The revised directive on the security of network and information systems (NIS2) will apply to postal service providers, including providers of courier services, that have more than 50 employees and a total annual turnover of €10m or more. This includes all providers that provide at least one of the four steps in the postal delivery chain, excepting transport.
Postal service providers must establish a cybersecurity risk mitigation strategy that:
- assesses the risks associated with their network and information systems;
- implements security policies to address the identified risks;
- establishes access control policies and uses authentication solutions to prevent unauthorised access;
- includes an incident handling procedure in response to cyberattacks; and
- establishes a service continuity strategy, including disaster recovery.
Postal providers must also notify significant security breaches within 24 hours to the national computer security incident response team.
As so-called “important entities” under NIS2, postal providers are subject only to ex post supervision.
For more information and to access our postal NIS2 report, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our Postal intelligence service.
more news
07 August 26
Global trends in data centres and cloud service providers
An updated Global Trends benchmark analyses policies and regulations of relevance for data centre and cloud service providers (CSPs) across 14 jurisdictions. It found there are different approaches worldwide on aspects such as licensing, ownership restrictions, cloud-related competition policies, cybersecurity and use of subsidies in the cloud sector.
04 August 26
Cross-border IoT data transfer rules across seven APAC markets
This new Cullen International benchmark analyses whether global IoT and M2M operating models can centralise data and platform functions outside the country where connected devices operate. It covers Australia, China, India, Japan, New Zealand, Singapore and South Korea, assessing how data protection, telecommunications, cybersecurity and sector-specific regulation affect the feasibility of offshore operating models.
27 July 26
Spectrum policy adapts to support new network models in the Americas
Cullen International's latest Americas Spectrum Benchmarks compare regulatory approaches across the Americas for a range of topics, including 5G deployment, spectrum assignments, spectrum refarming and private networks.