Sectors
Sectors
Airports
Corporate and Commercial
Corporate and Commercial
Retail
Sports and Entertainment
Sports and Entertainment
Telecom and Energy
Telecom and Energy
Transport and Infrastructure
Transport and Infrastructure
Systems
Systems
Security Management
Security Management
FLINQ Security Management System
FLINQ Security Management System
VDG SENSE Video Management System
VDG SENSE Video Management System
IPROTECT Access Control System
IPROTECT Access Control System
ATLAS Access System
PARK ASSIST Parking Guidance
Asset & Site Management
Asset & Site Management
APOLLO Asset & Site Management System
APOLLO Asset & Site Management System

NIS2 Compliance & Physical Access Security

Are You Ready?

Two colleagues reviewing the IPROTECT visitor and employee management dashboard on dual monitors in a control room

Did you know that in 2025:

3d space
+20% increase in cyber incident

and breach reporting across the EU

widgets
57% of companies

said they would likely go out of business if attacked

2
Nearly 1 in 3 companies

in the EU has not tested its cybersecurity in the past year

To address this growing threat, the EU is enforcing the NIS2 Directive, which came into force in October 2024, with enforcement now accelerating across member states throughout 2026.

What is NIS2?

The NIS2 Directive strengthens cybersecurity requirements across the EU, helping companies improve resilience against an increasingly complex threat landscape.

It introduces broader risk management obligations covering both digital and physical security. This includes areas such as access control, perimeter protection, visitor management, and securing critical infrastructure and sensitive locations.

Failure to meet NIS2 requirements can lead to significant financial penalties and increased accountability for management. Taking a proactive approach to compliance not only reduces risk but also helps build a more resilient organisation.

As cyber threats continue to evolve, making continuous improvement, regular risk assessments, and ongoing security investment is essential for long-term resilience.


Which Companies are Subject to NIS2 Requirements Today?

NIS2 applies to medium and large companies operating in sectors considered essential or important to the European economy and society. Companies within the supply chain of NIS2-regulated entities may also need to meet enhanced cybersecurity expectations. 

Classified Companies:

  • Mid-size Organizations: 50 to 250 employees and €10M–€50M in annual revenue
  • Large Organizations: more than 250 employees and more than €50 million in annual revenue

Large (essential) and mid-size (important) organizations are required to comply with NIS2 in the following 18 sectors:  Energy, Transport, Banking, Financial Market Infrastructures, Health, Drinking Water, Wastewater, Digital Infrastructure, ICT Service Management, Public Administration (If a member state decides), Space, Waste management, Manufacture, production and distribution of chemicals, Production, processing and distribution of food, Manufacturing, Digital Providers, Research.


Why NIS2 Requires Ongoing Board Management Commitment

NIS2 places responsibility for cybersecurity compliance on board management. Those responsible for ensuring compliance may face personal sanctions, (incurring fines of up to €10 million or 2% of global annual turnover, whichever is higher), management bans, and more.

As cyber threats continue to evolve, compliance should be viewed as an ongoing business commitment—not a one-off project.


The Role of Physical Access Security in NIS2 (Access Control, Video Management System)

While NIS2 focuses on strengthening cybersecurity, it also recognises the importance of protecting the physical environment of network and information systems. Access control helps reduce risk by ensuring only authorised individuals can access buildings, IT & critical infrastructure, and sensitive areas.

An access control solution supports NIS2 by helping companies to:

  • Secure buildings and restricted areas
  • Manage employee, visitor, and contractor access
  • Maintain detailed access logs for auditing and investigations
  • Reduce the risk of unauthorised access and insider threats
  • Strengthen business continuity and organisational resilience

How Our Physical Security Solutions Support 6 of the 10 Core NIS2 Requirements

Below you could find examples of physical security solutions. Let’s discuss what is applicable for your company.


(Physical) security aspects in the field of personnel, access policy, and asset management

  • Adaptive security through Threat level management: Adapt security policies instantly in response to changing threat levels or incidents. Automatically adjust access rights, lockdown sensitive areas, and strengthen protection when elevated security measures are required.
  • Flexibility through granular permission settings (RBAC): Assign access permissions based on an individual's role, responsibilities, or department. Granular access rights help enforce the principle of least privilege, reduce insider risk, and simplify ongoing user management.
Hand presenting an access card to a TKH Security reader in a server room
Man reviewing the IPROTECT security management dashboard (floor plan) on dual monitors in an office

Incident handling & real time response

  • Always notified about pre-defined events: Automatically trigger predefined actions when a security event occurs, such as displaying live camera feeds, notifying security personnel, or activating site responses. Automation helps ensure faster, more consistent responses to potential threats.
  • Automated alarm notification with workflow: An operator gets physical access alarm notification through floorplan with workflow steps should be taken.

Cryptography and Encryption

  • Secure access via OTP & SSO: Protect access to security systems with authentication methods, including passwords, one-time passwords (OTP), single sign-on (SSO), and Microsoft Entra ID integration. Multi-layer authentication helps verify user identities and reduce the risk of unauthorised access.
  • Secure end-to-end communication with IPROTECT: Ensure data exchanged between credentials, controllers, and servers is protected through end-to-end encryption.
Man reviewing a cybersecurity shield graphic on his laptop in an office
Three colleagues discussing security measures around a laptop in a server room

Business continuity and crisis management

  • Automated backup for operations (Failover protection): Automatically switch to a standby system if a server fails, ensuring continuous surveillance monitoring and uninterrupted security operations with minimal downtime.
  • Camera as a backup for lost network (Edge recording): Maintain video recording even during network outages by securely storing footage on cameras. Once connectivity is restored, recordings are automatically or manually synchronised to preserve a complete evidence trail.

Multi-factor authentication

Card & PIN and Card & Biometry offer flexible multi-factor authentication to strengthen access security while ensuring a fast and seamless user experience.

Man entering a PIN on a TKH Security keypad reader beside server racks
Hand holding an access card near a TKH Security swing handle and network switch panel

Security in the processing, development and maintenance of network and information systems, incl. your IT room and infrastructure

  • A Unified Security Interface: It provides a single, intuitive interface to monitor access points, cameras, alarms, intercoms, and more through a live, interactive floor plan of a facility. Take action in real time: arm or disarm systems, adjust door states, control video feeds, and respond to events as they happen.
  • Automation of predefined actions: Automatically initiate predefined responses to security events, such as displaying live video, notifying security personnel, activating alarms, or triggering other security workflows. Automation reduces response times and ensures consistent incident handling.
  • Automation of intrusion detection: Continuously monitor IT cabinets and critical infrastructure through door state monitoring, handle status detection, side panel tamper detection, and optional camera verification. Real-time alerts help security teams detect unauthorised access and respond rapidly to potential threats.

Real Use Cases

See how our solutions help companies protect their facilities and IT infrastructure against real security threats, ensuring business continuity, operational resilience, and rapid incident response.

Person using an access card at a TKH Security reader on an office door
Unauthorized Access

No card cloning risk with IPROTECT

TKH Security surveillance camera mounted on an industrial building facade
Network Sabotage

Automated backup operation for system continuity - Failover protection

Three colleagues discussing security data around a laptop in a server room
Database Attack

Secure end to end communication with IPROTECT

Man monitoring the IPROTECT security dashboard (floor plan) on dual monitors in an office
Incident Response

Pre-defined event in IPROTECT triggers alarm

And much more!

Customer Story
noris network AG

Founded in 1993, noris were the first Internet service provider in northern Bavaria making them a pioneer. They have been living up to this role for 30 years. With now more than 500 colleagues, they offer their customers IT services in various areas.
noris network AG data centre building exterior with modern infrastructure

Let's discuss your physical access security supporting NIS2 compliance