Explain it to me like I'm 5: Why does NIS2 matter?

Most people have never heard of NIS2. 

Yet it affects many of the services we use every day, from electricity and public transport to hospitals and cloud services. 

To understand NIS2, think about all the things society depends on to keep running smoothly. If a cyberattack were to disrupt a hospital's systems, knock an energy provider offline or take down a major digital service, the impact would be felt by thousands, sometimes millions, of people. 

NIS2 is designed to reduce that risk. 

As a Governance, Risk & Compliance (GRC) Consultant at Sopra Steria, Arne Putzeys works on NIS2 projects helping organisations understand what NIS2 means in practice and how they can strengthen their cybersecurity to meet its requirements. 


So, what is NIS2?

In simple terms, NIS2 is a set of EU cybersecurity rules that became law in Belgium in 2024. 


It applies to organisations that provide essential services, including healthcare providers, energy companies or transport operators. 

The goal is simple: help these organisations prepare for cyber threats, respond effectively to incidents and keep critical services running. 

Organisations must actively manage cybersecurity risks, report serious incidents and continuously improve their resilience. Responsibility does not sit solely with IT teams. Senior management is also expected to understand cybersecurity risks and take accountability for them. 


Why should consumers care? 


When you turn on the lights, book a train ticket or visit a hospital, you're relying on organisations whose systems need to be secure and resilient. A cyberattack on a hospital, transport operator or energy provider could impact thousands of people and disrupt essential services. NIS2 helps organisations reduce those risks and recover more quickly when incidents occur. 

While consumers may never directly interact with NIS2, they benefit from the stronger cybersecurity standards it promotes behind the scenes. 


What does Arne do? 


Arne is a GRC consultant within the Cybersecurity Business Line. He is currently part of a project team delivering NIS2 expertise for a large public entity. 

"We look at where an organisation stands today, identify gaps and then create a roadmap that helps them improve their maturity over time," says Arne. 

Through workshops and stakeholder discussions, Arne helps the organisation understand its current cybersecurity maturity, identify areas for improvement and prioritise actions. By assessing existing controls, risk management practices and operating processes against NIS2 requirements and industry best practices, the team develops a pragmatic roadmap to strengthen resilience over time. 

One of the key principles behind NIS2 is continuous improvement. "NIS2 is not a one-time project with a fixed end date. Organisations need to continuously assess risks, adapt to new threats and keep improving their cybersecurity capabilities." 


Sopra Steria's role 


Belgium's adoption of NIS2 created significant demand from organisations seeking guidance on what the regulation means and how to comply with it. 

For organisations operating across several European countries, compliance can be even more challenging. Because NIS2 is a directive rather than a regulation, each country has transposed it into national law in its own way. Sopra Steria helps clients navigate these differences and build a consistent cybersecurity approach across multiple jurisdictions. 

Drawing on its experience in cybersecurity and regulatory compliance, Sopra Steria supports organisations in translating NIS2 requirements into practical actions and strengthening their cybersecurity maturity over time. 


More than a compliance exercise 


While NIS2 is often discussed as a regulation, Arne sees it as something bigger than a compliance exercise. At its core, it's about helping organisations become more resilient and better prepared for an increasingly complex threat landscape. 

For him, the role offers a unique combination of stakeholder interaction, problem-solving and visible impact. "You get exposure to almost every domain of cybersecurity and can clearly see how organisations improve over time," he says. The variety of the role means every project brings new stakeholders, challenges and industries to learn from. And occasionally, the work offers a glimpse behind the scenes of some of Belgium's most important infrastructure. 

Not bad for a topic most people have never heard of. 

So if we had to explain NIS2 in one sentence, it would be this: 


NIS2 helps ensure that the organisations we depend on every day are better protected against cyber threats, and Arne helps them understand where they stand today, navigate evolving requirements and continuously strengthen their resilience for the future.