Cybersecurity
NIS2 at BCC25: Navigating Fragmentation, Culture Shifts, and a Path to Cyber Resilience
A closer look at how Europe’s flagship cybersecurity directive is being translated from policy to practice.
At the 2025 Barcelona Cybersecurity Congress, one directive resonated across keynotes, panels, and informal conversations: NIS2. Two standout sessions in particular—one focused on practical implementation experiences, and another offering a data-driven regulatory overview—captured the multi-layered challenges organizations face in adapting to this directive. Though its enforcement deadline has passed, the directive’s implementation remains fragmented, uneven, and fraught with real-world complications. As Europe pushes toward a more secure digital future, the cybersecurity community gathered in Barcelona to take stock of where things stand—and where they need to go.
The NIS2 Directive—short for the Directive on Security of Network and Information Systems—is the EU’s most comprehensive attempt yet to build cyber resilience across critical infrastructure and essential services. It replaces the 2016 NIS Directive, expanding its reach to more sectors, tightening reporting deadlines, and increasing accountability at the executive level. It’s a response to an evolving threat landscape—but also a pressure test for cross-border coordination and organizational culture.
Organizational Perspectives on Implementation
One of the most anticipated sessions at BCC25, titled “NIS2: Challenges, Opportunities, and Experiences in the Implementation of the New Directive,” brought together perspectives from public and private institutions to discuss how organizations are adapting to the evolving demands of the directive.
The panel brought together perspectives from public and private sector leaders, including David Esteban Haro (CISO, Barcelona City Council), Óscar López Santín (Cybersecurity Manager, Agrolimen Group), and Javier Montoya Tomás (Director of Cybersecurity, Continuity and Risk, Aigües de Barcelona), with moderation by Malu Ribalta Ribelles (Director of Public Affairs and Communication, ISMS Forum).
Proportionality, a principle central to the directive, became a recurring theme. It’s supposed to ensure that cybersecurity measures are scaled appropriately to the size and risk profile of each organization. But translating that into action has been elusive. Óscar López from Agrolimen summed up the dilemma: “We have many small suppliers. We’re not just auditing them—we’re helping them, even doing the consultancy work ourselves. It's the only way to guarantee security across the supply chain. But it’s a huge task. We have to prioritize.”
Beyond budgets and compliance plans, there was a call for a broader shift in mindset. David Esteban from the Ajuntament de Barcelona stressed that cybersecurity can no longer live in a technical silo. “The biggest challenge is cultural,” he said. “The CISO must speak the language of the business to gain alignment and trust.”
Javier Montoya of Aigües de Barcelona offered a glimpse into how his team approached this challenge by steadily bringing the board into the conversation, without panic or pressure. “We framed risk in calm, constructive terms—not threats or fear. It's about preparing for what’s coming, not panicking.”
Across sectors, the impact of NIS2 is unfolding differently. For financial institutions already working under frameworks like DORA, the shift has felt like a compliance formality. For healthcare organizations, it’s a storm—too many regulations, too few resources, too much exposure. Manufacturers sit somewhere in the middle, dealing with complex IT/OT integration and a growing reliance on consumer-grade technology in industrial environments.
The European Regulatory Landscape
Separately, a session titled “NIS2 Directive Implementation State of Play: National Transposition, Entities Readiness Level, and Sectoral Applications,” led by Régis Cazenave of ECSO, presented a data-driven overview of the current regulatory landscape. He noted that only eleven EU member states had fully transposed NIS2 into national law. ECSO maintains an up-to-date NIS2 Transposition Tracker, visualizing the state of implementation across the EU. He highlighted the burden of fragmented incident reporting requirements across countries and introduced ECSO’s roadmap to coherence: nine key recommendations ranging from a unified EU reporting mechanism to the formal recognition of existing international standards. “Otherwise,” he noted, “companies are forced to fill out different reports for each country impacted by a single incident.”

The ECSO survey results—based on feedback from 155 organizations across 23 countries—provided an inside look at how stakeholders are experiencing the transition. More than half of the respondents were newly regulated under NIS2, facing steep learning curves and operational stress. Many reported difficulty interpreting the directive, challenges coordinating across internal departments, and a lack of specific national guidance. The survey also revealed that in many organizations, NIS2-related efforts now account for 5% to 10% of the cybersecurity budget—an indicator of both its weight and urgency.
Cazenave also emphasized the need for alignment in incident classification across the EU. Different member states are using varying criteria and timelines for reporting, ranging from six-hour windows in Germany to broader thresholds in others. This creates a patchwork of obligations that’s especially difficult for cross-border companies to manage. Inconsistencies extend to how sectors are classified as well. While some countries have opted for minimal transposition, others have expanded the directive’s scope to include additional sectors and smaller organizations.
ECSO’s roadmap didn’t just critique—it also offered a way forward: encourage harmonized tools, accept compliance via well-known international standards like ISO 27001, and provide extra support for smaller, newly regulated entities. The emphasis was clear: compliance must be achievable and scalable.
Bridging the Divide
While challenges remain, the message from BCC25 was grounded in realism and forward motion. The road to NIS2 compliance is uneven, the directive’s rollout incomplete, and the tools scattered. But the ambition—to strengthen Europe’s digital resilience—is widely shared.
The task now is to close the gap not only between countries, but between intention and implementation. In Barcelona, the conversation began to bridge that divide.

How to resolve AdBlock issue?



