When every second counts

September 18, 2026

Why communication is becoming a key resource for resilient infrastructure

The new European CER guidelines are changing the way we view critical infrastructure. Resilience no longer simply means protecting buildings, networks and technical facilities against failures. Rather, what is crucial is whether essential services continue to function even under exceptional circumstances. This brings to the fore a factor that is often overshadowed by sensor technology, cybersecurity and redundancy in security concepts: communication between people.

When critical infrastructure faces a crisis, it does not necessarily mean that all technical systems will fail. Sometimes it is enough simply for information to no longer reach its recipients in time, for responsibilities to be unclear, or for different agencies to lack a shared operational picture. In such cases, even existing redundancies and sophisticated security systems can lose their effectiveness. This connection takes on new significance in the light of the European Commission’s guidelines on the application of Article 13(5) of the CER Directive, published in July 2026. Under reference number C/2026/3712, the Commission sets out specific technical, security-related and organisational measures that critical infrastructure operators can use to enhance their resilience. Whilst the guidelines are not legally binding, they clearly illustrate the understanding of resilience that is gaining ground at European level. The focus is no longer solely on how an individual facility can be protected. Rather, the decisive factor is whether the essential service provided by a critical infrastructure facility remains available despite a disruption, or can be restored as quickly as possible. The focus is thus shifting from the protection of individual assets to the operational capability of entire organisations and their interdependencies.

From protecting infrastructure to safeguarding services

Traditional security concepts often follow a comparatively clear logic: buildings are protected against unauthorised intrusion, data centres are fitted with redundant power supplies, networks are segmented, and facilities are secured through video surveillance, fire alarm systems and access control. All these measures remain necessary. However, the CER approach broadens the perspective and considers resilience in the face of a wide spectrum of natural and man-made hazards – ranging from extreme weather and technical failures to sabotage, cyber-attacks or other events caused either intentionally or unintentionally.
The benchmark is therefore no longer the protection of the individual facility alone, but the organisation’s ability to maintain its essential services. This also changes the role of security technology. A generator is only part of a resilient system if it is clear when it is needed, who is responsible for its operation and which processes are triggered in the event of a fault. A camera provides an image, but does not in itself trigger a coordinated response. An access control system can lock down an area, but does not decide which individuals must enter it in an exceptional situation. The more resilience is understood as the capability of an entire organisation, the more important the connections between individual systems become – and these do not consist solely of data lines.

Communication becomes part of the security architecture

What is noteworthy about the CER guidelines is not so much a single chapter on communication as the multitude of points where the exchange of information is a prerequisite for the functioning of other resilience measures. For responding to security incidents, the guidelines emphasise, amongst other things, clear decision-making hierarchies, defined roles, cooperation with public authorities and private actors, and structured crisis communication processes.

The guideline becomes particularly specific where it calls for crisis communication protocols designed to enable the timely and accurate dissemination of information to internal and external parties. These include, amongst other things, predefined communication procedures, multi-channel communication capabilities and redundant systems. Different target audiences, multiple languages and accessibility requirements should also be taken into account. Furthermore, the Commission recommends multi-channel warning systems, clear communication chains and designated spokespersons for emergency situations. Communication thus becomes an infrastructural link between technical detection, human assessment and operational response.
At first glance, this sounds self-evident. However, in highly automated security architectures, this is becoming less and less the case. Whilst substantial investment is being channelled into sensor technology, video analysis, AI-supported detection and Security Operations Centres, it is often assumed that the correct response will automatically follow from technical information. This is precisely where a key vulnerability in modern resilience concepts lies.

The greater risk is often a loss of situational awareness

Modern security control centres do not usually suffer from a lack of information. Quite the opposite is true. CCTV systems generate images and metadata, burglar alarm systems provide status updates, access control systems document movements, fire alarm systems trigger alarms, building management systems report technical anomalies, and cybersecurity platforms monitor networks and endpoints. The real challenge increasingly lies in quickly deriving a reliable situational picture from these signals.
An alarm on its own does not answer any of the crucial questions: What has actually happened? Which areas are affected? Who is there? Which services might be disrupted? Is an evacuation necessary? Which emergency services are already en route, and what decisions have been made? Resilience therefore does not arise solely from the ability to detect events. It arises from the ability to interpret information, pass it on and translate it into coordinated action.
This is where the difference lies between data and situational awareness. A camera can show that smoke is developing, a sensor can report a rise in temperature, and an analysis programme can correlate several events with one another. However, it is only through coordination between the control centre, operational staff, the fire service, security personnel and other responsible parties that a shared operational understanding is created. Communication is therefore not merely an appendage to a security architecture. It is the mechanism through which individual technical systems are transformed into a fully functional integrated system.

Why speech remains particularly relevant in a crisis

Digitalisation has significantly expanded the range of possible communication channels. Apps, messaging services, dashboards, automated workflows, mobile alerting and digital control centre solutions are now standard features of modern security and building services technology. Nevertheless, voice communication retains a special status in time-critical situations because it is immediate and allows for dialogue.
In a confusing situation, queries can be made, misunderstandings clarified immediately and priorities adjusted. Urgency, uncertainty or escalation can be conveyed instantly, whilst the recipient can simultaneously confirm that information has been received and understood. This is precisely what distinguishes voice communication from many one-way forms of alerting. A text message can convey an instruction, a display can show an alarm, and an app can trigger an evacuation request. However, in the event of complex or unexpected incidents, there is often a need for additional information. This is when communication becomes interactive.

For operators of critical facilities, this does not mean that traditional intercom, telephone, voice alarm or public address systems are suddenly more important than all other technologies. However, their role within an overarching resilience concept should certainly be reassessed. What matters is not merely whether a communication system functions during normal operation, but whether it remains available even when network connections are disrupted, individual sites are isolated or other communication channels are overloaded.

Redundancy also applies to communication

It is precisely this that gives rise to one of the most important practical consequences of the European approach to resilience. Anyone who provides for redundancy in power supply, servers, networks or control centres should not exclude communication from this. Crisis communication that relies exclusively on a single IP network, a cloud platform or a mobile network operator can itself become a single point of failure.
Resilient communication therefore requires different transmission routes, clear escalation procedures and, where necessary, the ability to continue working even when parts of the digital infrastructure have failed. Depending on the organisation, this can take various forms: local voice communication in addition to central platforms, independent alerting channels, emergency call points, alternative network connections or systems that maintain basic functions locally in the event of the loss of a higher-level connection.
This shifts the criteria for evaluating technical communication systems. In future, it is likely to be decisive not only which functions a system offers during normal operation, but also how it behaves when other systems fail and whether alternative communication channels are actually available.

Cybersecurity alone is not enough

The CER perspective also corrects a misconception that has increasingly crept in over recent years: resilience and cybersecurity are not the same thing. Cybersecurity remains indispensable for modern critical infrastructure. However, an organisation may be extremely well protected against certain cyberattacks yet still be ill-prepared for a prolonged power cut, flooding, a physical attack or the loss of key staff.
Conversely, effective emergency response arrangements, alternative operating procedures and redundant communication channels can help to limit the consequences of a cyberattack. The CER Directive and its accompanying guidelines therefore take a more integrated approach to technological, organisational and physical security. A link to the NIS2 Regulation is explicitly provided for, but the objectives differ: NIS2 focuses on the security of network and information systems, whilst CER takes a broader approach, targeting the resilience of critical facilities and the maintenance of essential services.
For operators, this has a clear implication: security disciplines that have long been treated separately at an organisational level can increasingly no longer be planned independently of one another.

Human decision-making remains part of resilience

It is particularly interesting in this context that the CER guidelines also explicitly take human intervention into account. For certain automated and AI-supported systems, the guidelines address, amongst other things, the ability to operate manually in the event of a failure or tampering. At the same time, clearly defined responsibilities, crisis teams, training, escalation processes and drills play a central role.
This does not contradict automation, but rather describes its limitations. Automated systems can detect recurring events more quickly and trigger predefined responses. In exceptional situations, however, the likelihood increases that precisely those conditions will arise which were not fully anticipated when the system was designed. In such cases, resilience requires human judgement.
The more technical systems are interconnected and processes automated, the more important it becomes to consider how people can continue to intervene, exchange information and adjust decisions in exceptional situations. Technology can accelerate and support human action, but it cannot completely replace it in complex crisis situations.

Good resilience is often unspectacular

The most effective resilience measures are hardly noticeable in everyday life. An emergency call is answered immediately, a report reaches the correct control centre, those in charge know their powers, emergency services receive clear information, staff understand an announcement, and a control centre can communicate with a remote location. If a primary communication channel fails, an alternative channel is available.
From a technological perspective, such requirements seem less spectacular than AI-based video analysis or autonomous security systems. Operationally, however, they can be more crucial. This is because resilience is not measured by how many security systems have been installed, but by how well an organisation functions when its normal operations are no longer available.
This is precisely why security planning is changing. Communication systems should not be regarded merely as an afterthought at the end of a project – as a supplement to video surveillance, access control or risk management – but should be incorporated into the risk analysis from the outset. Planners must ask who needs to communicate with whom in the event of a specific incident, what information is required, how quickly it must be transmitted, and which systems will remain available for this purpose even if individual pieces of infrastructure fail.

Intercom as part of a networked resilience architecture

Modern intercom solutions exemplify how these requirements can be translated into the technical security architecture. They are increasingly integrating voice communication with access control, video, control centre and building management systems, and can thus go far beyond the function of a traditional intercom system. Emergency call points, access points, control centres and decentralised locations can be networked with one another, whilst the integration of video or hazard management systems can provide additional information on the event in question.

For resilient infrastructure, integration alone is not the decisive factor. What matters is whether communication remains clear, immediate and reliably available even under difficult conditions. High speech intelligibility in noisy environments, robust end devices, prioritised emergency calls, defined call routing paths and local functions in the event of faults can help to maintain communication even under exceptional conditions. Intercom
technology can thus form an important interface between automated incident detection and human decision-making, particularly when additional information, queries or immediate support are required.

In the context of the CER requirements, the significance of such systems therefore lies less in an individual product function than in their role within a multi-channel and redundancy strategy. The more closely intercom, public address, video, access control and control centre platforms are integrated with one another, the more important the cyber resilience of the communication systems themselves and clearly defined fallback scenarios become.

Resilience remains a human capability

The European guidelines do not require critical infrastructure operators to use specific voice communication or intercom systems. Such an interpretation would be too broad. However, they highlight something more fundamental: resilience does not arise solely from technical systems continuing to operate under stress. It arises from an organisation’s ability to continue to observe, assess, decide and act.

For this to happen, people must remain reachable, information must be passed on reliably, responsibilities must be clear, and authorities, operators and emergency services must be able to coordinate with one another. Alerts must not only be sent out, but also understood. This is precisely where the strategic importance of communication lies – an aspect that has often been underestimated in traditional security architectures.

The paradoxical reality is therefore this: the more digital, automated and intelligent critical infrastructure becomes, the more valuable the ability for immediate human communication becomes. For ultimately, it is not solely a question of whether a technical system detects an incident. What matters is whether this detection leads to timely, coordinated action.

The defining characteristic of resilient infrastructure is therefore not solely demonstrated by how long technical systems can withstand a failure. It is equally demonstrated by whether operators, security forces and emergency services can establish a shared situational picture, coordinate decisions and communicate reliably with one another, even under exceptional conditions.

Sources
European Commission: Guidelines on the application of Article 13(5) of Directive (EU) 2022/2557 on the resilience of critical infrastructure, C/2026/3712, published on 13 July 2026:
eur-lex.europa.eu/legalcontent/DE/TXT/?uri=CELEX:52026XC03712
OpenKRITIS: CER Guidelines for Resilience: C/2026/3712 – Overview and classification of the CER guidelines.:
www.openkritis.de/massnahmen/cer-guidelines.html

Related Articles

AI boom: Data centres are becoming a security issue

AI boom: Data centres are becoming a security issue

The rapid expansion of AI infrastructure is driving investment in data centres to record levels. At the same time, power density, technical complexity and reliance on energy, cooling and communications systems are all increasing. This is also fundamentally altering...

Rail transport infrastructure: Platform barriers?

Rail transport infrastructure: Platform barriers?

From ticket gates to security architecture: what Germany can learn from other countries Will access to the platform soon be restricted to holders of a valid ticket only? The idea of platform barriers is back in Germany. Yet even a brief international comparison shows...

Thinking Ahead on Security: Detect Earlier, Act Faster

Security Autumn 2026 showcases an industry in transition. Cameras are becoming smarter, sensors more sensitive, access rights more digital and control centres more powerful. Yet perhaps the most important development is not taking place within individual products. It...

Share This