NIS2 at odds with academic freedom

New European cybersecurity directive places heavy demands on universities

Dutch universities have been required to comply with stricter data security rules since August 15. The new NIS2 directive requires, among other things, that all servers at TU/e be monitored — a measure that affects academic freedom. This is especially sensitive because the monitoring is done with an American tool, which raises concerns given the current geopolitical context.

by
photo Eoneren / iStock

NIS2 — a European directive implemented in the Netherlands through the Cybersecurity Act (Cbw) — sets higher cybersecurity requirements for Dutch universities and universities of applied sciences. The Cbw came into force on August 15, and with it NIS2.

Corry Wouters, Director of Library and Information Services (LIS), sees that this places significant demands on TU/e. “Fortunately, the ministry has provided some funding, but it’s still a major operation.”

The reason TU/e and other universities fall under NIS2 is mainly the knowledge generated through research. The government considers this intellectual property highly valuable for the Netherlands.

Dutch universities are jointly developing a plan to meet the new data‑security requirements. Wouters is the lead author of the WO Digitalisation Strategy 2030, a national project aimed at strengthening the digital resilience of Dutch universities. Together with representatives from other universities, she has developed a digital roadmap for the coming years.

Legislation

The European Commission (EC) recently launched a new action plan to ensure the safe use of AI and strengthen cybersecurity across Europe. This plan builds on existing regulations such as NIS2 and the AI Act, as AI has a major impact on cybersecurity and digital resilience. The EU sets goals and guidelines like NIS2; the Netherlands then creates national legislation to implement them — in this case, the Cybersecurity Act.

The EC’s plan has three goals: promoting safe and responsible use of advanced AI, strengthening the EU’s cybersecurity and resilience, and scaling up European AI capabilities for cybersecurity applications. Since August 15, the Cbw has been binding for Dutch universities, requiring them to pursue these European resilience objectives.

AI

AI is rapidly transforming the cybersecurity landscape. On one hand, AI can help detect system vulnerabilities, prevent cyberattacks, and strengthen the protection of critical infrastructure.

On the other hand, AI can also be misused by malicious actors to automate attacks, identify weak points, and carry out cyberattacks at unprecedented speed and scale.

TU/e will also use AI to improve digital security, but Wouters does not want to disclose exactly how. For security reasons: revealing too much could enable misuse.

Checking suppliers

“We’ve reached a point where the vast majority of applications used at TU/e are SaaS applications,” Wouters explains. This means you purchase a licence and receive a subscription to the software.

“You spend less time checking your own applications for security, and much more time checking your suppliers. They must have their resilience in order if we use their software and store sensitive data in it.” Think of HR or invoicing systems.

But how do you standardize checking whether all suppliers meet NIS2 cybersecurity requirements? For that, there is the international information‑security standard ISO27001.

“Suppliers must arrange certification themselves through an independent body, and we hold annual evaluation meetings with them to ensure everything is and remains in order,” Wouters says.

American tool

In addition to stricter supplier management, more changes come with the new law. “We must also map all servers, register them in a central administration, and monitor them.”

“And by all servers, we really mean all servers running at the university,” Wouters emphasises. “SURF has set up a monitoring centre so that each university doesn’t have to arrange this individually.”

TU/e must install a monitoring tool on every server to keep an eye on them remotely. This does not mean that TU/e or SURF will monitor or inspect research data.

“But still, Big Brother is watching you, and that affects academic freedom — I’m aware of that,” Wouters says. “And it’s extra sensitive because SURF chose an American monitoring tool: Microsoft Defender Endpoint.” Concerns about American control over data via software like Microsoft’s have been raised before in Cursor.

Wouters sometimes has difficult conversations about it, but she notices they stem from genuine concerns among TU/e staff.

Geopolitics

“Two years ago, when the tool was purchased, we couldn’t have predicted the geopolitical situation would shift so much, making this potentially a threat to our sovereignty. Still, we hope for cooperation from the departments. Fortunately, most are already on board.”

LIS has assigned staff to help the departments install the tool — a task that only takes a few minutes.

The idea behind central monitoring is that suspicious situations can be detected more quickly. This allows swift action and reporting — also a requirement under NIS2. Suspicious situations and incidents must be reported to the National Cyber Security Centre (NCSC).

Wouters stresses that TU/e does not want to restrict academic freedom. “The core idea is to detect technical signals faster so we can better protect systems, research data, and personal information.”

Crown jewels

In addition to registering and monitoring all servers, Wouters has also mapped all TU/e ‘crown jewels’. “These are applications that receive a 3‑3‑3 BIV classification for information security.”

“Without getting too technical: crown jewels are applications essential to our operations. They must be almost continuously available, their data must not be altered easily, and they contain highly sensitive information.”

The university‑wide crown jewels have largely been identified, such as the planning app Planon. “But from the departments, we don’t yet have a complete overview — that’s still in process.”

Wouters is pleased with the overview LIS has already created thanks to NIS2. “We now have one list of all applications used within TU/e, which is helpful for identifying duplicates in the future.”

Human factor

The new directive and all related work also make staff more aware of their own role, she observes. “People are the crucial factor in digital resilience — as we saw with the Canvas hack and the data theft at Odido.”

“Increased awareness can help keep personal data safer. Although I no longer dare claim that the organisation is a hundred percent secure — you simply can’t say that anymore. You do your best to organise cybersecurity as well as possible, but full guarantees are impossible to give.”

Share this article