When worlds converge

When worlds converge

Physical-cyber convergence under NIS2 and EU security policy

Physical-cyber convergence is a critical topic of discussion for many businesses. As of May 2026, 21% of companies are believed to face cyberattacks against Operational Technology (OT) infrastructure annually, 40% of which lead to business disruptions.

In Europe, digital assets now account for around 80% of cumulative business investments, signalling the importance of digital infrastructure to organisational goals. To safeguard both digital and physical assets, convergence between IT and OT infrastructure is a major priority.

For many kinds of businesses, convergence is now a mandated undertaking, with legislation like NIS2 expanding mandatory cybersecurity obligations to over 160,000 entities. With this in mind, the post below explores physical-cyber convergence under NIS2 and EU security policy.

The importance of physical-cyber convergence

In recent years, security convergence has emerged as a top priority for modern organisations.

Increasingly, threats posed against modern businesses cross between the physical and digital realms, exploiting blind spots in traditional security operations. In the past, organisations have approached cyber and physical security as independent undertakings, with minimal knowledge shared between siloed teams; malicious actors have used these gaps to wage serious attacks.

By pursuing convergence between OT and IT systems and breaking down organisational silos, entities can significantly improve key cross-practice threat detection and response capabilities.

Whether mandated or not, the benefits of physical-cyber convergence include:

  • Cross-practice threat mitigation: Knowledge and skill sharing between OT and IT security teams helps to flag anomalous events across both domains more effectively.

  • Streamlined response capabilities: By eliminating blind spots, OT and IT teams can enact responsive protocols across both practices swiftly to combat threats in real time.

  • Improved operational efficiency: Convergence can streamline access management across physical and digital environments to raise business-wide operational efficiency.

  • Cost and resource optimisation: Increased visibility into OT and IT infrastructure can help leaders to identify redundancies and duplicate efforts straining limited resources.

Core requirements of physical-cyber convergence under NIS2

The NIS2 Cybersecurity Directive is an expansion of the EU’s previous NIS1 framework that now mandates entities across 22 major sectors to pursue security convergence. Under NIS1, a formal designation from national authorities was required before entities were mandated to comply; under NIS2, entities operating in a listed sector are automatically required to comply.

NIS2 listed sectors include:

  • Highly critical sectors: Energy, transport, banking, financial services, health, water, digital infrastructure, ICT service management and public administration.

  • Critical sectors: Postal and courier services, waste management, chemicals, food, manufacturing, digital service providers and research.

Under NIS2, relevant entities are legally required to safeguard physical infrastructure against cyber threats. The directive employs an all-hazards approach to physical and cybersecurity, meaning all physical security systems like access control and CCTV solutions are treated as network-connected assets and, as such, face the same risk scrutiny as traditional IT solutions.

To maintain compliance with NIS2, entities must ensure convergence in the following areas:

  • Access control: Entities must mandate authenticated physical access to high-risk areas like server rooms and establish integrated physical and digital access systems.

  • Hardware security: Physical hardware like cameras and sensors must be secured against unauthorized access and tampering to minimise risks of failure and data loss.

  • Incident response: Workflows must be integrated across both OT and IT teams, with hardware, software and principles from both practices used to inform responses.

  • Supply chain security: All third-party providers of physical security equipment must undergo risk assessments; all vulnerabilities will be classed as network security risks.

NIS2 and aligned legislation are guiding security optimisation

NIS2 is just one element of wider efforts by EU officials to help modern organisations protect themselves against sophisticated threats. In alignment with NIS2, legislation like the Critical Entities Resilience (CER) Directive, the Digital Operational Resilience Act (DORA) and the Cyber Resilience Act (CRA) combine to help entities strengthen defences and optimise workflows.

As the threat landscape continues to evolve, with attackers leveraging intelligent solutions to bypass protections and expose new vulnerabilities, the importance of convergence will likely grow. To help organisations stay ahead of threats and mindful of security gaps, maintaining compliance with NIS2 and wider EU security policy is a critical and widely beneficial pursuit.

Will MacDonald

Will MacDonald is the Director of Product Management for the Avigilon Alta Video product line at Motorola Solutions, where he oversees the development and strategy of cutting-edge cloud-based video surveillance technologies. Building on his extensive experience as a technology leader, Will plays a key role in driving innovation, scalability and security within the video surveillance industry. With a strong background in SaaS, unified communications and cloud infrastructure, he ensures the delivery of impactful solutions tailored to the evolving needs of enterprise and public safety customers worldwide.