ZerumOne
ProjectsAbout UsClientsBlog
Back to blog
News and regulation

NIS2 and Cybersecurity in Slovakia: Does It Apply to Your Company?

Cybersecurity used to be a topic for banks, energy companies and government institutions. That is changing. The European NIS2 directive widened the circle of companies that must keep their security in order, and Slovakia has built it into its law. Many mid sized companies therefore don't even know it may apply to them.

What is NIS2 and how it appears in Slovakia

NIS2 is an EU directive that raises the level of cybersecurity across the Union. In Slovakia it was implemented through an amendment to Act No. 69/2018 Coll. on cybersecurity, effective from 1 January 2025. Supervision is carried out by the National Security Authority (NBÚ), and the national centre SK-CERT handles incident reporting.

Who is affected

Originally the law mainly covered operators of essential services. The new rules are broader. They apply to many sectors, for example energy, transport, healthcare, digital infrastructure, manufacturing, IT service providers and public administration. By estimates, the number of affected organizations has grown many times over.

It depends on the sector, size and type of service the company provides. The best approach is to check directly against the law and its annexes, or with the help of an expert. And note that even if it doesn't apply to you directly, it may apply indirectly. If you supply IT services to a regulated company, your client may ask for proof that you are a secure partner.

Main requirements

  • Risk management. A company must know what threats it faces and have measures ready for them.
  • Security measures. Technical and organizational, for example access management, encryption, backups and updates.
  • Incident reporting. Serious cyber incidents must be reported to the competent authorities within set deadlines.
  • Supply chain security. Responsibility for suppliers who have access to your systems.
  • Management responsibility. Management is accountable for the state of cybersecurity too, not only the IT department.

Failing to comply can lead to fines, so it doesn't pay to put the topic off.

First practical steps

  1. Find out whether the law applies to you. Check your sector and type of activity.
  2. Make an asset inventory. What servers, computers, applications and data do you have, and who has access to them?
  3. Introduce access control. Strong passwords, two factor authentication, removing rights from people who left.
  4. Back up and test recovery. A backup nobody has tried often doesn't work.
  5. Train your employees. Most incidents start with one careless click.
  6. Prepare an incident plan. Who does what when something happens.

How we can help

We help companies with network and server management, security setup, backups and protection against threats. We will gladly go through your current state and propose practical measures. For legal and formal questions we recommend working with a lawyer or auditor.

Conclusion

Cybersecurity is not only about meeting an obligation. It is about protecting your business. If you want to know where you stand, contact us. You can find more on the pages Network and server administration and IT security and anonymity.

Related services

Want to discuss this topic?

Contact us and we will help you choose the right next step.

Contact us