NIS2 Directive and the Railway Sector – What Changes Lie Ahead?
The implementation of the NIS2 Directive through amendments to Poland’s National Cybersecurity System Act will not mean a revolution for all participants in the railway sector. Michał Młotek, Deputy Director of the Office for the Protection of Classified Information and Defence Affairs at Polish State Railways (PKP), explains which organisations are likely to be most affected by the new regulations.
The expert notes that organisations that have already adapted their operations to the requirements of the NIS1 Directive will primarily need to incorporate the changes introduced under the new framework. The new regulations will present a much greater challenge for entities classified as important or essential. In their case, it will be necessary to align information security management processes with the requirements specified in the updated legislation.
“Regardless of the scale of the changes, it is essential to analyse the entire infrastructure and the services provided,” emphasises Michał Młotek. He adds that such an assessment makes it possible to determine which organisational and technical measures are needed to meet the new requirements.
Michał Młotek’s remarks demonstrate that the impact of the NIS2 Directive on the railway sector will vary from one organisation to another. For some, it will mean updating existing solutions and procedures, while for others it will become an opportunity to comprehensively strengthen and organise processes related to cybersecurity management and the protection of critical services.