{"id":18876,"date":"2025-04-01T13:05:18","date_gmt":"2025-04-01T11:05:18","guid":{"rendered":"https:\/\/kordon.app\/?p=18876"},"modified":"2025-04-01T13:05:18","modified_gmt":"2025-04-01T11:05:18","slug":"nis-2-just-came-out-but-we-already-know-what-nis-3-will-bring","status":"publish","type":"post","link":"https:\/\/kordon.app\/et\/nis-2-just-came-out-but-we-already-know-what-nis-3-will-bring\/","title":{"rendered":"NIS 2 Just Came Out But We Already Know What NIS 3 Will Bring"},"content":{"rendered":"<p class=\"p1\">In 7-8 years, my dad\u2019s dairy farm and other \u201cnormal\u201d non-techy companies will need to have formal information security programs.<\/p>\n<p class=\"p3\"><b>Here\u2019s why:<\/b><b><\/b><\/p>\n<p class=\"p1\">The <span class=\"s1\"><b>World Economic Forum (WEF)<\/b><\/span> has been publishing their <span class=\"s1\"><b>Cybersecurity Outlook reports<\/b><\/span> since 2022. In the latest <span class=\"s1\"><b>2025 report<\/b><\/span>, two key insights stood out to me:<\/p>\n<p class=\"p5\"><b>1. Regulations are becoming more accepted as an effective way to boost resilience.<\/b><b><\/b><\/p>\n<p class=\"p1\">Back in 2022, only <span class=\"s1\"><b>39%<\/b><\/span> of respondents thought that cyber regulations actually helped reduce risk.<\/p>\n<p class=\"p1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-18877 size-full\" src=\"https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk.png\" alt=\"Chart illustrating how the perception of regulations being effective for raising cyber resillience has grown from 39% in 2022 to 78% in 2025\" width=\"1488\" height=\"884\" srcset=\"https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk.png 1488w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk-600x356.png 600w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk-1024x608.png 1024w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk-768x456.png 768w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk-18x12.png 18w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/1.-regulations-are-effective-in-reducing-my-cyber-risk-570x340.png 570w\" sizes=\"(max-width: 1488px) 100vw, 1488px\" \/><\/p>\n<p class=\"p1\">Fast forward to 2025, and that number has jumped to <span class=\"s1\"><b>78%<\/b><\/span>.<\/p>\n<p class=\"p3\"><b>That\u2019s a massive 2x shift!<\/b><b><\/b><\/p>\n<p class=\"p1\">I think it\u2019s because more organizations have gone through their first rounds of compliance implementations and actually seen the results.<i><\/i><\/p>\n<p class=\"p3\"><b>Placement Suggestion:<\/b><span class=\"s3\"> Insert <\/span><b>Chart 1: Cyber and Privacy Regulations Effectiveness<\/b><span class=\"s3\"> here.<\/span><\/p>\n<p class=\"p5\"><b>2. At the same time, small and medium-sized organizations are falling behind.<\/b><b><\/b><\/p>\n<p class=\"p1\">In 2022, only <span class=\"s1\"><b>5%<\/b><\/span> of smaller companies reported insufficient cyber resilience.<\/p>\n<p class=\"p1\">By 2025, that number has grown to <span class=\"s1\"><b>35%<\/b><\/span>\u2014a whopping <span class=\"s1\"><b>7x increase!<\/b><b><\/b><\/span><\/p>\n<p class=\"p1\">And the gap keeps widening.<\/p>\n<p class=\"p1\"><img decoding=\"async\" class=\"alignnone size-full wp-image-18878\" src=\"https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience.png\" alt=\"Smaller companies struggle more with having cyber resillience\" width=\"1792\" height=\"1176\" srcset=\"https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience.png 1792w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience-600x394.png 600w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience-1024x672.png 1024w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience-768x504.png 768w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience-1536x1008.png 1536w, https:\/\/kordon.app\/wp-content\/uploads\/2025\/04\/2.-organisations-reporting-insufficient-cyber-resillience-18x12.png 18w\" sizes=\"(max-width: 1792px) 100vw, 1792px\" \/><\/p>\n<p class=\"p1\">This poses a risk not just to the small organizations themselves, but also to the entire ecosystem due to interconnected supply chains.<\/p>\n<p class=\"p1\">Larger organizations and regulators have a <span class=\"s1\"><b>strong incentive to support and invest<\/b><\/span> in smaller, less-capable organizations to enhance the resilience of the whole ecosystem.<\/p>\n<p class=\"p5\"><b>The Future of Cyber Regulations<\/b><b><\/b><\/p>\n<p class=\"p1\">That\u2019s why I think we\u2019re heading toward a future where even <span class=\"s1\"><b>smaller organizations (yes, maybe even dairy farms)<\/b><\/span> will be brought under new regulatory frameworks like <span class=\"s1\"><b>NIS 3<\/b><\/span>. This means that even small businesses will need formal <span class=\"s1\"><b>Governance, Risk, and Compliance (GRC) programs<\/b><\/span>.<\/p>\n<p class=\"p1\">Strengthening those weaker links is just <span class=\"s1\"><b>common sense<\/b><\/span> for all of us.<\/p>\n<p class=\"p6\"><b>Reference:<\/b><b><\/b><\/p>\n<p class=\"p3\"><span class=\"s3\">Insights from the <\/span><a href=\"https:\/\/www.weforum.org\/publications\/global-cybersecurity-outlook-2025\/\"><b>World Economic Forum\u2019s Cybersecurity Outlook Report 2025<\/b><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>In 7-8 years, my dad\u2019s dairy farm and other \u201cnormal\u201d non-techy companies will need to have formal information security programs. Here\u2019s why: The World Economic Forum (WEF) has been publishing their Cybersecurity Outlook reports since 2022. In the latest 2025 report, two key insights stood out to me: 1. Regulations are becoming more accepted as&#8230;<\/p>","protected":false},"author":1,"featured_media":18885,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-18876","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/18876","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/comments?post=18876"}],"version-history":[{"count":3,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/18876\/revisions"}],"predecessor-version":[{"id":18882,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/posts\/18876\/revisions\/18882"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/media\/18885"}],"wp:attachment":[{"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/media?parent=18876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/categories?post=18876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kordon.app\/et\/wp-json\/wp\/v2\/tags?post=18876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}