- Meaning
- A holistic view of all hazards, not just cyber
- Link to NIS2
- Expressly required by Article 21(2)
- Examples
- Power cut, fire, human error, service provider failure
- Aim
- Genuine resilience
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is the all-hazards approach?
The All-hazards approach is a fundamental way of thinking in Risk management: instead of concentrating on cyberattacks alone, it systematically takes in every danger that could disrupt critical processes. The approach therefore defines the scope of the risk assessment – it widens the view from IT security alone to the resilience of the whole operation. That is where it lays the foundation on which concrete contingency planning such as Business continuity can meaningfully build.
Which hazards are meant
An all-hazards approach looks at four typical categories of danger, each calling for safeguards of its own:
- Technical: hardware faults, software errors, power cuts.
- Human: operating mistakes, missing knowledge, social engineering.
- Physical: fire, water damage, break-in.
- External: failure of suppliers and service providers (Third-party risk).
Why NIS2 requires this approach
Article 21(2) of the NIS2 Directive states expressly that the risk management measures have to be based on an all-hazards approach, aimed at protecting network and information systems and the physical environment of those systems. The directive has applied since 18 October 2024. The thinking behind it: an organisation is only genuinely resilient once it accounts not just for hackers but for every realistic cause of failure. Neglecting the approach risks not only operational outages but fines – Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
From approach to practice
In practice that means looking at every kind of hazard in the risk analysis and covering it with fitting measures (Controls, business continuity), instead of thinking only in firewalls.
An example: a cloud provider hardens its systems against cyberattacks in exemplary fashion – but overlooks the fact that its only data centre depends on a single power supplier and a single cooling plant. When the air conditioning fails, the servers shut themselves down to protect themselves. An all-hazards approach would have spotted that physical risk and covered it with redundancy and a contingency plan, long before the day it mattered.
Further reading: ISO 22301 – holistic business continuity management
Frequently asked questions
What does the all-hazards approach mean?
The all-hazards approach is a way of thinking in risk management that systematically takes in every relevant danger – not only cyberattacks, but also technical failures such as hardware faults and power cuts, human error, physical events such as fire or water damage, and the failure of suppliers and service providers. It widens the view from IT security alone to the resilience of the whole operation and lays the foundation for effective contingency planning. The wording comes straight from Article 21(2) of the directive.
Is the all-hazards approach mandatory under NIS2?
Yes. Article 21(2) of the NIS2 Directive states expressly that the risk management measures of the entities in scope have to be based on an all-hazards approach; the directive has applied since 18 October 2024. Neglecting it risks not only operational outages but fines: Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
Why is cyber protection alone not enough?
Cyber protection on its own falls short, because an organisation is only genuinely resilient once it accounts for every realistic cause of failure. Power cuts, fires, water damage or the failure of a service provider can paralyse critical processes without any hacker being involved. Genuine resilience along the all-hazards approach therefore treats every category of danger alike and covers it with fitting measures such as redundancy, business continuity and contingency plans.