Glossary · NIS2
All-Hazards Approach
The NIS2 principle that security measures must protect against all threats to network and information systems, not just cyber attacks.
Explained in depth: The 10 NIS2 security requirements
Article 21 explicitly requires that the ten risk-management measures be based on an all-hazards approach. This means entities must protect network and information systems, and their physical environment, from any incident that could compromise them: ransomware and intrusions, but also power failures, fires, floods, hardware faults, and the loss of key personnel or suppliers. In practice, the all-hazards approach pulls traditionally separate disciplines into the NIS2 programme: physical security, facilities management, and business continuity planning sit alongside firewalls and endpoint protection. A risk assessment that only covers malicious cyber threats is incomplete under NIS2.
Why it matters
Auditors will look for evidence that your risk analysis considered non-cyber scenarios: what happens when the data centre loses power, when the office floods, or when your single-source supplier fails. If your risk register only contains attack scenarios, that is a finding.
