While GDPR focused on data protection, the NIS Directive focuses strictly on cybersecurity. It is the first piece of EU-wide legislation on cybersecurity and provides legal measures to boost the overall level of cybersecurity in the EU. As a security expert you are directly impacted if your company is in an industry defined as a Critical National Infrastructure. Depending on the country this can be financial services; energy; water; food; transport; health; government; and emergency services. What is the impact impact in terms of security requirements? What are the implications if you are a supplier to a CNI company? What measures are required to manage risks? What are the penalties if an incident happens?Learning Outcomes:Understand the NIS DirectiveUnderstand the impacts on the customers organisationHave a list of technical and organisational measures required to manage riskUnderstand the differences amongst EU countries implementationUnderstand how different this NIS is from GDPR