Operators of essential services are required to adopt appropriate and proportionate technical and organizational measures to manage risks posed to the security of network and information systems. This includes incident handling, business continuity, monitoring, auditing, and control.