As new cybersecurity rules have recently come into force in the European Union, Fitch Ratings stated that, while they are directionally positive, enhancing cybersecurity postures from compliance with regulations is neutral to credit ratings.
These rules include the NIS2 Directive, which replaces its 2016 predecessor NIS; the Resilience of Critical Entities (CER), which replaces the European Critical Infrastructure Directive of 2008; and the Digital Operational Resilience Act (DORA), a regulation that will apply from January 17, 2025.
The rating agency said: “Cyberattacks represent tail risks, or low probability events that can nonetheless have significant impact. Fitch has not taken a rating action on any issuer as a result of cyberattacks, which are hard to predict and quantify, making them difficult to model in our ratings analysis.
“Proper cyber hygiene and strong controls will not by themselves lead to positive ratings movement, although poor controls could result in negative rating actions if proven to be material to an entity’s finances and/or reputation. A cyber event could increase regulatory scrutiny and litigation.”
The NIS2 Directive, expands the sectors covered to fifteen from and bolsters rules on cybersecurity for EU organisations. It does this based on degree of digitization and interconnectedness as well as potential societal and economic effects.
It also includes ten key requirements for all companies, including incident handling, supply chain security, vulnerability handling and disclosure, use of cryptography, and encryption.
The CER is intended to strengthen critical infrastructure and networks against cyberattack threats including natural hazards, terrorist attacks, insider threats or sabotage. Member states have until Oct. 17, 2024, to transpose the two directives into national law.
The DORA sets uniform requirements on digital operational resilience and information security for the financial sector and critical third parties which provide information and communication technology services to it.
The regulation supersedes national laws and targets Europe’s financial sector, including banks, insurance companies, and investment firms, to make it more resilient against cyberattacks.
Fitch Ratings said: “The NIS2 defines and meaningfully expands the scope and number of organisations that are subject to the NIS2 requirements. Member states no longer have discretion to designate ‘essential’ entities that are subject to the obligations of the directive.”
It added: “Compliance may be more difficult for small-to-medium companies in unregulated industries that lack robust cybersecurity infrastructure, putting them more at risk than critical infrastructure and large companies in regulated industries.
“Cybersecurity budgets are increasingly under pressure amid reduced revenue outlooks, growing recessionary risks and economic uncertainty, which could increase the risk of attacks.”




