• Newsroom
  • Join us!
  • Newsletter
  • Kontakt
  • English English English en
  • Deutsch Deutsch German de
Experts Institut
  • Business Consulting
    • Business Solutions
      • Digitization
      • Sustainability Corporate strategy
      • Management systems
      • Project management
      • Strategy & Performance
      • Transformation & Leadership
  • GXP Consulting
    • GMP Beratung
      • Audits & inspections
      • GMP/GXP training courses
      • GMP Aircheck4
      • Continuous Manufacturing
  • Industries
    • Pharma
    • Service providers & trade
    • Automotive
    • FOOD & BEVERAGES
    • Financial service providers & insurances
    • Informationstechnik (IT)
    • Aerospace
  • Academy
    • Individuelle Inhouse-Schulungen
      • GMP/GXP training courses
    • Experts Institut Events
      • Academy
    • Direkt buchen
      • Live-Events
      • On-Demand Webinar
  • Kunden
  • Über uns
    • Über uns
      • Guideline
      • Portrait
      • Team
      • Geschäftsführung
      • Vision
      • Events
      • History Experts Institute
      • Sustainability at the Experts Institute
      • Social responsibility
    • Wissen
      • GMP Glossary
      • FAQ – Frequently asked questions in the GMP environment
      • Videos
    • Blog
      • Newsroom
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Link to LinkedIn
  • Link to Xing

Tag Archive for: Cybersecurity

GMP, GXP

NIS2, Business Continuity, ISO 27001 & Annex 11: Why the Pharmaceutical Industry Needs to Place Greater Emphasis on Cyber Resilience

The pharmaceutical industry has been under intense regulatory pressure for years. Quality, patient safety, validation, supply reliability, and documentation are firmly embedded in processes. However, what was often less visible in the past is now inevitably taking center stage: information security and business continuity are also increasingly becoming critical success factors.

This is because modern pharmaceutical companies are no longer merely manufacturing or research organizations. They are digital ecosystems. Research, clinical data, manufacturing facilities, laboratory information systems, supply chains, quality management, cloud services, and external service providers are all interconnected. If any of these systems is disrupted, the consequences can go far beyond a typical IT outage and have a direct impact on data integrity (ALCOA+) and, ultimately, patient safety.

This paradigm shift is underscored by the upcoming revision of EU GMP Annex 11. The new draft makes it unmistakably clear that cybersecurity, identity management, audit trails, and backup strategies are no longer isolated IT tasks, but are becoming fundamental components of GMP compliance. It is precisely at this intersection of IT operations, quality management, and legal obligations that NIS2, Business Continuity, ISO 27001, and the new Annex 11 work together to ensure the resilience of the entire ecosystem in a systematic and audit-proof manner.

Cyber

Why NIS2 Is Relevant to the Pharmaceutical Industry

The NIS2 Directive has significantly expanded the scope of regulated organizations. Of particular relevance to the pharmaceutical industry is the fact that the healthcare sector and related fields are explicitly addressed. These include, among others, institutions engaged in research and development activities related to medicinal products, manufacturers of pharmaceutical products, and certain manufacturers of medical devices.

This shifts the focus: Cybersecurity is no longer just a technical task for the IT department. It is becoming a matter of organizational resilience, business continuity, and ultimately, supply security.

For affected companies, this means that simply implementing individual protective measures is not enough. What is required is a systematic approach that identifies, assesses, addresses, and regularly reviews risks. This includes technical, organizational, and operational measures—ranging from access controls and backup strategies to incident response, supply chain management, and crisis management.

Business Continuity: More Than Just “Restarting IT”

In the pharmaceutical industry in particular, business continuity is more than just traditional IT disaster recovery. It is not just a matter of restoring servers or restoring data from a backup. The crucial question is: Which processes must continue to run so that research, production, quality assurance, approval processes, or delivery capabilities do not come to a standstill?

A cyberattack on a production system, an outage of a validated laboratory information system, or a disruption at a critical IT service provider can have a direct impact on deadlines, batch releases, documentation requirements, and supply chains.

Business continuity must therefore be approached from a technical perspective. Which processes are critical? What dependencies exist with regard to IT, OT, cloud services, or external partners? How long can a process be down? Which manual alternative processes are realistic? And have these scenarios actually been tested?

NIS2 makes this point particularly clear by explicitly including business continuity, backup management, disaster recovery, and crisis management among the relevant risk management measures.

ISO 27001 as a structured framework

While NIS2 sets out regulatory requirements, ISO 27001 provides a proven management framework for systematically managing information security. The standard requires an information security management system ( ISMS) that addresses risks not on an ad hoc basis, but on an ongoing basis.

This is particularly valuable for pharmaceutical companies because ISO 27001 integrates well with existing management systems. Many companies already have established structures in place for quality, compliance, auditing, and documented processes. An ISMS can build on these and integrate information security into the existing governance framework.

ISO 27001 is particularly helpful in clarifying responsibilities, assessing risks in a transparent manner, prioritizing measures, verifying their effectiveness, and continuously improving them. It is precisely this traceability that is crucial in regulated industries: it is not only the measure itself that counts, but also the rationale, documentation, and regular review.

Annex 11: Cybersecurity Becomes a GMP Requirement

The new draft of Annex 11 (published in July 2025) marks a clear shift away from purely project-based system validation toward a continuous lifecycle and governance approach. The guideline explicitly aligns GMP systems with European cybersecurity expectations such as the NIS2 Directive and ISO 27001. This means that a cyber incident (e.g., ransomware) is no longer just an IT problem, but a direct GMP violation, as it compromises data integrity (ALCOA+).

Seamless alignment with NIS2 and BCM requirements

The new Annex 11 requirements specify exactly the same measures for computer-based systems in a GMP environment as those required by NIS2 and BCM:

  • Business Continuity and Backups: Annex 11 now explicitly and in detail requires backup, archiving, and disaster recovery plans. Testing recovery processes becomes a mandatory requirement, which aligns with the BCM focus of NIS2.
  • Supply Chain Security and the Cloud: While NIS2 requires the management of supply chain risks, Annex 11 specifically mandates this for software and cloud providers. The pharmaceutical company remains fully responsible for compliance and must establish formal service level agreements (SLAs), risk audits, and exit strategies for IT service providers.
  • Identity and Access Management: Modern standards such as multi-factor authentication (MFA), the principle of least privilege (granting only the necessary permissions), and strict segregation of duties are also required in the GMP environment.

The Blind Spot: Supply Chain and Service Providers

A key risk factor in the pharmaceutical industry lies in its interconnections with third parties. Research partners, CROs, CDMOs, cloud providers, software vendors, logistics partners, and external IT service providers are often deeply integrated into critical processes. Therefore, a security incident does not have to originate within one’s own company to impact one’s own organization. If a service provider goes down, data becomes unavailable, or external access is compromised, this can directly impair one’s own operational capabilities.

Therefore, supplier relationships should be evaluated not only from the perspective of quality and procurement, but also from the perspective of information security and business continuity. This includes clear security requirements, defined reporting channels, emergency contacts, recovery times, and regular reviews.

What Matters Most for Pharmaceutical Companies Right Now

Companies should assess whether they are subject to NIS2 or the relevant national implementing legislation, identify which processes are truly critical, and determine how well these processes are protected against cyber incidents, system failures, and service provider disruptions.

Five questions are particularly important in this context:

  1. Which business processes are critical to research, production, quality, and delivery capability?
  1. What IT, OT, and service provider dependencies exist in these processes?
  1. Have risk analysis, incident response, backup, recovery, and crisis management been documented and tested?
  1. Are responsibilities clearly defined all the way up to management?
  1. Is there a management system in place that regularly reviews and improves information security?

Being able to answer these questions with confidence does not automatically mean that an organization is fully compliant. However, it lays the groundwork for a mature and verifiable approach to managing cyber risks.

Conclusion

NIS2, business continuity, ISO 27001, and the revised Annex 11 should not be viewed in isolation within the pharmaceutical industry. They take different approaches but share the same goal: to sustainably strengthen companies’ resilience to cyber risks, system failures, and supply chain disruptions.

While NIS2 establishes the regulatory framework for cybersecurity and organizational resilience, ISO 27001 provides a well-established methodology for the structured management of information security. Business continuity ensures that critical business processes can be maintained even in the event of a crisis. The new Annex 11 also makes it clear that topics such as cybersecurity, backup and recovery concepts, supplier management, and identity and access management will be an integral part of GMP compliance in the future.

The key to regulatory compliance and risk mitigation lies precisely in this integration of IT security, operational resilience, and corporate compliance.

We help companies take a holistic approach to cyber resilience and regulatory requirements—from assessing their current status and conducting risk analyses to establishing management systems and implementing business continuity and information security measures. Get in touch with us – info@expertsinstitut.de

References:

  1. Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 — NIS 2 Directive
    Basis for NIS 2 compliance, in particular scope, affected sectors, risk management measures, reporting obligations, and business continuity requirements.
    https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555
  1. DIN EN ISO/IEC 27001:2024-01 — Information security, cybersecurity, and data protection; Information Security Management Systems — Requirements
    Basis for the ISO 27001 reference, in particular ISMS, risk assessment, risk treatment, governance, documented information, and continuous improvement.
  1. Federal Office for Information Security (BSI): NIS 2 Starter Pack / Information for NIS 2-regulated companies
    Supplementary resource for the German context, particularly regarding the classification of affected companies, registration, reporting requirements, and risk management measures.
    https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-Starterpaket/nis-2-start_node.html
  1. European Commission: Stakeholder Consultation on the Revision of EU-GMP Annex 11, Annex 22, and Chapter 4
    Reference for the revision of EU-GMP Annex 11, particularly regarding the expanded cybersecurity requirements. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en

Read our entire blog here: https://experts-institut.de/newsroom/
And feel free to follow us on LinkedIn: https://de.linkedin.com/company/expertsinstitut

1 month /by Lirim Smajli
https://experts-institut.com/wp-content/uploads/2026/06/LinkedIn-Kopie.jpg 1080 1920 Lirim Smajli https://experts-institut.de/wp-content/uploads/2023/02/GEMI_Logo_Slogan_color_RGB.webp Lirim Smajli2026-06-15 17:56:042026-06-15 17:56:27NIS2, Business Continuity, ISO 27001 & Annex 11: Why the Pharmaceutical Industry Needs to Place Greater Emphasis on Cyber Resilience
Recent
  • Cyber
    NIS2, Business Continuity, ISO 27001 & Annex 11: Why...1 month 
  • Audit
    Too many audits, too little effect? Solving audit fatigue...23. April 2026 - 21:43
  • Lieferantenmanagement
    Supplier management in the GMP industry: regulatory framework...23. February 2026 - 15:36
  • AI
    Pharmaceutical-grade use of generative AI: regulations,...4. February 2026 - 15:19
Popular
  • Qualitätsmanagement
    How to create an effective quality management system (QMS)...31. July 2025 - 10:39
  • Informationssicherheit
    ISMS 2024: What companies need to know now about NIS2, DORA,...3. July 2025 - 12:32
  • Deviation Management
    Enhancing Process Stability through Effective Deviation...27. March 2025 - 11:07
  • Supplier-Audit Reports
    Untrue Supplier-Audit-Reports: The Danger of Ethnocentric...9. January 2025 - 11:29

Tags

AI AI Annex Annex 11 Annex 22 Artificial Intelligence Audit audits Business Continuity Management Cannabis Certification Clean room Computerized systems Continuous Manufacturing CRA Cultures Cytostatics Data Integrity DORA Draft EU AI Act Germ count Germ count monitoring GMP GXP Health insurance Information security inspections ISMS ISO/IEC 42001 ISO 9001 ISO 27001 ISO standard Laboratory Machine Learning NIS-2 NIS2 Pharmacy QMS Quality management system Reagents Regulations Retaxation Sustainability Transformation

Kategorien

  • AI
  • Business Solutions
  • GMP
  • GXP
  • News
  • Retaxation
  • Sustainability
  • Uncategorized

Archiv

  • June 2026 (1)
  • April 2026 (1)
  • February 2026 (2)
  • January 2026 (2)
  • December 2025 (1)
  • November 2025 (1)
  • October 2025 (1)
  • September 2025 (1)
  • July 2025 (2)
  • March 2025 (1)
  • January 2025 (1)
  • December 2024 (1)
  • November 2024 (1)
  • October 2024 (3)
  • September 2024 (2)
  • August 2024 (2)
  • July 2024 (2)
  • May 2024 (1)
  • April 2024 (2)
  • March 2024 (2)
  • February 2023 (10)
Logo Experts Institute

Webpräsenz der Allianz für Cyber- Sicherheit
kununu widget

Business Solutions

  • Digitization
  • Sustainability
  • Management systems
  • Project management
  • Strategy & Performance
  • Transformation & Leadership

GMP / GXP Consulting

  • GMP Consulting
  • GMP audits & inspections
  • GMP/GDP training courses
  • GMP/pharmaceutical engineering
  • Continuous Manufacturing

EI Academy

  • GMP / GxP
  • Academy
  • Live events
  • On-demand webinar

New town

Experts Institut Beratungs GmbH
Weinstraße 85

D-67434 Neustadt a. d. Weinstraße

Phone: +49 (0)6321 969210
E-mail: info@expertsinstitut.de

Fax: +49 (0)6321 9692199

Bamberg

Experts Institut Beratungs GmbH
Untere Sandstraße 53

D-96049 Bamberg

Phone: +49 (0)951 51939330
E-mail: info@expertsinstitut.de

St. Gilgen (Austria)

Experts Institut Beratungs GmbH
Helenenstraße 16

A-5340 St. Gilgen, Austria

Tel.: +43 (0)6227 21068
E-Mail: info@expertsinstitut.de

  • Link to LinkedIn
  • Link to Xing

© 2024 Experts Institut Beratungs GmbH
  • Imprint
  • Data protection
  • AGBs
  • Cookie Directive (EU)
Scroll to top Scroll to top Scroll to top