Higher Demands on Management
– Obligation to participate in the responsibility for safety
– The organization must be familiar with the requirements of the directive and the risk management efforts.
– Direct responsibility for identifying cyber risks, mitigating them, and ensuring compliance with requirements.
– Requirements for risk management and robustness.
– Implementation of preventive measures to reduce risks and consequences.
– Initiatives such as risk assessments, contingency plans, awareness training for employees, access control, and management.
Reporting Obligations
A specific reporting obligation is introduced, requiring companies to notify the relevant authority of significant incidents.
Within 24 hours:
Within 72 hours:
Within 1 month:
Who is Affected?
Digital infrastructure:
DNS, data centers, cloud providers, MSPs, communication platforms, top-domain administrators, trust services.
Energy:
Producers, operators, suppliers, distributors, transmission and sale of electricity, oil, gas, district heating/cooling, hydrogen, operators, and producers of EV charging stations.
Transport:
Air, rail, road, and sea transport as well as freight and port companies.
Public administration:
Central administration, regions, and municipalities.
Banking and financial market infrastructures:
Banks, credit, trading, and stock exchange companies, as well as their infrastructure.
Health:
Healthcare providers, research laboratories in health promotion, pharmaceutical companies, and manufacturers of medical equipment and raw materials.
Drinking and wastewater:
Suppliers, distributors, collection, and disposal.
Space:
Space infrastructure, software, and services.
Chemicals:
Manufacturing, production, and distribution.
Waste management:
Collection, transport, recovery, and disposal.
Postal and courier services:
Preparation, sorting, transport, and delivery of mail and packages.
Food companies:
Manufacturing, distribution, and production.
Digital service providers:
Providers of online marketplaces, search engines, and social platforms.
Research:
Research organizations.
Manufacturing of particularly critical equipment:
Manufacturing and production of pharmaceuticals, electronic and optical equipment, machinery, vehicles, and spare parts considered critical to society.
Is Your Company Affected?
If you fall under the above categories, you should be aware of the following: Your company must demonstrate how your IT & OT security is structured, how you handle IT & OT security, how your IT & OT systems recover, and how strong your IT security is. The directive outlines a series of mandatory measures, including:
Want to know more? Contact us – we can help with both the technical and legal aspects. Learn more at https://nto.dk/ot-cyber-security.
Click the link below to return to our main page on OT Cyber Security:

NTO has for many years worked on the development of logistics and storage automation for a number of industries.
Data management is the control of information that needs to flow from the ERP to the production floor and back again. NTO’s systems for data management handle logging of…
NTO has through the years delivered many complex internal transport and production solutions. In line with the increased IT threat level, NTO has become specialists in Cyber security.

Automation at the Dolle A/S production – one of the world’s biggest producers of stairs and European marked leader – has increased production capacity by 50 %.
NTO contributes to the ‘green switch’ by a close collaboration with NewRetex and Ferrum Robotics.
NTO has a close collaboration with the resource company Nomi4S regarding the separation of plastic from collected household waste.
NTO has programmed a new and unique waste management plant at the inter-municipal waste sorting company Nomi4S in Holstebro.

Intelligent management of buildings is an important part of NTO’s expertise. Within Building Management Systems (BMS), we work on intelligent…

NTO has worked on the ICONICS SCADA platform for a number of years and became an official ICONICS partner and system integrator in 2019.

The implementation of new options for passengers in Billund Airport is mainly based on NTO’s analysis of the existing luggage handling system.

Since 2003, NTO has delivered complete machine controls for industrial special machines. Among others, we have helped Pressalit A/S with the controls to more than 40 presses.
NTOlink is a Cloud based solution for logging production and incident data. It collects data from controls or IOT equipment that are spread geographically.

NTO has many years of experience with optical vision control systems aimed at foundries.
Motion Controls provide precise, quick, and controllable positioning, speed or momentum. That is why NTO collaborates with leading manufacturers.

NTO has its own Service & Aftersales department, where we handle support in connection with breakdowns, as well as minor adaptations and expansions.
NTO A/S · Industrivej 8 · DK-7430 Ikast · Tlf.: +45 9715 3344 · nto@nto.dk