ISJ hears exclusively from Jaroslav Barton, HID‘s Product Marketing Manager for Physical Access Control in Europe discusses NIS2.
The European Union’s Network and Information Security 2 (NIS2) Directive is now in effect, ushering in broad requirements to enhance cybersecurity and better protect critical infrastructures.
Failure to comply with the directive, which took effect October 17, 2024, could result in steep fines and other punitive measures.
Along with a comprehensive set of legal measures, NIS2 introduces a new landscape for cybersecurity with a focus on enhancing the resilience and security of network and information systems across the EU.
It comes at a particularly critical security juncture. Led by Distributed Denial of Service (DDoS) and ransomware, the European Union Agency for Cybersecurity (ENISA) study called ‘Foresight Cyber Security Threats for 2030’ reports a significant rise in the variety, quantity and consequences of cyber-attacks – with no signs of abatement on the horizon.
The NIS2 backstory
NIS2 represents a significant step forward in the EU’s efforts to enhance cybersecurity across member states.
It builds upon and modernises the legal framework first articulated in the original NIS Directive, addressing the evolving threats and challenges in the digital realm by strengthening the security of network and information systems.
Covering a wider range of entities than its predecessor, NIS2 encompasses sectors including energy, transport, finance, healthcare, utilities, digital infrastructure and public administration.
While size thresholds vary by industry, organisations with as little as €10 million in gross annual revenue are impacted.
Fines for non-compliance are also far steeper under NIS2, ranging up to 10% of an entity’s annual turnover. Other notable changes include:
- An expanded scope: Any company that is part of an “essential entity” (EE) or “important entity” (IE) organisation’s supply chain must now comply with NIS2
- Stricter controls: Stricter and more comprehensive security measures are required, such as mandates to implement robust controls to mitigate risks and protect systems and data
- Stronger reporting requirements: Organisations must report significant cybersecurity incidents – defined as any event that might cause severe damage, disruption or loss to either the organisation or other people – within 24 hours of detection to the authority designated by their member state
Ultimately, NIS2 is about building cybersecurity resilience which is why it emphasises company-specific assessments and processes rather than a “one-size-fits-all” approach to compliance.
As such, compliance efforts should begin with an operational risk assessment to understand relevant threats.
This assessment is not a one-off.
It should be repeated every four years or whenever there is a significant change in circumstance that alters an organisation’s risk profile.
Connecting physical and cybersecurity
NIS2 comes at a time when physical and digital worlds are increasingly intertwined. According to the 2024 State of Physical Access Control report, published by HID in partnership with IFSEC Insider:
- Nearly half (48%) of all respondents confirm that the IT department is “fully consulted” when it comes to upgrading physical access control systems
- 58% of security personnel work with the IT department to establish best security practices
- 55% of security respondents said they collaborate with IT when looking for new technologies
Gartner echoes this convergence, reporting that 41% of enterprises plan to combine parts of cyber and physical security by 2025 – a 10% increase over 2020.
This interconnection of physical and digital systems provides numerous benefits, but also additional vulnerabilities.
For example, a compromised physical access control system (PACS) might allow criminals to access restricted areas, disable alarms, alter permissions and steal proprietary information.
Legacy PACS provide significantly less security and introduce more risk. Per the State of PACS report, 42% of respondents reported their organisation’s access control system was less than three years old while 14% said it was more than six years old.
Upgrades to system software were planned by 54%, while 53% planned to upgrade readers and credentials and 50% intended to upgrade controllers.
Unifying information technology (IT) and operating technology (OT) is the only way to achieve a holistic view of the entire operation and mitigate the growing threats that come with interconnected systems and devices – which is why NIS2 addresses both fronts.
Fortifying compliance
Fortifying the cybersecurity of an organisation’s PACS goes beyond evaluating the integrity of individual components.
Part of an NIS2 risk assessment should be an examination of the path information travels from component to component to identify where risk might be introduced.
For example, how is sensitive information about employee identities and authorisation privileges provisioned onto credentials? How is it stored and managed?
A recommended approach is a “good, better, best” framework, which first establishes a baseline before making further upgrades and improvements. This framework focuses four areas:
- Credentials: Set a baseline with smart cards or virtual cards. Data stored on the card should be protected with encryption (AES 128 is best practice), as should data that is communicated to readers during the authentication process. Improve security by deploying key management policies. Also, look for solutions that have been penetration tested and certified by a third party
- Readers: Set a baseline with readers that support encrypted cards and are equipped with a secure element to store encryption keys. Improve security by selecting a solution that offers a secure communication channel between reader and controller using IEC 60839-11-5:2020 standard OSDP v2. Manage updates and upgrades via authorised maintenance applications, not configuration cards
- Controllers: Set a baseline by installing controllers in a secure, tamper-proof enclosure, connecting them to a secure, dedicated VLAN, deactivating all other interfaces, removing all default configurations and ensuring that firmware and patches are always current. Improve security by allowing only approved IP addresses to connect to the controller and ensuring that encryption is used to protect data at rest and in transit
- Access control servers and clients: Set a baseline by hosting servers and clients on a secure, dedicated VLAN. Select a solution that offers transparent Common Vulnerabilities and Exposures (CVE) reporting and complies with Secure Software Development Lifecycle (SDLC) standards like ISA/IEC 62443-4-1 and make sure to keep software and operating system patches up to date. Improve security by encrypting data at rest and in transit and deploying custom TLS certificates
Finally, ensure any vendors that are part of the organisation’s supply chain are compliant with NIS2.
Things to look for include certifications that exceed NIS2 such as SOC2 Type 2, ISO 27001, ISO 27018, CSA Star Level 2 and SEAL-5 TÜV Security Certification.
They should also demonstrate a commitment to continuously monitoring the evolving cybersecurity landscape and adjusting practices to meet or exceed new standards as they develop and provide end-to-end interoperable protection encompassing everything from PACS and identity and access management to digital certificates and biometrics.
Closing the security gaps
NIS2 comes at a time when physical and cybersecurity are increasingly entwined.
Compliance with this sweeping directive not only avoids financial penalties but is a way to navigate today’s twisting cybersecurity landscape and create secure, resilient IT and IO systems.
The key is to understand the scope and breadth of the directive, take the steps necessary to comply internally and ensure any vendors that are part of the organisation’s supply chain are as serious about compliance as the organisation itself.

