What an all-hazards approach means
NIS2 requires risk-management measures that fit the organisation's actual exposure. An all-hazards assessment starts with critical services and protected interests and then considers the different events that could affect them. Cyber incidents remain important, while physical, technical, organisational and supply-chain disruptions are assessed within the same coherent picture.
This avoids separate risk lists that compete for attention. A data-centre fire, malicious encryption, a telecom outage and a failed software update may have different causes yet produce similar effects on availability, safety and trust.
Why this matters in the boardroom
Boards allocate resources and accept residual risk. They therefore need to understand the service impact, duration, dependencies and recovery options behind a scenario. An all-hazards view supports proportionate decisions because it compares risks through common business and societal consequences.
The method also reveals shared weaknesses. A single location, supplier, identity platform or key employee may be relevant to several scenarios and deserve priority.
Use scenarios as well as control lists
Control lists help verify coverage, while scenarios reveal whether arrangements work together. A useful scenario describes the trigger, affected processes, immediate decisions, dependencies, expected impact, available controls, recovery target and escalation route.
- Which critical service is affected and for how long?
- Which people, systems, locations and suppliers are required for recovery?
- Which interests are at stake: continuity, safety, finance, reputation or personal data?
- Which control is preventive, detective, corrective or recovery-focused?
- Which residual risk requires an explicit board decision?
Connect the risk picture with internal control
The risk analysis becomes useful when each material scenario has an owner, measures, evidence of operation, a recovery objective and a review cycle. Management reporting can then show changes in exposure, overdue actions, test results and decisions instead of presenting a static heat map.
Exercises, supplier reviews and incident lessons keep the analysis current and help the board see whether control effectiveness is improving.
Frequently asked questions
Does all hazards mean every imaginable event?
No. Select credible scenarios that could materially affect critical services or protected interests and document why they matter.
Is an all-hazards assessment a technical exercise?
It combines technical, physical, organisational and supplier knowledge with board-level impact, priorities and decisions.
How often should the analysis be updated?
Review it periodically and whenever material changes, incidents, supplier changes or new information affect the risk picture.
Use all-hazards scenarios in your next board session
The Boardroom Day applies these scenarios to critical services, dependencies, controls and recovery priorities in your organisation.
Discuss the appropriate training route