Regulation · Physical security

NIS2 and the physical security everyone forgets

NIS2 is read as a cyber regulation, and the work lands with IT. But the requirements expressly cover the physical environment around the systems as well — and that is the part that rarely has an owner.

Christian Tang Mathiasen · · 6 min read

When we get brought into a NIS2 programme, it is usually late. The policies are written, the suppliers are mapped, the logging is in place. Then somebody asks who has actually looked at whether you can walk in through goods reception and be standing in the plant room ten minutes later.

That question typically has not had an owner. Not because anyone has neglected anything, but because it falls between two organisations that are not used to sharing a risk picture.

Briefly, what NIS2 requires

NIS2 is an EU directive from 2022 that replaces the original NIS directive. It extends the requirements to more sectors, divides the organisations in scope into essential and important entities, sharpens supervision and sanctions — and places responsibility with the management, not with the IT department.

The directive was to have been transposed into national law by October 2024. Denmark missed the deadline, and the Danish implementation came later. Supervision is distributed, so which authority you fall under depends on your sector.

The core itself is short: you must take appropriate and proportionate technical, operational and organisational measures to manage risk — and you must be able to show that they work. It does not say which products to buy. It says the risk must be managed, and that somebody must have assessed the effect.

Where the physical sits in the text

Article 21 is where the measures are described. Two things in that article are worth reading slowly.

The first is that the measures must rest on an all-hazards approach: they must protect the network and information systems and the physical environment around them from incidents. So not only from something arriving over the network. An incident can just as easily be water, power, fire, vandalism, or a person standing somewhere they should not have been standing.

The second is the list of minimum measures. It is often read as an IT list, but several of the items cannot be satisfied with technology alone:

  • Access control policies — physical access too. Who can walk over and stand next to the equipment?
  • Asset management — where are the things, who has them, and what happens when they move?
  • Human resources security — what happens to cards, keys and access on hiring, on a change of role and on departure?
  • Supply chain security — supplier risk is not only software. It is also who holds a key, a code or a standing arrangement to turn up outside opening hours.
  • Incident handling and business continuity — both presuppose that somebody notices something has happened.
  • Procedures to assess whether the measures work — that means testing, not self-evaluation in a spreadsheet.

On top of that, the Commission has set more detailed technical requirements for certain types of digital provider in an implementing act. The organisations it applies to get the physical protection spelled out: perimeter, access to premises, protection against physical and environmental threats, and securing supplies such as power and cooling. If you are not covered by that particular act, it is still the best available guidance on what “the physical environment” concretely covers.

And if you fall under critical infrastructure, there is a parallel EU directive on the resilience of critical entities — CER — where physical protection is not a footnote but the entire point. A fair number of organisations are covered by both at once.

Why that part still gets forgotten

The explanation is organisational, not legal.

The NIS2 project lands with the CISO, the head of IT or a compliance function. Physical security sits with facility management, property operations, HR or emergency preparedness. The two sides have their own suppliers, their own budget and usually their own risk picture — if the physical side has one written down at all.

An attacker moves across that dividing line without effort. Network segmentation on a diagram does not mean much if the network socket in the meeting room is live and the meeting room sits before reception. That is not a technical error. It is two correct decisions, taken by two different departments, that nobody has looked at side by side.

From practice

Five places where the requirement and reality do not meet

None of them is exotic. They are the same five we find again and again — in organisations with policy, budget and good intentions alike.

  • Plant rooms and server rooms

    The door is locked. The key is in an unlocked drawer in reception, the code is on the whiteboard, or the door closer has been unscrewed because the room got too hot. The lock is not the problem. The operation around it is.

  • Access cards in practice

    The policy describes issue and withdrawal. Reality is cards that were never blocked after somebody left, contractor cards with no expiry date, and an unknown number of cards in circulation. Run a count — it tends to be uncomfortable, and it is free.

  • Supplier access

    Supply chain security is almost always read as software suppliers. But cleaning, service engineers, catering, guarding and tradespeople have physical access — often outside working hours, often with master keys, often without anyone being able to say who turned up yesterday.

  • Networks in open zones

    Live sockets in meeting rooms, canteens and corridors. Guest networks that are not separated in practice. Printers and screens with access to more than anyone has thought about. This is where the cyber-physical boundary actually runs.

  • Detection and reporting

    There are cameras, and there is logging. The question is whether anyone is looking — and whether an employee who is puzzled knows who to call. The notification deadlines (an early warning within 24 hours, the notification proper within 72) presuppose that the incident was detected and reported. Otherwise the clock never starts.

How an assessment can be used in the work

Let us be precise about what we are not: we are not auditors, we do not issue attestations, and we are neither certified nor accredited to approve anything. What an assessment can do is deliver what the requirement to assess the effectiveness of the measures asks for — documentation that somebody has tested them in the real world.

In concrete terms, what usually goes straight into a NIS2 programme is this:

  • The risk picture — findings from reality instead of from a form, with photographic evidence and a description of how we got further from there.
  • Access control and asset management — a walkthrough of who can actually reach the equipment, and where it stands.
  • Supply chain — a test of whether a supplier role can be imitated well enough to get in.
  • Detection and response — was it noticed, was it escalated correctly, and how long did it take?
  • A baseline over time — eight categories with a percentage score that the next measurement can be held up against. That is the kind of thing that can go into a management report without being translated first.
  • Management briefing — the management’s duty of oversight is hard to discharge from a spreadsheet. Forty-five minutes with pictures of your own building is something else.
We work from
  • ISO 27001 (Annex A)
  • CPTED
  • F&P Sikringsguiden
  • NIS2 / CER
  • NIST SP 800-115

A caveat that belongs here

We are not lawyers. Whether your organisation is in scope, which category you fall into, and how the requirements are formally to be met belongs with your compliance function or your legal counsel. Ask them — and do not use a security supplier’s assessment as a legal basis. Not ours either.

We can answer something else, and something more concrete: do the measures hold when somebody actively tries to get round them? That is also the question a real incident asks — whatever the policy says.

If you are working on NIS2 and cannot point to anyone who owns the physical part, that is probably where the next quarter of an hour should go. And if it then needs testing, a Security Assessment is the shortest route to an overall picture — 200+ control points, eight scored categories and a three-phase action plan, from DKK 47,500 excl. VAT.

Next step

Test the assumptions.
Find the attack paths.

A short conversation is enough to work out whether a Security Assessment or a full penetration test is the better fit. It costs nothing and commits you to nothing.