Europe’s critical infrastructure protection model is changing. Hybrid threats, regulatory pressure and growing dependencies between physical and digital systems are pushing operators beyond conventional perimeter security. The decisive question is no longer whether an individual asset is protected, but whether essential services remain operational when systems, communications or security layers fail.
Europe’s critical infrastructure is becoming more interconnected – and therefore more vulnerable to cascading disruption.
Energy networks depend on telecommunications. Industrial production relies on power, digital control systems and logistics. Data centres require uninterrupted electricity, cooling and connectivity. Transport systems increasingly depend on digital infrastructure, while physical access to operational technology can itself create cyber risk.
At the same time, the threat spectrum has expanded. Sabotage, suspicious drone activity, cyberattacks, communications failures and deliberate interference with supply chains can affect the same organisation simultaneously.
This is changing the logic of infrastructure security.
A well-protected site can still become operationally vulnerable if alarm transmission fails, communications are interrupted or intervention procedures break down. Conversely, strong cybersecurity offers limited protection if attackers can physically access network components, control systems or other sensitive equipment.
The European security debate is therefore moving from asset protection towards operational resilience.
This shift is reflected in the EU’s Critical Entities Resilience Directive, or CER Directive. It requires critical entities to strengthen their ability to prevent, protect against, respond to, resist, mitigate, absorb and recover from incidents that could disrupt essential services.
The implications for security providers are significant. Physical protection, cybersecurity, alarm management and business continuity can no longer be planned as separate disciplines.
Security begins after detection
Traditional physical security has often been organised around individual technologies: perimeter protection, video surveillance, intrusion detection, access control, guarding and alarm transmission.
All remain essential. But their effectiveness increasingly depends on what happens between them.
A camera can identify movement. A sensor can detect manipulation. An access-control system can register an unauthorised entry attempt.
None of these events represents an effective security response in itself.
Operational security begins when information is reliably transmitted, assessed, verified, prioritised and converted into action.
Modern critical infrastructure protection therefore depends on the complete chain:
Detect – Transmit – Assess – Decide – Intervene – Recover.
The resilience of this chain is becoming a more meaningful measure of security performance than the capabilities of any individual component. Security technology, communications infrastructure, control rooms, intervention forces and recovery procedures have to work as one system.
This also changes procurement.
The relevant question is no longer simply which camera offers the highest resolution or which sensor provides the greatest detection range. Operators need to know whether their security architecture will still work when network connections fail, power becomes unstable or several incidents occur at the same time.
CER and NIS2 are closing the organisational gap
European regulation increasingly reflects this systems perspective.
The CER Directive creates a common framework for the physical resilience of entities providing essential services. Its measures extend from risk analysis and physical protection to crisis procedures and recovery capabilities.
In parallel, NIS2 addresses cybersecurity and cyber-risk management across many of the same sectors.
Taken together, both frameworks challenge one of the most persistent weaknesses in critical infrastructure protection: the organisational separation of physical security and cybersecurity.
That separation is becoming increasingly artificial.
A cyberattack can disable physical processes. Physical access can enable a digital compromise. A network outage may affect video transmission, electronic access control and alarm reporting simultaneously. An electricity failure can remove several technical protection layers at once.
Critical infrastructure security must therefore be planned against combined failure and attack scenarios, not isolated threat categories.
For operators, this means that corporate security, IT security, OT security, facility management and business continuity management require much closer coordination.
Germany shows how European requirements become operational
Germany offers a useful example of how the European resilience agenda is being translated into national practice.
The German KRITIS-Dachgesetz entered into force on 17 March 2026 and creates a national framework for the physical resilience of critical facilities.
It strengthens requirements relating to risk assessment, technical and organisational protection measures and the ability to maintain or restore essential functions.
At the same time, implementation is not instantaneous. The identification and registration of affected facilities is linked to further regulatory steps, after which specific operator deadlines will apply.
That distinction matters.
Compliance deadlines may be phased in, but resilience cannot be created on demand. Risk analyses, redundant communications, emergency procedures, intervention concepts and organisational responsibilities often require months or years to establish.
Waiting for the final administrative deadline is therefore not a resilience strategy.
For European operators, Germany illustrates a wider principle: regulation may trigger action, but operational resilience has to precede compliance.
Business continuity becomes a security function
This development also changes how security success is measured. For critical infrastructure, preventing every incident is unrealistic; the decisive question is whether essential services can continue, impacts can be contained and operations can be restored quickly. The CER framework therefore places business continuity at the heart of resilience, shifting security planning from pure incident prevention towards consequence management and recovery capability.
The alarm receiving centre becomes a decision hub
Professional alarm receiving centres play a central role in this model. Beyond receiving intrusion, fire or technical alarms, modern control centres increasingly connect automated detection with human assessment and intervention. DIN EN 50518 sets requirements for physical protection, technical availability, communications, procedures and staffing – particularly relevant for critical infrastructure, where the resilience of the entire alarm chain depends on reliable reception and processing.
A practical example can be found in Wuppertal in western Germany.
Wach- und Schließ-Gesellschaft Elberfeld-Barmen Nachfolger Herkströter GmbH & Co. KG places its AES-Core alarm receiving centre at the centre of its critical infrastructure security model for the Bergisches Land industrial region. According to the company, the facility combines norm-compliant alarm handling with multiple communications and intervention structures.
The broader significance lies not in the existence of another monitoring centre.
It lies in the changing function of the control room.
The modern alarm receiving centre is becoming an operational decision hub where information from technical systems is consolidated, assessed and converted into action.
The critical moment is not when the sensor detects an anomaly. It is when somebody – or an automated process governed by defined rules – decides what happens next.
Redundancy must remove common points of failure
Communications infrastructure is therefore a critical component of physical security.
Alarm transmission frequently depends on terrestrial broadband or mobile networks. Under normal conditions, these systems provide high levels of availability.
Critical infrastructure planning, however, is concerned precisely with abnormal conditions.
Cable damage, power outages, cyber incidents or deliberate sabotage can affect the communications channels on which security systems depend.
Redundancy therefore has to mean more than simply adding a second connection.
Where justified by the risk profile, alternative transmission paths should rely on different underlying infrastructure.
In Wuppertal, the security provider supplements terrestrial communications with a Starlink satellite connection designed to provide an additional communications route.
The strategic value lies in the principle rather than in the individual provider.
True resilience requires technological diversity.
But even an independent communications channel provides limited protection if both systems depend on the same power source, router, network configuration or operating procedure.
Security planners therefore need to identify common points of failure across communications, energy, hardware, software and organisational processes.
Redundancy is not the number of backup systems. It is the absence of shared vulnerabilities.
Mobile surveillance adds an adaptive layer
Resilient security also needs to be flexible.
Critical sites are not static. Construction projects change perimeters. Maintenance work creates temporary access routes. Storage areas move. Threat levels change. Permanent security infrastructure may temporarily be unavailable.
Mobile video and detection systems can provide an additional tactical layer in such situations.
Mobile video towers, for example, are increasingly being used beyond conventional construction-site security. At critical facilities they can reinforce surveillance around temporary access points, construction areas, external storage zones or sections of perimeter undergoing modification.
Their strength lies in rapid deployment.
Yet mobile surveillance only creates security value when it is integrated into the wider response architecture.
A camera producing additional footage does not automatically increase resilience. The decisive factor is whether detection leads to verification, decision-making and intervention.
Flexible technology therefore has to be embedded in fixed processes.
Drones make the perimeter three-dimensional
Unmanned aerial systems are also changing the physical security model.
Traditional perimeter security is largely two-dimensional: fences, gates, walls, vehicle barriers and building envelopes.
Drones introduce a vertical dimension.
They can observe facilities from above, bypass conventional physical barriers and potentially support reconnaissance or other hostile activities.
For selected high-risk environments, this is increasing interest in radar, RF detection, video analytics and sensor fusion.
The longer-term implication is significant.
Perimeter protection is gradually moving away from protecting a boundary line towards maintaining situational awareness across the three-dimensional space surrounding a critical site.
That development will require both new technologies and new concepts of operation. Detecting an unidentified drone is one problem. Determining its relevance, coordinating a response and operating within the applicable legal framework is another.
Local intervention remains strategically important
More technology does not automatically mean more centralisation.
Critical infrastructure is ultimately physical.
Intervention personnel must reach the facility. Access routes matter. Local knowledge matters. Established relationships with operators, emergency services and local authorities can matter considerably during an incident.
Regional providers can therefore retain a strategically important role within increasingly connected security systems.
The Bergisches Land provides an illustrative case. Its industrial structure combines production facilities with energy, transport, communications and supply infrastructure. Security incidents can therefore create consequences beyond the immediately affected location.
The Wuppertal model combines local alarm receiving and intervention structures with technically redundant communications.
This suggests one possible future role for regional security companies across Europe: not as smaller versions of global security platforms, but as regional resilience nodes connecting local intervention capabilities with standardised technologies and wider digital security ecosystems.
The security provider is becoming a resilience partner
The same transformation is reshaping the security market.
Critical infrastructure operators increasingly require integrated capabilities rather than isolated guarding or technology contracts.
They need providers capable of combining security systems, alarm receiving centres, mobile services, intervention processes, risk analysis and business continuity requirements.
This does not eliminate the human security professional.
It changes the function of human expertise.
As automated detection increases, personnel can increasingly focus on areas where judgement provides the greatest value: verification, situation assessment, escalation, intervention and crisis support.
The industry’s transformation is therefore not primarily about replacing people with technology.
It is about placing human decision-making at the points where automation alone is insufficient.
INFOBOX: How resilient is the security architecture?
Critical infrastructure operators should be able to answer the following questions:
Detection: How quickly can a security-relevant event be identified?
Alarm transmission: Will an alert still reach the responsible control centre if the primary communications route fails?
Verification: How quickly and with what quality of information can an event be assessed?
Decision-making: Are responsibilities, escalation routes and decision-making authority clearly defined?
Intervention: Which personnel and technical resources are available, and how quickly can they respond?
Redundancy: Which critical functions have genuinely independent fallback systems?
Business continuity: Which services and processes must remain operational during a major disruption?
Recovery: How quickly can essential functions be restored after an attack or technical failure?
Exercises: Are disruption scenarios regularly tested, and are the results translated into measurable improvements?
Resilience is tested when normality ends
Europe does not primarily need more security technology.
It needs security architectures capable of functioning when technology, communications and organisational structures are under stress.
CER and NIS2 reinforce this shift at regulatory level. Hybrid threats and infrastructure interdependencies make it operationally unavoidable.
The Wuppertal example illustrates how the transition can look in practice: norm-based alarm receiving capability, diversified communications, mobile surveillance and local intervention are integrated into a broader resilience model rather than operated as isolated services.
For Europe’s security industry, this is the central challenge ahead.
The question will no longer be whether an operator owns the right individual technologies.
It will be whether detection, communications, decision-making, intervention and recovery still function when the first layer of protection has already failed.
That is when resilience begins.



