The minimum cybersecurity risk-management measures
Article 21 requires essential and important entities to implement a proportional set of technical, operational, and organizational measures to manage cybersecurity risks. These measures must be commensurate with the entity's risk profile and aim to ensure the resilience of network and information systems.
What it means
The intent is to move away from static checklists toward a dynamic, risk-based approach to security. Organizations are not expected to implement every possible control, but rather those that specifically mitigate the risks identified in their unique operational environment.
In practice, this means cybersecurity cannot be treated as a purely IT issue; it must be integrated into organizational governance. The scope extends beyond internal systems to include the entire lifecycle of assets and the security of the external supply chain.
The directive emphasizes an "all-hazards" approach. This requires balancing preventative measures (like encryption) with detective capabilities (monitoring) and restorative capabilities (disaster recovery), ensuring that if a breach occurs, the entity can maintain essential services.
How to meet it
- Establish a formal risk management framework based on recognized standards (e.g., ISO 27001 or NIST CSF) to identify and prioritize threats.
- Implement an incident handling process that includes clear procedures for detection, containment, eradication, and mandatory reporting of significant incidents.
- Develop and regularly test business continuity plans (BCP) and disaster recovery (DR) protocols to ensure operational resilience during a crisis.
- Conduct supply chain risk assessments by evaluating the security posture of critical vendors and incorporating cybersecurity requirements into service level agreements (SLAs).
- Enforce basic cyber hygiene practices, including mandatory multi-factor authentication (MFA), systematic patch management, and least-privilege access controls.
- Deploy cryptography and encryption for sensitive data both at rest and in transit to protect confidentiality and integrity.
- Implement a recurring training program to ensure all staff members are aware of current threats and follow secure operational procedures.
Evidence an auditor asks for
- A comprehensive Risk Register documenting identified risks, their impact/likelihood, and the chosen mitigation strategies.
- Documented policies and procedures for incident response, business continuity, and information security management.
- Records of "tabletop" exercises or simulation tests proving that recovery plans actually work.
- Vendor risk assessment reports and signed contracts containing specific cybersecurity obligations for third-party providers.
- Training logs and completion certificates demonstrating that employees have undergone cyber hygiene training.
Common pitfalls
- Treating the requirement as a one-time project rather than a continuous cycle of assessment, implementation, and review.
- Overlooking the supply chain by assuming that large vendors are "compliant by default" without verifying their specific controls.
- Implementing technical tools (e.g., an EDR or Firewall) without documenting the underlying policy that governs how those tools are managed and monitored.