Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 6 sources · 3 days · First seen · Last updated
Categories: TECHNOLOGY
EU NIS2 cybersecurity implementation
Entities: NIS2 Directive · Italian Government · European Union · Law 5160/2024 · Agenzia per la Cybersicurezza Nazionale (ACN)
Overview
In late July 2026, Greece formally incorporated the EU’s NIS2 Directive into national law (Law 5160/2024), creating a broad framework that obliges entities in critical sectors—such as energy, transport, finance, health and public administration—to register with the National Cybersecurity Authority, adopt mandatory risk‑management measures and integrate cybersecurity into overall business resilience.
A few days later, the European Union Agency for Cybersecurity (ENISA) released sector‑specific procurement guidelines for hospitals, stressing the need to embed security requirements throughout the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements.
Together, these developments show the EU’s move from national legislative transposition to the rollout of practical, sector‑focused tools and clarifications aimed at achieving consistent cyber‑risk management across member states.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] ENISA released new guidelines for cybersecurity procurement in hospitals and health service providers. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] The guidelines emphasize integrating cybersecurity throughout the supply chain and procurement lifecycle. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] ENISA’s Threat Landscape 2024 reports the healthcare sector accounts for 8 % of ransomware incidents. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] Only 27 % of healthcare organisations have a dedicated ransomware‑defence programme and 40 % lack staff security‑awareness training. (4b657ecb-9ce2-44c5-868e-87ea7aa4c445)
- [○ 1 SOURCE] The Italian National Cybersecurity Agency (ACN) updated its FAQ on NIS2 responsibilities on 23 July 2026. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] The updated FAQ adds three new clarifications (FAQ ODA 10, ODA 11, ODA 12). (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] NIS2 requires board members of essential and important entities to approve, supervise, and train on cybersecurity risk‑management measures. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
- [○ 1 SOURCE] Italy’s implementing decree (d.lgs. 138/2024) incorporates NIS2 governance responsibilities into national law. (b4425eab-dc22-4fea-82b9-9dbcb419b68b)
Timeline
-
3 days ago
[TECHNOLOGY] 4 sourcesEU ENISA Issues New Hospital Cybersecurity Procurement Guidelines Under NIS2ENISA rolled out new hospital procurement cybersecurity guidelines, noting healthcare's 8 % share of ransomware hits, while Italy’s ACN updated NIS2 FAQ clarifying board‑level security duties.
-
6 days ago
[TECHNOLOGY] 2 sourcesGreece Adopts NIS2 Cybersecurity Directive, Raising Business Resilience StandardsGreece has enacted the EU NIS2 Directive via Law 5160/2024, broadening cyber‑security obligations for many sectors and mandating registration with the National Cybersecurity Authority.
Sources
banks.com.gr · campaniadih.it · cybersecitalia.it · dalealbo.cl · diritto.it · mononews.gr
This summary has been updated 1 time: see revision history