NIS2 knowledge base

All hazards and NIS2: cybersecurity is broader than IT

An all-hazards approach examines every relevant cause of disruption, from cyberattack and human error to fire, flooding, power loss and supplier failure. It helps the board focus on impact, continuity and recovery rather than on one threat category.

What an all-hazards approach means

NIS2 requires risk-management measures that fit the organisation's actual exposure. An all-hazards assessment starts with critical services and protected interests and then considers the different events that could affect them. Cyber incidents remain important, while physical, technical, organisational and supply-chain disruptions are assessed within the same coherent picture.

This avoids separate risk lists that compete for attention. A data-centre fire, malicious encryption, a telecom outage and a failed software update may have different causes yet produce similar effects on availability, safety and trust.

Why this matters in the boardroom

Boards allocate resources and accept residual risk. They therefore need to understand the service impact, duration, dependencies and recovery options behind a scenario. An all-hazards view supports proportionate decisions because it compares risks through common business and societal consequences.

The method also reveals shared weaknesses. A single location, supplier, identity platform or key employee may be relevant to several scenarios and deserve priority.

Use scenarios as well as control lists

Control lists help verify coverage, while scenarios reveal whether arrangements work together. A useful scenario describes the trigger, affected processes, immediate decisions, dependencies, expected impact, available controls, recovery target and escalation route.

  • Which critical service is affected and for how long?
  • Which people, systems, locations and suppliers are required for recovery?
  • Which interests are at stake: continuity, safety, finance, reputation or personal data?
  • Which control is preventive, detective, corrective or recovery-focused?
  • Which residual risk requires an explicit board decision?

Connect the risk picture with internal control

The risk analysis becomes useful when each material scenario has an owner, measures, evidence of operation, a recovery objective and a review cycle. Management reporting can then show changes in exposure, overdue actions, test results and decisions instead of presenting a static heat map.

Exercises, supplier reviews and incident lessons keep the analysis current and help the board see whether control effectiveness is improving.

Frequently asked questions

Does all hazards mean every imaginable event?

No. Select credible scenarios that could materially affect critical services or protected interests and document why they matter.

Is an all-hazards assessment a technical exercise?

It combines technical, physical, organisational and supplier knowledge with board-level impact, priorities and decisions.

How often should the analysis be updated?

Review it periodically and whenever material changes, incidents, supplier changes or new information affect the risk picture.

Use all-hazards scenarios in your next board session

The Boardroom Day applies these scenarios to critical services, dependencies, controls and recovery priorities in your organisation.

Discuss the appropriate training route