Explain it to me like I'm 5: Why does NIS2 matter?

Most people have never heard of NIS2. 

Yet it affects many of the services we use every day, from electricity and public transport to hospitals, banking apps and cloud services. 

To understand NIS2, think about all the things society depends on to keep running smoothly. If a cyberattack were to disrupt a hospital's systems, knock an energy provider offline or take down a major digital service, the impact would be felt by thousands, sometimes millions, of people. 

NIS2 is designed to reduce that risk. 

As a Governance, Risk & Compliance (GRC) Consultant at Sopra Steria, Arne Putzeys helps organisations understand what NIS2 means in practice and how they can strengthen their cybersecurity to meet its requirements. 


So, what is NIS2?

In simple terms, NIS2 is a European cybersecurity law that came into force in Belgium in 2024.


It sets out clear rules for organisations that provide services society relies on, such as healthcare providers, energy companies, transport operators, digital service providers and many others. 

The objective is straightforward: make sure these organisations are prepared for cyber threats and can continue operating when incidents occur. "NIS2 requires organisations to actively manage their cybersecurity risks, report serious incidents, plan for disruptions and make sure security is considered throughout their supply chain," Arne explains. 

Importantly, responsibility does not sit solely with IT departments. Senior management is also expected to understand cybersecurity risks and take accountability for them. 


Why should consumers care? 


When you turn on the lights, book a train ticket or visit a hospital, you're relying on organisations whose systems need to be secure and resilient. 

A cyberattack on a hospital, transport operator or energy provider could impact thousands of people and disrupt essential services. NIS2 helps organisations reduce those risks and recover more quickly when incidents occur. 

While consumers may never directly interact with NIS2, they benefit from the stronger cybersecurity standards it promotes behind the scenes. 


What does Arne do? 


Arne currently spends much of his time conducting NIS2 assessments for large organisations. Think of it as carrying out a health check, but for cybersecurity. 

Together with his team, he runs workshops with stakeholders from across the organisation to understand how they currently operate, what security measures they have in place and how they manage risk. The findings are then compared against NIS2 requirements and recognised industry best practices. 

"We look at where an organisation stands today, identify gaps and then create a roadmap that helps them improve their maturity over time," says Arne. 

That work involves much more than reviewing technical systems. It can include governance, risk management, incident response, business continuity planning and supplier management. Based on these discussions and findings, Arne assesses the organisation's cybersecurity maturity and helps create a practical roadmap that supports long term improvement. 


Sopra Steria's role 


Belgium's adoption of NIS2 created significant demand from organisations seeking guidance on what the regulation means and how to comply with it. 

Sopra Steria supports clients throughout that journey. Depending on the client's needs, Sopra Steria can support everything from NIS2 assessments to implementing security frameworks, risk management processes and governance structures. 

Arne has worked on both sides, helping organisations establish the foundations of strong cybersecurity and assessing how mature those capabilities are today. 


More than a compliance exercise 


While NIS2 is often discussed as a regulation, Arne sees it as something bigger than a compliance exercise. At its core, it's about helping organisations become more resilient and better prepared for an increasingly complex threat landscape. 

For him, the role offers a unique combination of stakeholder interaction, problem-solving and visible impact. "You get exposure to almost every domain of cybersecurity and can clearly see how organisations improve over time," he says. The variety of the role means every project brings new stakeholders, challenges and industries to learn from. And occasionally, the work offers a glimpse behind the scenes of some of Belgium's most important infrastructure. 

Not bad for a topic most people have never heard of. 

So if we had to explain NIS2 in one sentence, it would be this: 


NIS2 helps ensure that the organisations we depend on every day are better protected against cyber threats; and Arne helps them understand where they stand today and what they need to do to become more secure tomorrow.