Contact company icon Add as a preferred source Download PDF version
Summary is AI-generated, newsdesk-reviewed
  • NIS2 expands cybersecurity regulations, impacting 160,000 organisations and their physical security strategies.
  • Organisations face severe penalties for non-compliance, including fines up to €10 million.
  • ASSA ABLOY solutions enhance NIS2 compliance by securing digital infrastructure from hybrid attacks.

The European Union's NIS2 Directive is reshaping strategies across organisations by emphasising both cybersecurity and physical security measures. While traditionally the focus has been on cybersecurity, the directive now highlights the importance of cyber-physical resilience. This shift brings significant consequences for organisations failing to comply, including hefty penalties.

NIS2 builds upon the 2016 NIS Directive on Network and Information Security, tightening IT security requirements, particularly for critical infrastructure, and extending them to additional sectors. The European Commission anticipates that approximately 160,000 organisations will be affected by NIS2 from the outset.

Important change for security

For security and facilities managers, a critical shift introduced by NIS2 is the "all-hazards approach." This broader regulatory strategy mandates enhanced digital security measures paired with processes and devices that protect digital infrastructure physically.

Consequently, cyber-physical resilience becomes vital as the volume and sophistication of hybrid cyber-physical attacks increase. Enhancing collaboration between cyber and physical security teams is essential to address these evolving threats.

NIS2 and physical security: Scope, compliance, financial penalties

NIS2's scope now reaches above formal infrastructure sectors, including energy, utilities, transport, telecoms

NIS2's scope now reaches beyond traditional infrastructure sectors, including energy, utilities, transport, telecoms, and data centres. It also encompasses sectors such as healthcare, digital services, and various manufacturing industries, including food, chemicals, and automotive. Organisations within these categories should review the directive to determine their compliance obligations.

The directive mandates taking appropriate technical, operational, and organisational measures to manage risks to network and information security and minimising the impact on service recipients. Protecting areas where malicious actors could access digital infrastructure, such as IoT devices or servers, is essential, necessitating robust access control protocols.

Non-compliance with NIS2 may result in substantial penalties, potentially reaching up to €10 million or 2% of global annual turnover. Older security systems could thus pose significant liability risks.

NIS2 impact on access control workflows

NIS2's impact on security management involves implementing the "all-hazards" approach. This includes refining risk analysis of digital devices, ensuring supply-chain security, optimising physical access management for personnel, enhancing cyber hygiene training, and planning for business continuity in breach scenarios. Security teams must promptly assess their current cyber-physical resilience to identify necessary improvements.

NIS2 compliance efforts

Access management plays a crucial role in achieving NIS2 compliance. Advanced access solutions can enhance cyber-physical resilience through improved identity management, auditability, and remote building control. Systems requiring regular credential renewal reduce the risk of unauthorised key circulation, a potential vulnerability for digital infrastructure.

Solutions from ASSA ABLOY offer robust digital access systems to enhance compliance with the NIS2 Directive. They ensure comprehensive access control, supporting both online and offline scenarios, enabling instant cancellation of lost credentials, and providing scalable control over formerly inaccessible access points. Wireless solutions offer easy installation without structural modifications.

In an era of hybrid attacks, physical access often remains a critical vulnerability. Mitigating this with digital enhancements aligns with NIS2 obligations, alleviating compliance concerns for security decision-makers. ASSA ABLOY's experts offer guidance to align features with directive requirements, bolstering organisational cyber-physical security frameworks.

Learn why leading casinos are upgrading to smarter, faster, and more compliant systems

In case you missed it

What are emerging applications for physical security in transportation?
What are emerging applications for physical security in transportation?

Transportation systems need robust physical security to protect human life, to ensure economic stability, and to maintain national security. Because transportation involves moving...

Gallagher & Fortified enhance perimeter security solutions
Gallagher & Fortified enhance perimeter security solutions

Global security manufacturer - Gallagher Security is proud to announce a strategic partnership with Fortified Security, a pioneering perimeter systems integrator with over 30 years...

Genetec: Data sovereignty in physical security
Genetec: Data sovereignty in physical security

Genetec Inc., the global pioneer in enterprise physical security software, highlights why data sovereignty has become a central concern for physical security leaders as more survei...