NIS2 and the water sector — new obligations
The NIS2 directive (Network and Information Security Directive 2) replaces the original NIS directive and fundamentally changes cybersecurity requirements for critical infrastructure operators. The water and wastewater sector — supply and distribution of drinking water as well as collection and treatment of wastewater — is explicitly listed in Annex I of the directive as a sector of “high criticality.”
In practice, this means water utilities meeting the size criterion (at least 50 employees or 10 million EUR annual turnover) are automatically classified as essential entities. Smaller entities may be covered by regulation through a national authority decision if deemed significant for water supply continuity in a given area.
NIS2 transposition into national law occurs through amendments to each member state’s cybersecurity legislation. Water utilities must register with the relevant authority, designate a point of contact, and implement a range of technical and organizational measures.
Risk management requirements — Article 21 NIS2
The heart of the NIS2 directive is Article 21, imposing the obligation to implement appropriate and proportionate cybersecurity risk management measures. For a water utility, this means specific actions across ten areas.
A risk analysis and information system security policy requires developing a formal policy covering both IT systems and OT systems (SCADA, PLC, HMI). Risk analysis must account for water infrastructure specifics: legacy PLC controllers without vendor support, dispersed facilities with limited physical oversight, IT/OT convergence, and remote service access.
Incident handling mandates implementing procedures for detecting, analyzing, responding to incidents, and restoring normal operations. For water utilities, this means not only IT procedures but also OT incident response scenarios — for example, what to do when the SCADA system is unavailable while pumps operate autonomously.
Business continuity covers backup management, disaster recovery, and crisis management. In the water context, this extends beyond IT data backups to include PLC configuration backups, procedures for switching to manual control, and emergency water supply plans.
Supply chain security requires assessing risks associated with suppliers and subcontractors — including SCADA system vendors, OT integrators, service companies, and chemical suppliers using online ordering systems.
Incident reporting obligations
NIS2 introduces strict deadlines for reporting security incidents to the relevant CSIRT (Computer Security Incident Response Team).
An early warning must be submitted within 24 hours of detecting a significant incident. It should contain an initial assessment of whether the incident may have a cross-border dimension and whether there is suspicion of malicious intent.
An incident notification — within 72 hours — must contain an update to the early warning, an initial severity and impact assessment, and indicators of compromise (IoC).
A final report — within one month of the notification — should contain a detailed incident description, root cause, applied remedial measures, and any cross-border impact.
For a water utility, it is crucial to define what constitutes a “significant incident” in the OT context. Is SCADA system unavailability for 30 minutes a reportable incident? What about a detected but blocked remote access attempt? Clear escalation criteria must be established in advance and known to operational personnel.
Management liability
NIS2 introduces an unprecedented change — personal liability of senior management for cybersecurity. The water utility’s board must approve risk management measures, oversee their implementation, undergo cybersecurity training, and bear responsibility for compliance failures.
In case of identified violations, the supervisory authority can impose temporary bans on holding management positions on board members. This is a fundamental shift from previous practice, where cybersecurity responsibility rested with IT departments.
The board does not need to be technically expert, but must understand cybersecurity risks and make informed resource allocation decisions. Regular briefings from the security team or external partner, reviews of key security metrics, and participation in tabletop exercises — this is the minimum required by NIS2.
NIS2 implementation plan for a water utility
NIS2 implementation should proceed in phases, starting with an assessment of the current state.
Phase 1 (months 1-3): gap analysis. Conduct a security audit comparing the current security posture with NIS2 requirements. Inventory IT and OT assets. Identify critical systems and processes. Assess maturity of risk management, incident handling, and business continuity.
Phase 2 (months 3-6): implementing priority safeguards. IT/OT network segmentation. Deploy security monitoring. Develop and implement incident handling procedures. Configure OT system backups. Train operational staff and senior management.
Phase 3 (months 6-12): process improvement. Implement supply chain risk management. Conduct business continuity tests. Regular tabletop exercises. Review and update security policies. Register with the relevant national registry.
Phase 4 (ongoing): maintaining compliance. Regular internal audits. Continuous monitoring and SOC. Update risk analysis after infrastructure changes. Train new employees and periodically refresh knowledge.
Funding NIS2 implementation
NIS2 implementation costs for water utilities can be partially covered by available funding programs. Poland’s Cybersecure Water Supply program funds up to PLN 1.3 million for cybersecurity — including audits, network segmentation, monitoring systems, training, and SOC services.
National Recovery and Resilience Plan funds and Operational Program resources can be used for IT/OT infrastructure modernization, including cybersecurity components. A growing number of grant programs include cybersecurity as an eligible project cost.
nFlo supports water utilities in preparing funding applications, ensuring planned activities align with NIS2 requirements and maximizing the efficiency of resource utilization. NIS2 compliance is our specialty — from gap analysis through implementation to ongoing support.
Related topics
See also:
