Directive 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2) has been transposed into national laws that have entered into force in all three Baltic states. Entities classified as “essential” or “important” must comply with cybersecurity risk management, incident-reporting and governance requirements.

NIS2 has a much broader scope than the original NIS Directive, extending to areas including waste management, manufacturing of critical products, food production and distribution, cloud computing, data centres and social networking platforms. Entities in these sectors generally must also meet certain size thresholds, although Member States may introduce stricter requirements.

When cyber risk becomes financial risk

Companies should have effective risk assessment and management, incident detection and response procedures, business continuity and recovery measures, access controls and other security measures appropriate to the risks they face.

A clear incident-response plan should define responsibilities and escalation procedures for employees and management. For entities subject to NIS2, administrative fines for non
compliance may reach up to EUR 10 million or 2% of worldwide annual turnover. NIS2 also places responsibility on management bodies, which must approve and oversee cybersecurity risk management measures and may be held accountable under applicable national laws for
breaches of those duties.

Cybersecurity failures may also trigger liability under the General Data Protection Regulation
(GDPR), irrespective of whether a company falls within the scope of NIS2. Organisations must
implement appropriate technical and organisational measures to ensure the security of personal
data. Administrative fines for non compliance with data-processing obligations may reach up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.

n certain cases, personal criminal liability and potential coercive measures against the company may also apply, irrespective of whether the company is subject to NIS2.

The whole article is available at Baltic Business Quarterly magazine Autumn/Winter 2026 edition.