In recent years, there have been several important developments in the European Union’s cybersecurity policy. NIS2 has come along, with requirements no longer limited to critical infrastructures, but also covering many other areas that have not been regulated sectors from a security point of view – they had only to comply with contractual or corporate requirements at best. The market will soon be in great need of high level expertise if the players are to comply with the letter of the law and, not least, to conduct secure business.
We spoke to Tamás Tóth, GRC Consultant at EURO ONE’s InfoSec Business Unit, about the complexity of the regulation. He and his team are responsible for general information security consulting activities, conducting various surveys, writing policies and procedures, as well as implementing GRC platforms and developing their content. The company has been involved with the NIS2 Directive since the summer of 2022 and has been monitoring developments ever since. NIS2 covers food processing and retailing, manufacturing, postal and courier services, and a long list of new sectors that have not been subject to such legal information security requirements, he told ITBUSINESS.
More organizations may be affected indirectly, as those who are essentially covered by the legislation will have to extend various cybersecurity requirements to their suppliers as well. EURO ONE has identified two main drivers for adoption in the area of information security or cybersecurity: the need to manage real risks and the need to comply with legislation, also known as compliance pressure.
So what needs to be done?
The detailed requirements will be published soon; in the meantime we can rely on the official EU text of the NIS2 Directive and on the requirements detailed in the Hungarian Act XXIII of 2023 on cybersecurity certification and cybersecurity supervision, said Tamás Tóth. Based on this, the main requirements include the designation of an information security officer; the application of information security policies and continuous risk management; and the management of cybersecurity incidents.
These should also be reported to the relevant authorities, cybersecurity awareness training should be conducted and basic cyber hygiene practices should be applied on the user side. One such good practice is secure password management. In addition, strong encryption and secure communications and physical security measures should be applied. Compliance with all these requirements should be audited every two years by an external, independent auditing organization.
System Integrator and Information Security Advisor
EURO ONE can support to achieve compliance as a system integrator, for example by implementing network security, endpoint protection, multi-factor authentication solutions, and by deploying and operating SIEM (especially NetWitness) and SOAR systems.
SIEM systems are centralized log analysis systems, the technology collects event log data from various sources (e.g. servers, endpoints, network devices), identifies through real-time analysis out-of-normal activities that may indicate an information security incident. Security analysts then can use the information to start an investigation into what happened.
SOAR systems can assist cybersecurity analysts in automating processes related to information security incident management and other security activities, and in gathering additional information based on built-in rules and established processes. Here, specific incident management plans can be mapped out in the form of so-called playbooks, which the SOAR system guides the user through, especially during frequently repetitive and time-consuming tasks.
On the other hand, EURO ONE can also act as a cybersecurity consultant to assist the organizations concerned in conducting gap-, risk- and business impact analyses, as well as in the preparation of policies and related processes, and in providing professional support to the information security officer, said Tamás Tóth.
Here comes the SOC expert

„EURO ONE’s InfoSec business will be 20 years old in 2024. During this time, they have worked with many major companies in sectors such as critical infrastructure, energy and financial institutions. We are also present in the education sector, and we have successfully concluded projects with NATO and several major international corporations on an international level,” said Tamás Tóth.
The benefits of GRC
GRC, or Governance Risk Compliance platforms, can replace Excel spreadsheets and can be used to map organizational units, processes and records. They can capture and manage risks, audit findings and NIS2 requirements. Email notifications, external integration options, customizable interfaces, custom workflows help users. EURO ONE also delivers GRC solutions as a complex enterprise solution – such as the Archer GRC platform – and as a simpler, more cost-effective platform tailored to the needs of mid-sized companies. This is accompanied by training, providing the necessary information and guidance for use.
The detailed Hungarian requirements for NIS2, including technical and other organizational measures, have not yet been released, but are expected to be published in the form of a ministerial decree. Organizations operating in the sectors covered by the Cybersecurity Act are advised to check with their lawyers whether they fall under the scope of the legislation and to start their preparations in time.
The next legal deadline is 30 June 2024 for official registration, classification of information systems and designation of the information security officer. Preparing for an audit involves a complex approach, as requirements that cover both processes and the technological environment must be met. It is prudent to seek the assistance of a consultant who can support stakeholders in all areas and throughout the entire preparation and audit process from the outset.
More information: nis2iranyelv.hu







