NIS2 and the financial sector — scope of application
The NIS2 Directive (Network and Information Security Directive 2) broadens the scope of cybersecurity regulations to essential and important entities in the European Union. The financial sector, including insurance, is explicitly covered as an essential sector.
For insurers, NIS2 coexists with DORA, creating a complementary regulatory framework. While DORA focuses on digital operational resilience specifically for the financial sector, NIS2 establishes broader cybersecurity standards. Article 4 of DORA provides for the lex specialis principle — in areas where DORA and NIS2 overlap, DORA applies.
In practice, insurers must comply with both regulations, but DORA serves as the primary reference for areas it regulates in detail. NIS2 fills gaps that DORA does not address, creating a comprehensive security posture requirement.
Cybersecurity risk management obligations
NIS2 requires essential entities to implement appropriate and proportionate cybersecurity risk management measures. For insurers, this includes: risk analysis and information system security policies, incident handling, business continuity and crisis management, and supply chain security.
Particularly relevant for the insurance sector is supply chain security. Insurers use dozens of ICT providers — from actuarial systems to customer service platforms. NIS2 requires assessing each provider’s security and incorporating supply chain risks into the overall risk assessment.
The management body bears personal responsibility for approving risk management measures and overseeing their implementation. Board members must undergo regular cybersecurity training to maintain adequate awareness of evolving threats.
Incident reporting — requirements and timelines
NIS2 introduces a three-tier system for reporting significant cybersecurity incidents. An early warning must be submitted to the CSIRT within 24 hours of detecting the incident. An incident notification follows within 72 hours. A final report is due within one month.
For insurers, a significant incident is one that causes substantial operational disruption or financial losses, affects other natural or legal persons causing considerable damage, or could potentially have caused such effects.
In the context of DORA, which also requires ICT incident reporting, insurers must ensure consistency in reporting processes to different authorities. DORA-compliant reporting can simultaneously satisfy NIS2 requirements, provided processes are properly configured.
Supply chain security in the insurance sector
The ICT supply chain in the insurance sector is particularly extensive and complex. It encompasses core insurance system providers, claims management platforms, actuarial tools, CRM systems, cloud infrastructure, analytics services, and broker integrations.
NIS2 requires insurers to consider vulnerabilities specific to each provider, the quality of providers’ cybersecurity products, providers’ cybersecurity practices (including secure development procedures), and the overall quality and resilience of the supply chain.
In practice, this means conducting regular security audits of providers, verifying their certifications (ISO 27001, SOC 2), and implementing security clauses in contracts. For critical insurance system providers, continuous monitoring of their security posture is required.
Board responsibility and training
NIS2 introduces an unprecedented level of board responsibility for cybersecurity. Insurance company board members must approve cybersecurity risk management measures and oversee their implementation. They may bear personal liability for violations.
The directive also requires board members to undergo regular cybersecurity training. Training should cover the current threat landscape for the insurance sector, ICT risk management fundamentals, and regulatory consequences of non-compliance.
For insurers, this means formally incorporating cybersecurity into board and supervisory board meeting agendas, designating a person responsible for cybersecurity at the management level, and establishing regular security status reporting to the board.
Penalties and enforcement
NIS2 provides for severe penalties for non-compliance. For essential entities (including insurers), fines can reach 10 million euros or 2% of total annual turnover — whichever is higher.
Supervisory authorities can also order specific remediation actions, issue public warnings identifying the non-compliant entity, and in extreme cases, temporarily suspend certifications or authorizations.
The interaction between NIS2 and DORA enforcement means that a single regulatory body may assess compliance with both frameworks, underscoring the need for a coherent approach to compliance across all applicable cybersecurity regulations.
How nFlo supports NIS2 compliance
nFlo helps insurers achieve and maintain NIS2 compliance. We conduct comprehensive cybersecurity assessments against NIS2 and DORA requirements, identifying gaps and prioritizing remediation actions.
Our services include supply chain security audits, designing incident reporting processes consistent with both regulatory frameworks, board-level cybersecurity training, and continuous 24/7 SOC monitoring.
With over 500 projects and deep understanding of the financial sector, nFlo is a partner that helps insurers not only meet formal requirements but genuinely elevate organizational security posture.
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
Related terms
Our services
- NIS2 for hospitals — implementation and compliance
- NIS2 for local government — municipalities implementation
