What happened?
TKH Security has aligned its solution portfolio in the areas of access control, video management, and incident response with the increased requirements of the EU NIS2 Directive. The goal is to help companies and critical facilities view cybersecurity and physical security as a unified whole and implement them accordingly. Carsten Keite, Managing Director of TKH Security GmbH, emphasizes that unauthorized physical access can undermine digital protection mechanisms – a key reason why NIS2 places greater focus on the physical security of IT infrastructure as well.
The Details
NIS2 follows a risk-based approach that encompasses technical, operational, and organizational measures. Topics such as access control, incident handling, business continuity, and multi-factor authentication directly touch on aspects of physical security. After all, servers, network components, and data lines are located at real physical sites and must be protected there.
The access control solution Iprotect plays a central role in this regard: it enables the assignment of role-based permissions as well as traceable documentation of access events. Depending on the individual risk analysis, additional mechanisms such as anti-passback, two-person authorization, or multi-factor authentication can be deployed to provide extra protection for particularly sensitive areas.
This is complemented by integration with the VDG Sense video management system. This connection makes it possible to link access events with image and video data, better trace processes, and detect potential manipulation. This creates a more comprehensive situational overview for IT managers as well as corporate security teams to assess security-relevant events.
The response to security incidents is also supported by predefined processes: alerts can be linked to specific action recommendations, live footage enables rapid situational assessment, and intelligent search functions facilitate forensic analysis afterward. Logged operator actions further ensure transparency and traceability.
Another important component is business continuity. TKH Security relies on failover concepts, edge recording, and autonomous access functions to ensure that monitoring and controlled access remain in place even in the event of network or server failures.
Context
TKH Security's statements illustrate a shift in perspective that is becoming increasingly relevant for the security industry: NIS2 cannot be fulfilled through software updates or firewalls alone. Physical security measures – from the door to the server room – are becoming an integral part of cyber resilience. For operators of critical infrastructure, this means that access control systems can no longer be considered separately from the IT security strategy.
Carsten Keite highlights a crucial point: NIS2 compliance does not result from individual systems, but from the interplay of technical, operational, and organizational measures based on an individual risk analysis. This statement makes clear that there is no one-size-fits-all "off-the-shelf" solution – every company must assess its specific risks and define protective measures accordingly.
Practical Tips
- Physical security measures and IT security strategy should not be planned separately, but as part of a holistic security concept.
- An individual risk analysis is the foundation for deciding which additional protective mechanisms – such as anti-passback, two-person authorization, or multi-factor authentication – are required for sensitive areas like server rooms.
- Linking access control and video management can help better trace security-relevant events and detect attempted manipulation at an early stage.
- Defined response processes with clear action recommendations in the event of an alarm facilitate a swift and coordinated response to security incidents.
- Failover concepts and autonomous access functions should be planned for to ensure business continuity even in the event of network or server failures.
Outlook
As implementation of NIS2 progresses, the trend toward more closely integrating physical security solutions with IT security concepts is likely to intensify. Carsten Keite sees the directive as an opportunity to more strongly connect IT and corporate security and to make the protection of critical infrastructure more holistic. For operators and security managers, this means that investments in access control, video management, and incident response processes must in future be regarded not merely as traditional security measures, but as an integral part of their compliance strategy.