What happened?
According to reports from Germany's Federal Office for Information Security (BSI), the security situation in German industry remains critical. Whether targeted data theft, sabotage of critical infrastructure, or ransomware attacks – the damage to the economy has long since reached the hundreds of billions of euros, according to the BSI. Industrial environments are particularly affected: sprawling company premises, distributed sites, and the increasing interconnection of information technology (IT) and operational technology (OT) create a large attack surface. At the same time, regulatory pressure is rising due to the implementation of the NIS-2 Directive and the upcoming KRITIS umbrella law, which significantly expand risk management obligations and liability risks for company management.
The Details
The article from Protector Magazin, written by editor Miriam Steinitz, describes a central challenge for security managers in industry: how can an infrastructure be protected in which a single unauthorized opened door can compromise the entire digital network? This question illustrates how closely physical and digital security are now intertwined.
In addition to NIS-2 and the KRITIS umbrella law, industry-specific standards such as ISO/IEC 27001, TISAX, IFS Food, or ATEX also demand comprehensive proof of security measures. This creates a balancing act for architects, specialist planners, and operators: a high degree of regulatory compliance must be achieved without impairing daily production and logistics processes.
The article names modern access control as a solution approach, which is transforming from a mere "gatehouse-and-key system" into an intelligent building block of overall cyber resilience. Cited areas of application include securing the perimeter, protection against espionage in research departments, and complete audit trails for audits. Modern locking and access systems are intended to serve as a link between the physical and digital worlds.
The article leaves the concrete technical implementation open: which system architectures can withstand the dynamic requirements of modern sites, and how seamless integration into existing IT landscapes can be achieved in a flexible, scalable, and future-proof manner, is formulated as a central question. On this point, the article refers to a whitepaper from manufacturer Assa Abloy, which is intended to provide practical insights and checklists for implementation.
Context
The development described in the article shows a fundamental shift in the security understanding of industrial companies: physical access control is no longer viewed in isolation but understood as an integral part of cyber resilience. This interconnection is a direct consequence of the advancing convergence of IT and OT in production environments, which is dissolving the classic boundaries between digital and physical security.
For security managers and specialist planners in access control, this means a changed set of requirements: compliance with NIS-2, the KRITIS umbrella law, and industry-specific standards such as ISO/IEC 27001, TISAX, IFS Food, or ATEX must be systematically factored in going forward when access solutions are planned or modernized. The liability risks for company management described in the article further increase the pressure to implement appropriate measures promptly.
Practical Tips
- Plan access control systems not in isolation, but in the context of the overall IT/OT security architecture.
- Establish audit trails and complete documentation of access events as the basis for compliance obligations toward auditors and regulatory authorities.
- Secure perimeter protection and sensitive areas such as research departments with particular attention to protection against espionage.
- Check early on which system architectures can be flexibly and scalably integrated into existing IT landscapes to avoid later retrofitting.
- Use available practical guides and checklists, such as the whitepaper from Assa Abloy mentioned in the article, for guidance on implementing regulatory requirements.
Outlook
With the entry into force of the KRITIS umbrella law and the ongoing implementation of NIS-2, industrial companies are foreseeably going to face continued mounting pressure to act. The development outlined in the article – the merging of physical access control with cyber resilience strategies – is likely to continue, as hybrid IT/OT structures in industry continue to increase. For operators, architects, and specialist planners, it is therefore becoming increasingly important to design access solutions that are regulatorily and technically future-proof from the outset, rather than making adjustments retroactively.