the ability to write scripts (e.g., in Python) to automate tasks. Pentesters must additionally be proficient in penetration testing tools and have knowledge of the latest attack techniques. For analysts, on the other hand, the ability to analyze logs, network traffic and malware (malware analysis) is essential.

In the context of NIS2, Cloud Security skills are becoming increasingly important as more companies move their infrastructure to providers such as AWS, Azure and Google Cloud. Equally important is becoming knowledge of operational technology (OT) and industrial systems (ICS) security, which are regulated in many key sectors.

Why are transversal skills (soft skills) as important as technical skills?

ENISA strongly emphasizes that technical competence alone is not enough to build an effective cyber security program. Equally important, and often even more important, are the so-called transversal, or soft skills. These are the ones that determine whether a specialist can work effectively in a team, communicate with the business and operate under pressure.

One of the most important skills is communication. A security expert must be able to explain complex technical issues clearly and concisely to a non-technical audience, including management. He or she must be able to argue the need for investment in security, presenting the risks in a business context. During an incident, it is up to his or her communication skills to effectively coordinate actions and calm the situation.

Other key skills include problem solving, critical thinking and the ability to work in a team. Cyber security is a field in which there are rarely ready-made solutions. Professionals must be able to analyze unusual situations, think outside the box and make quick decisions under conditions of uncertainty. Effective defense and incident response is always the result of teamwork, so the ability to collaborate and share knowledge is absolutely essential.

What are the biggest challenges in attracting and retaining cybersec talent?

The biggest challenge identified in the ENISA report is the global and local **Shortage of qualified cyber security specialists **. Demand for experts far exceeds supply, leading to intense competition among companies. Organizations covered by NIS2 will have to compete for the same candidates not only among themselves, but also with technology companies and specialized security service providers, which often offer better financial terms and more interesting projects.

Another problem is talent retention (retention). Due to high demand, cybersec professionals often change jobs in search of better salaries, growth opportunities and new challenges. For companies, this means risking the loss of key employees and institutional knowledge. To retain the best, organizations need to offer not only competitive salaries, but also a clear career path, access to training and certification, and interesting, developing assignments.

The rapid pace of technological change is also a challenge. Knowledge in cyber security becomes outdated very quickly. Companies must invest in continuous training for their teams to keep up with new threats and defense technologies. Creating an effective continuous development program is costly and time-consuming, but necessary to maintain a high level of competence and ensure compliance with NIS2.

What competence-building strategies does ENISA recommend?

In response to the challenges of the talent shortage, ENISA recommends adopting a multi-track competency-building strategy that does not rely solely on external recruitment. Investing in the development of existing employees through upskilling and reskilling programs is key. Upskilling involves developing the skills of professionals already working in the security department, while reskilling is training employees from other departments (e.g., IT, data analytics) to prepare them for new roles in cyber security.

Another important strategy is to work closely with the education sector. Companies should engage in internship programs, apprenticeships and partnerships with technical universities to identify and attract talent early in their careers. Creating dedicated academic programs and supporting educational initiatives helps increase the pool of available professionals in the market in the long term.

ENISA also encourages the promotion and use of professional certifications. Certifications such as CISSP, CISM or OSCP provide objective confirmation of a candidate’s knowledge and skills, which facilitates the recruitment process. For employees, becoming certified is an important part of professional development, so companies should support them in the process, such as by funding training and exams. This creates a culture of continuous improvement and professionalism.

When is it worth considering the support of external experts, or MSSP?

The ENISA report clearly indicates that not every organization, especially in the small and medium-sized enterprise sector, will be able to build and maintain a fully competent in-house cyber security team on its own. In such cases, a strategic and often more cost-effective solution is to use Managed Security Service Providers (MSSPs).

Partnering with an MSSP gives you immediate access to a team of highly skilled experts with expertise and advanced technologies that a single company often could not afford. Third-party providers can take on some or all of the operational tasks, such as 24/7 network monitoring (as part of SOC as a Service), vulnerability management, incident response, or regular penetration testing.

The decision to use MSSP services should be based on a cost-benefit analysis and an assessment of one’s own capabilities. For many important entities, and even some key ones, a hybrid model of cooperation, in which a small in-house team coordinates activities and works with an external partner, will be the most effective way to meet NIS2 requirements. This allows them to optimize costs, provide access to top-notch specialists and focus their own resources on their core business activities.

Learn key terms related to this article in our cybersecurity glossary:

  • Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
  • SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
  • Firewall — A firewall, also known as a network firewall or security barrier, is a security…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist