Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
NIS2 Directive’s impact on reshaping the CISO role
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The evolving cybersecurity threat landscape and recent legislative advancements in the European Union have brought the role of the Chief Information Security Office (CISO) more attention. This thesis investigates the impact of the NIS2 Directive on the responsibilities, expectations, and strategic positioning of CISOs in the affected organizations. NIS2 seriously broadens the scope of the original NIS Directive by introducing stricter cybersecurity requirements, and adding explicit, more severe obligations and enforcement to now both public and private sectors. Using a combination of a comparative analysis of legal texts, systematic literature review, and semi-structured interviews with industry professionals, this research identifies how the directive reshapes the CISO’s responsibilities in areas such as risk management, incident reporting, regulatory compliance, and internal governance. The findings reveal that NIS2 orders for a more proactive and integrated approach to cybersecurity, adding to the CISOs’ duties. Depending on the organizations, those changes might be well processed if prepared accordingly, but might induce more disorganization in others. This study highlights the need for clearer role definitions through standardization and an enhanced organizational support. The results aim to provide insights for organization leaders, and cybersecurity practitioners looking to better their regulatory transition and strengthen their cyber resilience.

Place, publisher, year, edition, pages
2025. , p. iv, 64
Keywords [en]
CISO, NIS2, Chief Information Security Officer, Network and Information Systems, Directive, Governance, Systematic Literature Review, Interviews
National Category
Information Systems, Social aspects Law
Identifiers
URN: urn:nbn:se:his:diva-25479OAI: oai:DiVA.org:his-25479DiVA, id: diva2:1983413
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-07-10 Created: 2025-07-10 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(728 kB)551 downloads
File information
File name FULLTEXT01.pdfFile size 728 kBChecksum SHA-512
fd473f4e721fa480cf6e95fe12c48a471dfd31025b0f59bc7c0e7f69180bd54ad11786ce17be9336ab42d68699a58b1f5da36f7cf60daca8557a807174d1001f
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspectsLaw

Search outside of DiVA

GoogleGoogle Scholar
Total: 555 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 440 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf