Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
NIS2 Case Studies in the Belgian Medical Sector
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The recent NIS2 Directive raises cybersecurity expectations for essential and important companies within the European Union. However, empirical evidence on the implementation process of NIS2 in these companies remains scarce. This study addresses that gap by examining two Belgian medical-supply manufacturers through a mixed-methods case-study design.

First, each company completed a self-assessment from the CyFun framework, a framework created by the Centre of Cybersecurity Belgium. The assessments were performed by rating both documentation and implementation of NIS2 related security measures. The results of these assessments showed that the implementation scored significantly better than the documentation in both organisations.

Second, to contextualise these scores, seven stakeholders participated in semi-structured interviews. Thematic analysis revealed four dominant barriers: (1) unstructured security management, (2) awareness of the NIS2 directive, (3) lack of understanding of some parts of the directive, and (4) lack of resource including financial, human, and knowledge-based resources. Collectively, these factors hinder systematic compliance with NIS2, despite the reasonable technical practices that are already implemented within these companies.

The findings suggest that policy makers and responsible parties should complement the existing regulations and guidance with scalable templates, funding incentives, and targeted training. This will further help resource-constrained business formalise their security governance in the best way possible. While the small sample limits generalisability, this work offers one of the first insights into the practical application of NIS2 in Belgian companies.

Place, publisher, year, edition, pages
2025. , p. 47
Keywords [en]
NIS2 Directive, medical sector, cybersecurity, CyFun framework, case study, Belgium
National Category
Information Systems, Social aspects Law Business Administration
Identifiers
URN: urn:nbn:se:his:diva-25507OAI: oai:DiVA.org:his-25507DiVA, id: diva2:1984101
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-07-14 Created: 2025-07-14 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(2755 kB)619 downloads
File information
File name FULLTEXT01.pdfFile size 2755 kBChecksum SHA-512
2d789f548910e542c5f1c874336ae039c1383eaf6781efb7cdc9e60242eee7098d50a899b88579b306abb7f97e944216ee9725bc163e89a57c9ca8a8da15fbb1
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Information Systems, Social aspectsLawBusiness Administration

Search outside of DiVA

GoogleGoogle Scholar
Total: 620 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 520 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf