Connect with us

Business

NIS2: how best should businesses prepare?

Steve Bradford, Senior Vice President EMEA, SailPoint

In January 2023, the European Union’s updated Network and Information Security Directive, more commonly known as NIS2, came into force. This means that EU Member States will have until 17 October 2024 to put this new law into their national legislation.  

The original NIS Regulations were introduced into national law in 2018. These currently apply to organisations that provide ‘essential services’ (think: healthcare, energy, and transportation) as well as digital service providers (for example, online marketplaces and search engines). The regulations place requirements on those organisations to ensure appropriate security measures to help manage cybersecurity risks, and they impose certain reporting obligations in the case of security incidents. 

Yet it is incontrovertible that there is an increased reliance of the economy and wider society on digital services, and this is driving ransomware attacks globally. We also live in a more connected world – ever more linked and complicated supply chains are leading to higher levels of cyber risk. In fact, 90% of companies polled in the latest IDSA survey reported at least one identity-related breach in the last 12 months, a 6% increase from last year’s report.

So, how does NIS2 fit into this evolving cyber landscape, and what does it mean for businesses?  

Comprehensive cybersecurity 

Organisations and businesses need to integrate cyber resilience into their business models and risk management strategies – and this is where the updated NIS2 directive comes in.  

NIS2 targets all public and private entities operating in the EU that are critical to the economy and society – this also includes UK companies with operations in the EU. Sectors such as healthcare, energy, transport, digital infrastructure, financial market infrastructures, the food sector, social networking services platforms, cloud computing services, data centres, and more will fall under the NIS2 directive.  

The NIS2 directive strives to deliver a broad, comprehensive, and holistic improvement of cybersecurity across the EU. Whilst much of the onus lies on governments (for example, Computer Security Incident Response Teams will be needed in each country and cross-border cooperation between those bodies for information sharing and where incidents require it), there is still a great deal for businesses to be aware of and prepare for.  

All organisations in EU member states should familiarise themselves with the requirements of the directive and begin shaping their cybersecurity strategy over the next 18 months to ensure they are both compliant and secure when the updated directive comes into force.  

Organisations will need to put policies and procedures in place for risk analysis, information system security, assessing the effectiveness of cybersecurity risk management measures, and more. Some examples of this include: companies need to ensure access is disabled when employees or contractors stop working for it, and they should also refrain from using ‘generic’ accounts (for example, accounts that are not tied to a named individual). Moreover, granting access to sensitive applications and/or data should be subject to approval and risk analysis to prevent toxic situations that could lead to fraud or data leakage.  

Coordinated risk management

NIS2 will require senior management to approve the cybersecurity risk-management measures taken and oversee their implementation. And take heed! Under NIS2, senior management can be held liable for any infringements. 

The new legislation will be far-reaching according to a new IDC report, “Identity governance will be a key to NIS2 compliance.” It will impact training, with the NIS2 directive stipulating the need for cybersecurity training and awareness for all employees, as well as for the broader ecosystem. Supply chain security will also be impacted. Recent cyber-attacks on payroll services provider Zellis and outsourcing group Capita – which have both affected multiple organisations – highlight the importance of protecting third parties. The NIS2 directive will mandate coordinated risk assessments of critical supply chains that cover critical ICT services, CIT systems, or ICT products. 

Addressing risks through identity security

Organisations often struggle to assess the efficacy of their cybersecurity measures or identify vulnerabilities that remain despite those measures. Many organisations struggle to ensure access is promptly rescinded for employees that change roles or leave the company.

Managing all these risks must be addressed through a proactive and policy-driven approach. The European Commission recommends that essential and important entities adopt zero-trust principles and identity and access management. Least-privilege access that is implicit through zero trust approaches can be fundamental to managing that access for partners and contractors.  

European organisations have until October 2024 to conduct NIS2 gap assessments and implement strategies to address the outcomes of those assessments. 

Let the implementation of the EU’s General Data Protection Regulation (GDPR) serve as a warning that European regulators are more than ready to penalise businesses that have been dragging their heels when to comes to managing data security, privacy, and cyber risk. The punishments may come in the form of regulatory penalties. Add this to the costs of operational downtime, reputational damage, customer loss, and system restoration that follow any breach, and it becomes quite clear all that is at stake for businesses.  

European organisations face an ever-growing burden of management for identities and access, for human and non-human accounts and identities, and for employees, partners, contractors, and customers. The capabilities of legacy identity security solutions are inadequate to address the volume and velocity of identity-related tasks that most organisations must now address. However, modern identity security solutions, driven by AI and machine learning, are changing the game. These enable organisations to automate identity processes and build contextual insights to improve the detection of suspicious behaviour and trigger quicker and more impactful responses.  

These benefits will be crucial as devices, bots, and all manner of other non-human identities proliferate at a much faster rate than manual capabilities can handle. Proactive and automated identity and access management should be a pillar of every organisation’s cybersecurity risk management strategy, and preparation should start today.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business

How can a payments strategy support business growth?

Source: Finance Derivative

Following the global economic upheaval brought on by the pandemic, businesses are once again prioritising growth on a global scale. While every business recognises the importance of expansion, their methods, obstacles, and risks differ greatly.

In the following article, Sonya Geelon, Chief Commercial Officer at Conferma, explores some of the most common challenges holding businesses back, and how by including innovative payments solutions in your payment strategy, you can successfully position your business to expand into global markets.

Barriers to global expansion

At Conferma, we wanted to know what businesses felt stood between them and their growth ambitions, so we spoke to 400 financial decision makers to find out.

The research, shared in our new Growth Ignition Index report, identified global expansion as a key priority for businesses looking to grow across all regions. Significant drivers included increasing customer demand (46 per cent), maintaining a consistent cashflow (36 per cent) and undertaking digital transformation (34 per cent.) Businesses also highlighted a number of barriers, such as identifying valuable markets to expand into (27 per cent) and navigating complex cross-border payment systems (13 per cent.) The following sheds light on some of the factors that businesses perceive to be hindering their growth.

Operational inefficiencies

It’s a well-known fact that operational efficiency is crucial for giving businesses the competitive edge. If your processes run smoothly and effectively, you’re likely in a good position to grow. However, a third (33 per cent) of businesses identified operational inefficiencies as a significant sticking point, particularly among small-and-medium sized organisations. This perhaps indicates that larger companies have already invested in boosting efficiency to a degree, however, the issue was noted across businesses of all sizes.

Complex cross-border payments

Successful growth relies heavily on being able to make fast, seamless transactions, however, recent research from Rapyd found that 38 per cent of businesses experience delays of five days or more when sending or receiving international payments.[1] Costs and delays in cross-border transactions can have a significant impact on growth, cutting into revenues, restricting cash flow and complicating financial planning. Our own research highlighted this, with 14 per cent of businesses reporting slow and/or complex cross-border payments as a significant barrier to expansion.

So how can businesses overcome these challenges and unlock global growth?

Taking your payments strategy virtual

Amid the array of payment options available in the market, virtual cards have emerged as a versatile solution, valued by users globally. According to Juniper Research, the global value of virtual cards will increase over threefold in just 5 years, climbing from $1.9 trillion in 2021 to a staggering $6.8 trillion by 2026.[2]

So how do they work?

Virtual cards are essentially digital versions of traditional credit cards. The technology generates a 16-digit card  number, allowing an employee to make payments without having to physically hand over a card. Instead, they provide the virtual card number, expiration date, and security code, just like they would with a regular credit or debit card.

Virtual cards come with built-in fraud and security features, enabling restrictions on usage. For instance, users can set a specific date range or limit usage to certain merchants. This ensures that any attempts to exceed the set amount, use the card at unauthorised merchants, or spend beyond the specified date range will result in a declined transaction.

Using a virtual card provider allows access to extensive, pre-existing payments ecosystems. For example, Conferma connects 75+ card issuers and banks across the world. This enables businesses to use virtual cards in 62 different currencies, making international payments frictionless while mitigating costly cross-border fees. Virtual cards can also help boost cashflow and improve operational efficiency, automating reconciliation and cutting lengthy processing times. By removing convoluted payment processes, virtual cards give businesses the freedom to grow in the markets they deem most valuable, not just most accessible.

Of those surveyed, four out of five  respondents (82 per cent) plan on expanding their virtual card usage in the next twelve months, with 64 per cent extending usage to additional payment needs. Businesses already using virtual cards also anticipate a substantial increase in the volume of payments they make virtually, with our data projecting a rise from 45 to 57 per cent of all payments being made using virtual cards in the next 12 months.

Virtual cards offer a compelling solution to the challenges limiting international growth by offering enhanced security, streamlined operational processes, and seamless cross-border transactions. By embracing virtual cards as a strategic tool, organisations can unlock opportunities for growth and innovation, empowering them to navigate the complexities of international commerce with ease.


[1] The 2023 State of Cross-Border Payments, Rapyd, 2023.

[2] Virtual Cards: B2B and B2C Applications, Competitive Analysis & Market Forecasts 2021-2026, Juniper Research

Continue Reading

Business

How can businesses make the cloud optional in their operations?

Max Alexander, Co-founder at Ditto

Modern business apps are built to be cloud-dependent. This is great for accessing limitless compute and data storage capabilities but when connection to the cloud is poor or shuts down, business apps stop working, impacting revenue and service. If real-time data is needed for quick decision-making in fields like healthcare, a stalled app can potentially put people in life-threatening situations.

Organisations in sectors as diverse as airlines, fast food retail, and ecommerce that have deskless staff who need digital tools accessible on smartphones, tablets and other devices to do their jobs. But because of widespread connectivity issues and outages, these organisations are beginning to consider how to ensure these tools can operate reliably when the cloud is not accessible. 

The short answer is that building applications with a local-first architecture can help to ensure that they remain functional when disconnected from the internet. But then, why are not all apps built this way? The simple answer is that building and deploying cloud-only applications is much easier as ready-made tools for developers help expedite a lot of the backend building process. The more complex answer is that a local-first architecture solves the issue of offline data accessibility but does not solve the critical issue of offline data synchronisation. Apps disconnected from the internet still have no way to share data across devices. That is where peer-to-peer data sync and mesh networking come into play.

Combining offline-first architecture with peer-to-peer data sync

In the real world, what does an application like this look like?

  • Apps must prioritise local data sync. Rather than sending data to a remote server, applications must be able to write data using its local database in the first instance, and then listen for changes from other devices, and recombine them as needed. Apps should utilise local transports such as Bluetooth Low Energy (BLE) and Peer-to-Peer WiFi (P2P Wi-Fi) to communicate data changes in the event that the internet, local server, or the cloud is not available.
  • Devices are capable of creating real-time mesh networks. Nearby devices should be able to discover, communicate, and maintain constant connections with devices in areas of limited or no connectivity.
  • Seamlessly transition from online to offline (and vice versa). Combining local sync with mesh networking means that devices in the same mesh are constantly updating a local version of the database and opportunistically syncing those changes with the cloud when it is available.
  • Partitioned between large peer and small peer mesh networks to not overwhelm smaller networks if they try to sync every piece of data. In order to do this, smaller networks will only sync the data that it requests, so developers have complete control over bandwidth usage and storage. This is vital when connectivity is erratic or critical data needs prioritising. Whereas, the larger networks sync as much data as they can, which is when there is full access to cloud-based systems.
  • Ad-hoc to enable devices to join and leave the mesh when they need to. This also means that there can be no central server other devices are relying on.
  • Compatible with all data at any time. All devices should account for incoming data with different schemas. In this way, if a device is offline and running an outdated app version, for example, it still must be able to read new data and sync.

Peer-to-peer sync and mesh networking in practice

Let us take a look at a point-of-sale application in the fast-paced environment of a quick-service restaurant. When an order is taken at a kiosk or counter, that data must travel hundreds of miles to a data centre to arrive at a device four metres away in the kitchen. This is an inefficient process and can slow down or even halt operations, especially if there is an internet outage or any issues with the cloud.

A major fast-food restaurant in the US has already modernised its point of sale system using this new architecture and created one that can move order data between store devices independently of an internet connection. As such, this system is much more resilient in the face of outages, ensuring employees can always deliver best-in-class service, regardless of internet connectivity.

The vast power of cloud-optional computing is showcased in healthcare situations in rural areas in developing countries. By using both peer-to-peer data sync and mesh networking, essential healthcare applications can share critical health information without the Internet or a connection to the cloud. This means that healthcare workers in disconnected environments can now quickly process information and share it with relevant colleagues, empowering faster reaction times that can save lives.

Although the shift from cloud-only to cloud-optional is subtle and will not be obvious to end users, it really is a fundamental paradigm shift. This move provides a number of business opportunities for increasing revenue and efficiencies and helps ensure sustained service for customers.

Continue Reading

Business

When something personal fills an important gap in the market 

by Cécile Mazuet-Eller, founder of NameSwitch

There aren’t many business ideas that go from a personal experience to filling an important gap in the market. However, this is certainly the case for NameSwitch, the UK’s pioneering and only name changing support service launched in 2018. But what inspired its inception and what challenges did it face? Here, Cécile Mazuet-Eller, the founder of the company, in its seventh year, explains.

My entrepreneurial journey is a bit unusual in that it started from my own experience of going through a divorce, which became a pivotal turning point for me not only emotionally, but practically too. I wanted to remove my married name, and I had a visceral reason to do so as I really didn’t want to keep it. Feeling extremely frustrated at still receiving letters and official documents featuring my previous name, I was desperate to change it but like for so many people it became a stop-start, arduous task.

Once I started the process, I realised it was taking up far too much time I didn’t have; being a single mum to two young children and working full-time is no mean feat, so when I embarked on the name changing process I realised it wasn’t going to be easy.  Searching for a solution to help, all I came up with was a service covering the US and Canada, but nothing that worked for the UK, so in the end, I spent a whole year to get everything changed that had to be, which proved long and stressful to say the least.

Nurturing the idea

In the early days I was fortunate enough to be surrounded by positive people who had good contacts, and who saw the viability of my idea. Living in a small community filled with intelligent and well-rounded people, I wasn’t short of encouragement from them and friends, who recognised as well as I did there was a definite gap in the market. Working with a web development team in Serbia which was also recommended, I enlisted additional help from a university student on some research.

I always wanted to run my own business, and there were several reasons why I needed to embark on something new. As the only breadwinner in the house, there were mounting bills while balancing the demands of motherhood and other financial responsibilities. Cash was limited but what little I had was used carefully which I put into the business.

In the early stages, which included the development of the unique technology that underpins the service, I carved pockets of time at night and on weekends to create a strong foundation for the business. Creating something completely from scratch was like a form of healing, which is why it was and remains such a personal project.

Mulling over the idea for at least two years following the original lightbulb moment, the business was registered in 2015, with time needed for building the robust platform in order to  create a viable product. Drawing on my previous experience, I investigated overseas equivalents, financials and marketing intelligence ensuring there was a genuine need for the service in the UK. Fortunately enough I was able to share my plans with my employer at the time, who turned out to be my biggest supporters, becoming my first paying customer who purchased a NameSwitch for his ex-wife, who was getting married to someone else!

With a career in telecommunications and a degree in marketing, I was already used to hard work and having the support and encouragement from my telecoms team was extremely helpful.   

Support and coaching

Coaching was an important element of the start-up process, obtained through a wider network and some financial support from family,  with no other funding or investment being available.

The challenges

Presented with certain obstacles like all businesses are, there was a lot to juggle and at times it felt like too much but I managed to navigate the complexities involved. When Covid hit that was a huge set-back, given that our biggest target market was and still is, newly-weds. With all weddings being banned, it hit NameSwitch hard, but our saving grace were the people who used the time to change their name’s in lockdown, by doing something they previously didn’t have time for. Being 100% employed by the business by this stage, it turned into a year of survival and another big challenge.  

In 2022-2023 we concentrated on growth for NameSwitch, when me and my dedicated team were satisfied with the service, it was time to consider investment into PR, advertising and partnerships to increase brand awareness to reach the revenues that were needed.

In 2022-2024, it was forecast that 285,000 – 415,000 weddings will take place resulting from the pandemic, which has reflected well on the business in recent years. And amidst the trials and tribulations it’s proved to be both exhilarating and exhausting in equal measure.

With hindsight, there are certain things I’d have done differently, such as bringing in a partner early on to put us in a stronger position sooner, and adding more resource  to improve growth, but I know that’s all part of the steep learning curve and something to take with me to projects in the future.

Advice for aspiring entrepreneurs

For anyone contemplating their own entrepreneurial endeavours, I’d recommend to ‘one hundred percent go for it’ – but do not bet the house on it and whatever happens, embrace the journey.

Continue Reading

Copyright © 2021 Futures Parity.