- Meaning
- The values and resources of an organisation that are worth protecting
- Examples
- Hardware, software, data, cloud services, networks
- Relation to NIS2
- The starting point of every look at risk
- Related
- Asset inventory
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are assets?
The term Assets covers every resource that has value for an organisation and therefore has to be protected: physical devices such as servers, laptops and network components, software and applications, data and databases – but also cloud services, network connections and, not least, intangible values such as trade secrets or reputation. The term therefore describes what is worth protecting; recording those values in a structured way is the job of the asset inventory.
Why assets are central to NIS2
NIS2 requires entities in scope to manage the risks to their own systems and services systematically. That is only possible once it is clear which assets exist at all and how much protection each single one deserves. A forgotten server or an unrecorded cloud application stays invisible to Risk management and is therefore unprotected. Assets are in this sense the starting point in thought for the whole of cybersecurity.
IT and OT assets
Alongside classic IT (the office environment, servers, end-user devices) there are also OT assets – the operational technology that runs machines, plants and infrastructure. In NIS2 sectors such as energy, water, health or manufacturing, OT is especially critical, because an outage hits physical processes directly. OT assets often have long life cycles and cannot be patched at will, which calls for protection concepts of their own.
From assets to security
Assets are recorded in the asset inventory, their risks are assessed and they are protected with the matching Controls always measured against the Security objectives of availability, integrity, confidentiality and authenticity. That is how a plain list of values turns into a level of security you can actually steer.
A typical case: An energy supplier inventories not only its office IT but also rates the remote maintenance connections to its substations as critical OT assets. Because those values are classified as highly worth protecting, they get stricter controls such as segmented networks and MFA – and not the same treatment as an ordinary office printer.
Further reading: BSI IT-Grundschutz, the German baseline security standard
Frequently asked questions
What is an asset in IT security?
In security terms an asset is any resource that has value for an organisation and is therefore worth protecting. That includes physical devices such as servers, laptops and network components, along with software and applications, data and databases, cloud services and network connections. Intangible values such as trade secrets, know-how or reputation count as assets too. The term describes what is worth protecting; recording those values in a structured way is the job of the asset inventory.
Why do assets matter for NIS2?
Assets matter for NIS2 because risks and protective measures can only be determined once you know which values are worth protecting at all. A forgotten server or an unrecorded cloud application stays invisible to risk management – and therefore unprotected. Assets are the starting point in thought for the whole of risk management under NIS2, and to steer them they are recorded systematically in the asset inventory, assessed and given the protective measures that fit.
Does OT count as an asset too?
Yes, OT assets count as well. Operational technology covers the control systems that run machines, plants and infrastructure. In NIS2 sectors such as energy, water, health or manufacturing, OT is especially critical, because an outage hits physical processes directly. OT assets therefore belong alongside classic IT on equal terms, but their long life cycles and limited patchability often call for protection concepts of their own.