Directive NIS2 European Union
Art. 21(2)(g)

Basic cyber hygiene practices


The baseline practices every entity must implement, alongside cybersecurity training.

The directive does not enumerate them, which is deliberate. Recital 89 points to zero-trust principles, software and device updates, network segmentation, identity and access management, user awareness, and staff training on cyber threats such as phishing and social engineering.

Related terms

Full glossary →

Cart 0