
Figure 1
Topic 1: Strategic & Policy-Level Cyber Governance.
Source: Own processing based on data from Web of Science.

Figure 2
Topic 2: Cybersecurity Law & Regulation (EU).
Source: Own processing based on data from Web of Science

Figure 3
Topic 3: Skills & Technical Capacity Building.
Source: Own processing based on data from Web of Science.

Figure 4
Cumulative number of GDPR fines over time.
Source: Own processing based on data from enforcementtracker.com.

Figure 5
Sum of GDPR fines by sectors.
Source: Own processing based on data from enforcementtracker.com.
Table 1
Scope extensions of NIS Directive to NIS 2
| NIS 1 | NIS 2 |
|---|---|
| Drinking water supply and distribution | Water – drinking water, waste water |
| Energy | Energy – electricity, district heating and cooling, oil, gas, hydrogen |
| Digital infrastructure | Digital infrastructure |
| Banking | Banking |
| Financial market infrastructures | Financial market infrastructures |
| Health | Health |
| Transport | Transport – air, rail, water, road |
| ICT service management (B2B) | |
| Public administration | |
| Space | |
| Postal and courier services | |
| Waste management | |
| Manufacture, production and distribution of chemicals | |
| Production, processing and distribution of food | |
| Manufacturing – medical devices, computer electronic or optical products, machinery, vehicles | |
| Digital providers | |
| Research |
Source: Annex I and Annex II of Directive (EU) 2022/2555.