Glossary · Term

All-hazards approach explained

The all-hazards approach looks beyond cyberattacks in risk management to every relevant danger – from technical failures through human error to physical events.

At a glance
Meaning
A holistic view of all hazards, not just cyber
Link to NIS2
Expressly required by Article 21(2)
Examples
Power cut, fire, human error, service provider failure
Aim
Genuine resilience
Updated
June 2026
Editorial team
Compliance Compass

What is the all-hazards approach?

The All-hazards approach is a fundamental way of thinking in Risk management: instead of concentrating on cyberattacks alone, it systematically takes in every danger that could disrupt critical processes. The approach therefore defines the scope of the risk assessment – it widens the view from IT security alone to the resilience of the whole operation. That is where it lays the foundation on which concrete contingency planning such as Business continuity can meaningfully build.

Which hazards are meant

An all-hazards approach looks at four typical categories of danger, each calling for safeguards of its own:

Why NIS2 requires this approach

Article 21(2) of the NIS2 Directive states expressly that the risk management measures have to be based on an all-hazards approach, aimed at protecting network and information systems and the physical environment of those systems. The directive has applied since 18 October 2024. The thinking behind it: an organisation is only genuinely resilient once it accounts not just for hackers but for every realistic cause of failure. Neglecting the approach risks not only operational outages but fines – Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

From approach to practice

In practice that means looking at every kind of hazard in the risk analysis and covering it with fitting measures (Controls, business continuity), instead of thinking only in firewalls.

An example: a cloud provider hardens its systems against cyberattacks in exemplary fashion – but overlooks the fact that its only data centre depends on a single power supplier and a single cooling plant. When the air conditioning fails, the servers shut themselves down to protect themselves. An all-hazards approach would have spotted that physical risk and covered it with redundancy and a contingency plan, long before the day it mattered.

Further reading: ISO 22301 – holistic business continuity management

Frequently asked questions

What does the all-hazards approach mean?

The all-hazards approach is a way of thinking in risk management that systematically takes in every relevant danger – not only cyberattacks, but also technical failures such as hardware faults and power cuts, human error, physical events such as fire or water damage, and the failure of suppliers and service providers. It widens the view from IT security alone to the resilience of the whole operation and lays the foundation for effective contingency planning. The wording comes straight from Article 21(2) of the directive.

Is the all-hazards approach mandatory under NIS2?

Yes. Article 21(2) of the NIS2 Directive states expressly that the risk management measures of the entities in scope have to be based on an all-hazards approach; the directive has applied since 18 October 2024. Neglecting it risks not only operational outages but fines: Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

Why is cyber protection alone not enough?

Cyber protection on its own falls short, because an organisation is only genuinely resilient once it accounts for every realistic cause of failure. Power cuts, fires, water damage or the failure of a service provider can paralyse critical processes without any hacker being involved. Genuine resilience along the all-hazards approach therefore treats every category of danger alike and covers it with fitting measures such as redundancy, business continuity and contingency plans.

Risk management

All hazards in view

Compliance Compass guides you through a risk analysis that captures not just cyber, but every relevant hazard.