Cart

    Sorry, we could not find any results for your search querry.

    NIS2: impact on your TransIP services

    The European NIS2 Directive imposes stricter requirements on the digital resilience of organisations that are important to the economy and society. In the Netherlands, NIS2 is being transposed into the Cyberbeveiligingswet (Cbw).

    Do you use services such as Web Hosting, a domain name, a VPS, OpenStack, or Kubernetes? This does not automatically mean that your organisation falls under NIS2. However, these services may form part of your network and information systems. If your organisation falls under NIS2, you should therefore include them in your risk analysis, security measures, incident process and supplier management.

    • This guide provides general information about NIS2 and TransIP services. No legal rights can be derived from this article.
       
    • If your organisation will fall under the Cyberbeveiligingswet, you will have to deal with a duty of care, reporting obligation and registration obligation.
     

     

    Does NIS2 apply to your organisation?

     

    Whether your organisation falls under NIS2 and the Cyberbeveiligingswet mainly depends on the sector in which you operate, the size of your organisation and, in some cases, the type of service you provide.

    For the formal assessment, use the NIS2 self-assessment from the RDI and the information from the NCSC about the Cyberbeveiligingswet.

     

    Always check this for your entire organisation, not just for an individual website, server or application. NIS2 looks at the entity and the services that this entity provides.

    Broadly speaking, these are the most important steps:

    • Check your sector: NIS2 applies to sectors including energy, transport, banking, healthcare, drinking water, waste water, digital infrastructure, ICT service management, government, space, postal and courier services, certain manufacturing companies, digital providers and research.
       
    • Check your size: for many sectors, NIS2 mainly applies to medium-sized and large organisations. Size is determined by factors including the number of employees, annual turnover and balance sheet total.
       
    • Check exceptions: some organisations fall under the Cyberbeveiligingswet regardless of their size. This includes DNS service providers, domain name registration service providers, providers of public electronic communications networks and communications services, providers of top-level domain name registries, trust service providers and government organisations.
       
    • Check your role in the chain: if you provide ICT services to an organisation that falls under NIS2, you do not automatically fall under NIS2 yourself. Your customer may, however, impose security requirements on you, for example via contracts, an SLA or a supplier assessment.

     

    What does NIS2 mean for your TransIP services?

     

    NIS2 makes the organisation itself responsible for appropriate and proportionate security measures. A product or supplier therefore does not automatically make your organisation compliant. The services you use are, however, relevant to your measures.

    Therefore treat TransIP services as components of your technical environment. For each service, map out which data, systems and processes depend on it, who has access and what happens if the service is temporarily unavailable.

     

    Web Hosting

    If you use web hosting for a website, webshop or customer portal, include at least the following topics:

    • Keep CMS systems (e.g. WordPress), plugins, themes and your own code up to date.
    • Use secure passwords and restrict access to administrator accounts.
    • Use an SSL certificate for websites where visitors enter data.
    • Agree who may make changes to the website and how you check those changes.
    • Record which personal data or commercially sensitive data is processed via the website.

     

    Domains and DNS

    Domains and DNS are important for the availability of your website, email and applications. NIS2 explicitly mentions DNS services and domain name registration services within digital infrastructure.

    • Restrict access to domain and DNS management (your TransIP account and API access) to the people who need it.
    • Periodically check whether DNS records are still correct and remove records you no longer use.
    • Where appropriate, use security measures such as DNSSEC, SPF, DKIM and DMARC for your domains.
    • Ensure correct contact details and administrative WHOIS details for your domains, so that you receive notifications about abuse or incidents.
    • Include scenarios such as DNS changes by an unauthorised person, domain hijacking or expired domains in your risk analysis.

     

    VPS

    With a VPS, you manage the operating system, software and applications yourself. This gives you a lot of freedom, but also more responsibility.

    In this overview you will find documentation that goes into the points below in more detail.

     
    • Install security updates for the operating system and your applications.
    • Restrict access via SSH, use strong authentication and only grant users the permissions they need.
    • Use firewalls, such as the firewall on your VPS and the VPS firewall in the TransIP control panel.
    • Create backups and regularly test whether you can successfully restore a backup.
    • Use monitoring and logging to detect deviations more quickly.
    • Record who is responsible for management, patching, incident handling and recovery.

     

    OpenStack

    With OpenStack, you build cloud environments yourself. For NIS2, it is especially important to maintain control over projects, instances, networks, object storage and access keys.

    • Use separate OpenStack projects or tenants for environments you want to manage separately.
    • Restrict access to API keys, SSH keys and service accounts.
    • Use security groups and network segmentation to restrict access to instances.
    • Record which images, volumes, snapshots and object storage buckets are part of critical services.
    • Automate configuration wherever possible, so that you can repeat and verify changes.

     

    Kubernetes

    Kubernetes is often used for applications consisting of multiple containers. For NIS2, this mainly touches on configuration management, access control, secrets (passwords and similar), images and monitoring.

    • Restrict access with RBAC and only grant users, service accounts and workloads the permissions they need.
    • Do not store secrets in application code or container images.
    • Use NetworkPolicies or similar measures to restrict traffic between workloads.
    • Update container images regularly and scan images for known vulnerabilities.
    • Back up configuration, persistent volumes and data needed to restore your application.
    • Use logging and monitoring for clusters, nodes, workloads and ingress traffic.

     

    What do you need to do to comply with NIS2?

     

    NIS2 compliance is not a single setting in a product. It is an organisation-wide process in which governance, technology, processes and supplier management come together.

    Use the points below as a starting point for your own preparation.

    1. Create a risk analysis

      Map out which services are essential to your organisation, which systems are needed for them, which risks are involved and which measures have the greatest impact. Also include direct suppliers and service providers in this process.
       
    2. Create an asset and services overview

      Record which domains, DNS zones, websites, servers, cloud projects, clusters, backups and storage locations you use. For each component, note who owns it, who manages it, which data is processed and how you recover in the event of an incident.
       
    3. Set up access management properly

      Use unique accounts, strong passwords, MFA where available and the principle of least privilege. Remove accounts that are no longer needed and periodically check who has access to your TransIP control panel, servers, cloud environments and backup environments.
       
    4. Keep systems up to date through updates

      Make patch management concrete. Determine who performs updates, within what timeframe critical vulnerabilities are fixed and how you check whether updates have been applied.
       
    5. Protect data with encryption

      Use encrypted connections, such as HTTPS and SSH. Encrypt sensitive data where appropriate, for example in applications, databases, object storage or backups.
       
    6. Create and test backups

      A backup is only useful if you know that recovery works. Therefore periodically test whether you can restore files, databases, servers or applications. Document the test and improve the process if recovery takes too long or is incomplete. Tip: with Acronis, you can create backups of files, disks and folders on your laptop, computer, servers and, in many cases, also your website.
       
    7. Prepare incident handling

      Create an incident plan that states who makes decisions, who performs technical investigation, who communicates with customers or suppliers and when you report to the CSIRT or supervisory authority. Also record how you preserve evidence, such as logs and timelines.
       
    8. Record supplier agreements

      If your organisation falls under NIS2, you must also manage risks in your supply chain. Therefore record which services you purchase from suppliers, which security agreements apply, how incidents are reported and who is responsible for what.
       
    9. Register your organisation when this is mandatory

      Organisations that fall under the Cyberbeveiligingswet must register in the entity register. According to the NCSC, voluntary registration is already possible via Mijn.NCSC.nl. The obligation only arises once the Cyberbeveiligingswet enters into force.

     

    Incidents and reporting obligation

     

    If your organisation falls under the Cyberbeveiligingswet, you must report significant incidents as soon as possible. According to the NCSC, a significant incident must in any case be reported to the supervisory authority and the relevant sectoral CSIRT within 24 hours.

    An incident is not automatically significant because a server or website goes down. The main question is whether the incident significantly disrupts, or could disrupt, your organisation’s service delivery. The exact thresholds will be further elaborated in ministerial regulations.

    Therefore include the following in your incident process:

    • who assesses whether an incident is significant;
    • which systems or services have been affected;
    • which logs, notifications and timestamps are recorded;
    • who contacts suppliers, customers, the CSIRT or the supervisory authority;
    • how you recover and how you record improvement measures afterwards.

    If the incident involves a TransIP service, contact our support department via the TransIP control panel. State as specifically as possible which service, what time, which error message and what impact you are seeing.


     

    Supplier or service provider for a NIS2 organisation

     

    Even if you do not fall under NIS2 yourself, you may still have to deal with it. For example, if you provide web development, hosting management, application management, managed services or other ICT services to an organisation that does fall under NIS2, that customer may impose requirements on your security.

    Prepare for this by making clear in advance:

    • which technical and organisational security measures you have taken;
    • how you manage access to customer environments;
    • how you follow up vulnerabilities and updates;
    • how you detect, report and handle incidents;
    • which backup and recovery agreements apply;
    • which subcontractors or hosting providers you use.

    A certificate or standards framework can help in conversations with customers, but is not an automatic guarantee that you meet all requested measures. Appropriate measures depend on the risks in the specific chain.


     

    In this guide, you have read what NIS2 and the Cyberbeveiligingswet mean for organisations using TransIP services. First check whether your organisation falls under the Cyberbeveiligingswet, and then include your hosting, domains, servers, cloud environments, storage and backups in your risk analysis and security measures.

    Are you looking for more information about NIS2? Consult the following sources:

    Need help?

    Receive personal support from our supporters

    Contact us