NIS2 and email security.pdf
NIS2 and Email Security
Your Checklist for NIS2 Compliance
NIS2 and Email Security
Introduction
NIS2 sets out stringent practices for protecting data, particularly in the realm of digital communications. Evaluating your existing communications tools to ensure they meet the requirements of NIS2 is a key step to meeting compliance.
This guide will outline everything you need to know to understand your organization’s responsibilities around email security under NIS2, including a checklist to help guide you on your way toward NIS2 compliance.
NIS2 and Email Security
Email and NIS2
Sending Sensitive Data Information via Email Has Become Common Practice.
However, evolving legislation means that ‘regular’ email no longer provides the required security functionality to protect sensitive data.
Indeed, when it comes to transmitting sensitive information, there are a number of factors that data governance and IT leaders must now take into consideration to ensure the proper handling of sensitive data. The NIS2 Directive sets stringent standards for cybersecurity, particularly concerning email communications.
Let’s Start with the Basics.
NIS2 and Email Security
What is NIS2?
NIS2 stands for Network and Information Security Directive. Introduced in 2020, NIS2 is a continuation and expansion of NIS, the previous EU cybersecurity directive.
NIS2 intends to expand on the original NIS directive. It enhances the security of network and information systems within the EU by requiring operators of critical infrastructure and essential services to implement appropriate security measures and report any incidents to the relevant authorities.
NIS2 enforces more stringent measures across Europe, expanding its EU-wide security requirements and the scope of covered organizations and sectors. In this way, NIS2 seeks to improve the security of supply chains and simplify reporting obligations.
NIS2 and Email Security
Who Does NIS2 Apply To?
NIS2 affects all entities that provide essential or important services to the European economy and society, including companies and suppliers.
If your organization falls under any of the categories below, NIS2 is applicable to you.
Essential Entities (EE)
Important Entities (IE)
Size threshold: varies by sector, but generally:
- EE: 250 employees, balance sheet of €43 million
- IE: 50 employees, balance sheet of €10 million
Essential Entities (EE)
Important Entities (IE)
- Public Administration
- Postal Services
- Space
- Energy
- Chemicals
- Health
- Research
- Finance
- Foods
- Water Supply (Drinking & Wastewater)
- Waste Management
An entity may still be considered “essential” or “important” even if it does not meet the size criteria, in specific cases such as when it is the sole provider of a critical service for societal or economic activity in a Member State.
Digital Providers
- E.g. social networks, search engines, online marketplaces
Manufacturing
- E.g. medical devices and other equipment
Plus all sectors under “essential entities” and within the size threshold for “important entities.”
NIS2 requires medium to large-sized entities within the relevant sectors to take appropriate technical and organizational measures to manage risks posed to their network security and information systems.
Why Compliance is Vital for Your Organization
The importance of compliance with NIS2 cannot be overstated. Organizations that fail to take adequate measures to protect their networks and information systems risk not only financial losses but huge reputational damage and legal liabilities. Fines for non-compliance can reach up to 2% of an organization’s total annual turnover or €10 million - whichever is greater.
Executives and directors face severe consequences for non-compliance. Under the new regulations, Member States are required to establish legal penalties, which can include substantial fines and even criminal charges in some cases. Additionally, executives and directors also face personal liability for any breaches that occur as a result of their failure to implement adequate cybersecurity measures.
In short, the stakes are high. Steps must be taken to comply with the NIS2 directives to protect not only their operations and organizational reputation but also the personal liability of leadership teams.
One of the Main Requirements of the NIS2 Guidelines
Set out in Article 21, is to have policies and procedures in place regarding the use of encryption and secure communication platforms.
How Secure is Email?
It may surprise you to learn that email is inherently insecure. According to research, 88% of employees say they rely on email to get their job done and 81% see email as the most secure way to send sensitive information.
However, standard email traffic is not encrypted, meaning that the content of emails can be intercepted and read by third parties. So, for sharing sensitive data, such as medical information, personally identifiable information (PII), or financial data, email requires additional security measures to prevent security incidents.
Limitations of Transport Layer Security (TLS) Email Security
TLS is a protocol used to encrypt email traffic and improve its security. Unfortunately, TLS is optional and opportunistic, meaning it depends on the settings of sending and receiving email servers. If either server does not support TLS, or if the settings are not configured correctly, the email will be sent unencrypted, putting the privacy and confidentiality of the information at risk.
DANE for Proper Server Control
TLS presents an additional often overlooked problem. While TLS does provide encryption, it does not guarantee that the email will be sent to the correct server. TLS is susceptible to so-called Man-in-the-Middle (MitM) attacks, in which third parties are able to route encrypted emails to another server, instead of the recipient's, without anyone noticing.
Domain Name System-based Authentication of Named Entities (DANE) improves the security of email traffic through proper server control, using DNSSEC (Domain Name System Security Extensions) to verify the authenticity of the email server, and ensure emails are delivered to authorized servers only.
How Multi-Factor Authentication (MFA) Improves Email Security
While DANE ensures that emails are delivered securely from the sending to the receiving server, it does not protect the email once at rest in the recipient’s inbox. Anyone with access to a user's mailbox can read the email, including administrators of the email service, the organization, a colleague (if a device is left unattended), or any unauthorized person who has obtained the user's password.
MFA is a familiar protocol for most of us today, used frequently to protect sensitive data in banking applications, healthcare or government portals, or work platforms. MFA provides an extra layer of security that requires users to provide a second form of authentication, such as a unique code sent to their mobile device, in addition to their password.
While MFA is considered best practice for securing accounts, it is lacking in ‘regular’ email. NIS2 refers to the application of MFA to ensure only authorized individuals can access sensitive data.
From Secure Email Gateway (SEG) to Email Data Protection (EDP)
Regulations such as NIS2 are prompting IT leaders to evaluate their tools and solutions, presenting an opportunity to identify vulnerabilities and enhance existing tools to combat risk vectors in the organization’s digital infrastructure.
As we have made clear, standard email clients, such as Microsoft 365, fall short on a number of security fronts required to meet compliance with NIS2. For this reason, email must be enhanced with DLP tools and advanced encryption protocols, often in addition to secure email gateways.
Traditional SEGs fail to detect and prevent common human errors, such as sending emails to incorrect recipients - some of the leading causes of data incidents. This is often because SEGs rely on basic filters and rules that do not adequately address simple mistakes.
How to Email Securely and Compliantly
Email data protection solutions proffer a number of tools to support compliance, including:
- Data loss prevention tools
- EDPs empower users to utilize the right security levels at the right time through the application of strong encryption and 2FA, ensuring the confidentiality and integrity of data.
- Large file transfer capabilities
- Advanced encryption
- 2FA controls
Seven Steps to NIS2 Compliance
To guide you along the path to NIS2 compliance, we have provided a checklist to support you in taking the necessary steps to enhance your email security. From advanced encryption to data loss prevention, we’re ready to support your organization in meeting the requirements of NIS2.
Implement Robust Encryption Protocols
Encryption is a cornerstone of NIS2 compliance. According to Article 21 of the NIS2 Directive, policies and procedures regarding the use of cryptography including, where appropriate, encryption, are required. While Microsoft 365 (M365) supports transport encryption through TLS, integrating DNS-based Authentication of Named Entities (DANE) can enhance security.- Actions
- Enable TLS for all email communications
- Use supplementary encryption tools to provide fallback mechanisms
- How Zivver Can Help
Zivver provides advanced encryption protocols for email and file transfers, ensuring that sensitive information remains protected from unauthorized access during transmission and storage.
- Actions
Enforce Multi-Factor Authentication (MFA)
MFA is critical in preventing unauthorized access to data. In addition to encryption, Article 21 of the NIS2 Directive specifies the use of multi-factor authentication.- Actions
- Enable MFA for all users within M365
- Integrate third-party MFA solutions for external recipients
- Regularly review and update MFA policies
- Actions
Automatic Email Classification and Data Loss Prevention (DLP) Effective data classification and data loss prevention protocols are vital to protecting your data. The NIS2 Directive emphasizes the importance of approved data classification and appropriate protection measures. M365’s native tools for email classification and DLP are often inadequate for NIS2 standards, necessitating advanced classification tools.
- Actions
- Set up automatic classification rules in M365
- Conduct regular audits of classification and DLP policies
- How Zivver Can Help
Zivver’s data loss prevention features help organizations avoid the accidental or malicious sharing of sensitive information.
- Actions
Secure Handling of Sensitive Attachments
- Use Purview Message Encryption for attachments up to 25MB
- Implement integrated secure file transfer solutions for larger attachments
- Ensure all attachments are scanned for sensitive information before sending
Prevent Human Error
- Use email verification tools to confirm recipient addresses
- Integrate solutions that prompt users to verify sensitive information before sending
- Train employees regularly on the importance of email security
Revocation and Tracking of Emails
- Enable message revocation within M365 where possible
- Implement tracking systems to monitor the delivery and opening of sensitive emails
Regular Security Audits and Updates
- Schedule regular security audits of your email systems
- Update security protocols and tools in response to new threats and regulations
- Keep documentation of all compliance measures and audits for regulatory review
Conclusion
Traditional email falls short when it comes to securely handling sensitive data. The introduction of NIS2 increases the responsibilities of organizations to take action and enhance tools to ensure they are robust enough to protect sensitive information.
By following our seven steps, organizations can ensure their email communications are secure and compliant, mitigating risks and enhancing their overall cybersecurity posture.