The European Union’s NIS2 Directive represents a fundamental shift in how organisations must approach digital security. Driven by an increasingly complex, interconnected and aggressive cyber threat landscape, NIS2 moves beyond traditional, checklist-based compliance to mandate true operational cyber resilience.
For organisations operating within the EU, NIS2 fundamentally elevates cybersecurity from an IT concern to a boardroom imperative. It mandates an "all-hazards" approach to risk management — the ability to respond to any threat while building overall operational resilience — expands its reach across critical supply chains while demanding a proactive, unified strategy to protect network and information systems. The goal is no longer just preventing attacks, but ensuring the continuous, secure delivery of essential services to the European economy and society, even when disruptions occur.
To enforce this culture of resilience, NIS2 is highly prescriptive. It introduces specific legislative mandates that make the deployment of advanced cybersecurity solutions a legal requirement, not just an operational best practice.
The primary objective of the NIS2 Directive is to establish a harmonised, elevated baseline of cybersecurity across European critical infrastructure, moving beyond traditional IT to encompass the operational technology (OT) that keeps our societies functioning.
The most significant shift NIS2 brings is its sheer scope and its strict demand for board-level accountability. It explicitly recognises that systems like Land Mobile Radio (LMR) networks are no longer isolated islands; they are converged ecosystems where a breach in an enterprise IT environment can swiftly compromise public safety communications.
Ultimately, NIS2 aims to force organisations to transition from reactive scrambling to proactive, intelligence-driven defence, ensuring that the critical communications we rely on remain resilient under attack.
The NIS2 Directive casts a significantly wider net than its predecessor, moving beyond traditional utilities to encompass a vast array of industries. In practical terms, NIS2 applies to all medium and large enterprises, specifically those with 50 or more employees or an annual turnover exceeding €10 million — operating within 18 designated sectors across the European Union.
These are divided into “Essential” entities, such as energy, transport, healthcare and digital infrastructure, and 'Important' entities, which include manufacturing and waste management. For those of us managing mission-critical Land Mobile Radio (LMR) networks, the implications are direct. If your organisation relies on LMR for public safety, transportation logistics or utility operations, your converged IT and OT communications infrastructure falls squarely into the highly critical Essential category. This means your entire ecosystem, from the dispatch consoles to the broadband gateways, is bound by NIS2 compliance and its stringent reporting mandates.
By mandating "appropriate and proportionate technical, operational and organisational measures" (Article 21), the directive explicitly requires organisations to invest in active, continuous security capabilities. Specifically, the law demands technical solutions that deliver:
Critically, Article 20 places the liability directly on the management body — holding leadership personally accountable for approving and overseeing the implementation of these measures.
While the main Directive establishes the legal and financial framework, the Commission Implementing Regulation dictates the exact technical and methodological standards that entities within the Digital Infrastructure, ICT Service Management and Digital Provider sectors must adopt to prove compliance. It translates broad risk-management goals into concrete, auditable IT requirements:
Complying with NIS2 is rarely a journey an organisation should undertake alone. It requires more than just updating internal policies; it demands a shift to active and continuous operational security. The regulations dictate that we must move beyond passive defences and implement systems capable of detecting and responding to threats in real time.
To truly align with the Implementing Regulations, security leaders must operationalise their strategy across several critical areas:
Securing converged Land Mobile Radio (LMR) and IT networks requires an ecosystem approach. Much like building watertight bulkheads on a ship to prevent a single breach from sinking the vessel, separating and securing your IT and OT environments requires deep technical expertise and round-the-clock vigilance. This is where partnering with a mature security provider becomes a strategic advantage.
At Motorola Solutions, we view this transition not just as a compliance tick-box but as a fundamental upgrade to your operational resilience. We help organisations move from reactive recovery to proactive resilience through a combination of expert human intelligence and purpose-built technology. A robust defensive posture requires a suite of managed capabilities:
Ultimately, NIS2 is an opportunity to fortify the critical communications our societies rely upon. By treating compliance as an operational baseline rather than an endpoint, we can ensure our networks remain secure, available and resilient under pressure.