Skip to content
Cybersecurity

NIS2 for the insurance sector — obligations and implementation

How does the NIS2 directive affect the insurance sector? Cybersecurity obligations, incident reporting, supply chain risk management, and penalties for non-compliance.

NIS2 and the financial sector — scope of application

The NIS2 Directive (Network and Information Security Directive 2) broadens the scope of cybersecurity regulations to essential and important entities in the European Union. The financial sector, including insurance, is explicitly covered as an essential sector.

For insurers, NIS2 coexists with DORA, creating a complementary regulatory framework. While DORA focuses on digital operational resilience specifically for the financial sector, NIS2 establishes broader cybersecurity standards. Article 4 of DORA provides for the lex specialis principle — in areas where DORA and NIS2 overlap, DORA applies.

In practice, insurers must comply with both regulations, but DORA serves as the primary reference for areas it regulates in detail. NIS2 fills gaps that DORA does not address, creating a comprehensive security posture requirement.

Cybersecurity risk management obligations

NIS2 requires essential entities to implement appropriate and proportionate cybersecurity risk management measures. For insurers, this includes: risk analysis and information system security policies, incident handling, business continuity and crisis management, and supply chain security.

Particularly relevant for the insurance sector is supply chain security. Insurers use dozens of ICT providers — from actuarial systems to customer service platforms. NIS2 requires assessing each provider’s security and incorporating supply chain risks into the overall risk assessment.

The management body bears personal responsibility for approving risk management measures and overseeing their implementation. Board members must undergo regular cybersecurity training to maintain adequate awareness of evolving threats.

Incident reporting — requirements and timelines

NIS2 introduces a three-tier system for reporting significant cybersecurity incidents. An early warning must be submitted to the CSIRT within 24 hours of detecting the incident. An incident notification follows within 72 hours. A final report is due within one month.

For insurers, a significant incident is one that causes substantial operational disruption or financial losses, affects other natural or legal persons causing considerable damage, or could potentially have caused such effects.

In the context of DORA, which also requires ICT incident reporting, insurers must ensure consistency in reporting processes to different authorities. DORA-compliant reporting can simultaneously satisfy NIS2 requirements, provided processes are properly configured.

Supply chain security in the insurance sector

The ICT supply chain in the insurance sector is particularly extensive and complex. It encompasses core insurance system providers, claims management platforms, actuarial tools, CRM systems, cloud infrastructure, analytics services, and broker integrations.

NIS2 requires insurers to consider vulnerabilities specific to each provider, the quality of providers’ cybersecurity products, providers’ cybersecurity practices (including secure development procedures), and the overall quality and resilience of the supply chain.

In practice, this means conducting regular security audits of providers, verifying their certifications (ISO 27001, SOC 2), and implementing security clauses in contracts. For critical insurance system providers, continuous monitoring of their security posture is required.

Board responsibility and training

NIS2 introduces an unprecedented level of board responsibility for cybersecurity. Insurance company board members must approve cybersecurity risk management measures and oversee their implementation. They may bear personal liability for violations.

The directive also requires board members to undergo regular cybersecurity training. Training should cover the current threat landscape for the insurance sector, ICT risk management fundamentals, and regulatory consequences of non-compliance.

For insurers, this means formally incorporating cybersecurity into board and supervisory board meeting agendas, designating a person responsible for cybersecurity at the management level, and establishing regular security status reporting to the board.

Penalties and enforcement

NIS2 provides for severe penalties for non-compliance. For essential entities (including insurers), fines can reach 10 million euros or 2% of total annual turnover — whichever is higher.

Supervisory authorities can also order specific remediation actions, issue public warnings identifying the non-compliant entity, and in extreme cases, temporarily suspend certifications or authorizations.

The interaction between NIS2 and DORA enforcement means that a single regulatory body may assess compliance with both frameworks, underscoring the need for a coherent approach to compliance across all applicable cybersecurity regulations.

How nFlo supports NIS2 compliance

nFlo helps insurers achieve and maintain NIS2 compliance. We conduct comprehensive cybersecurity assessments against NIS2 and DORA requirements, identifying gaps and prioritizing remediation actions.

Our services include supply chain security audits, designing incident reporting processes consistent with both regulatory frameworks, board-level cybersecurity training, and continuous 24/7 SOC monitoring.

With over 500 projects and deep understanding of the financial sector, nFlo is a partner that helps insurers not only meet formal requirements but genuinely elevate organizational security posture.


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:


See also:

Our services

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist