NIS2 for Critical Communications: Professor Kai London on Meeting the New Resilience Standard
By the Finnish Express Technology Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The second Network and Information Security Directive has raised the bar for essential-service operators across Europe, and telecoms sits squarely within its scope. “NIS2 is not IT paperwork,” says Professor Kai London , a senior CISO and board advisor. “It puts personal accountability for cyber resilience on senior management — and for communications providers, the obligations are significant.” “The regulator's question has changed from ‘do you have a policy?’ to ‘can you prove it worked?’ For critical communications, that is the whole shift.” What NIS2 requires London distils the directive into a few operational demands: risk management proportionate to the threat, prompt incident reporting within tight timeframes, supply-chain security, and management accountability. “Essential and important entities must demonstrate resilience,” he says, “not merel...