
NIS2 and Building Technical Infrastructure: What Companies and Facility Managers Must Actually Do
NIS2 has attracted a lot of marketing noise, and it is easy to miss the basic point: the directive is not only about "cybersecurity" in the sense of firewalls and antivirus software. Physical security of infrastructure — access to server rooms, power, cooling, cabling — is explicitly part of the risk management the directive requires, along with the national legislation implementing it.
Who it applies to
The list of essential and important entities is broad: energy, transport, healthcare, public administration, waste management, selected manufacturing categories, digital services — and, indirectly through the supply chain, their subcontractors and service providers as well. In practice, NIS2 requirements cascade downwards: a company in scope starts imposing them on its suppliers, including the managers of the buildings it operates in.
The physical layer everyone forgets
The risk analysis NIS2 requires also covers physical scenarios: unauthorised access to technical rooms, power failure, fire in the server room, overheating. From a facility perspective this translates into a concrete list:
Access control to technical zones — named, with an event log that cannot be overwritten. A key hanging at the reception desk does not meet that requirement. Environmental monitoring of the server room: temperature, humidity, water leaks, smoke — with alerting, not just logging. Backup power with documented test results: a UPS whose batteries have not been tested in three years is a declaration, not a safeguard. Redundancy wherever the risk analysis calls for it: a second power source, two independent network paths, backup cooling.
Business continuity and documentation
NIS2 requires business continuity and disaster recovery plans. For technical infrastructure that means answering some direct questions: what happens when a power outage outlasts UPS runtime? Who responds to a server room alarm at three in the morning on a Saturday, and how quickly? Where is the documentation needed to rebuild the configuration? If the answer to any of these is "depends who happens to be at work", the plan does not exist.
There is also the obligation to report significant incidents on tight deadlines (an early warning within 24 hours). Without infrastructure monitoring it is hard to even know an incident occurred, let alone report it on time.
Where to start
A sensible sequence: audit the current state and map physical risks, close the critical gaps (access control, environmental monitoring, power testing), then put procedures and service contracts with guaranteed response times in place, and document everything at the end. The penalties in the legislation are attention-grabbing, but the real argument is different: the same measures that deliver compliance simply reduce the risk of a costly outage.
Facility Infrastructure Monitoring
Centralized real-time monitoring and management of building technical infrastructure.
Related Articles

Server Room Cooling in Summer: Why Outages Happen and How to Prevent Them
Read full article
What Does 24/7 IT Support Cost? Pricing Models and SLAs Explained
Read full article
