Discussions around the UK’s Cyber Security and Resilience Bill (CSRB) and the EU Network Information Security Directive (NIS2) directive often fixates on software patches and threat detection, but a critical part of both regulatory requirements is often overlooked. What about the physical resilience of the underlying IT infrastructure?
Both legislations require organisations to maintain continuous service delivery through robust hardware management and rigorous maintenance of legacy assets. For sectors designated as essential services under the CSRB, including energy, transport, health, and defence, the integrity of the server room, cooling systems, and decades-old mainframes is just as much a compliance requirement as any encryption standard.
Recent incidents in the United Kingdom illustrate the consequences of neglecting this dimension. In early 2026, a major disruption to a regional rail network stemmed not from a cyber intrusion, but from the catastrophic failure of an ageing control system server running beyond its lifecycle without adequate redundancy. The Rail Delivery Group noted that heavy investment in perimeter firewalls was rendered ineffective by a “single point of failure” within the physical estate. Similarly, National Audit Office reports on NHS supply chain vulnerabilities highlighted that reliance on unpatched, end-of-life hardware for patient scheduling created bottlenecks preventing rapid recovery. These events show that regulators increasingly view hardware decay and lack of maintenance as direct violations of business continuity obligations.
The draft guidance for the Cyber Security and Resilience Bill makes this expectation explicit. It states that “designated entities must ensure the resilience of their digital infrastructure, including the capacity to maintain critical functions despite component failure.” This moves the focus from purely defensive postures to proactive stewardship of the entire technology lifecycle. It acknowledges that a system cannot be secure if it is unstable, and that instability often stems from the physical deterioration of servers and switches kept running because migration was deemed too risky. The Bill mandates a strategy for the continued operation of legacy hardware through expert maintenance or secure encapsulation, rather than relying on a “rip and replace” timeline that leaves gaps in coverage. We’ve written a lot about this, particularly with the NHS frequently being in the news regarding this topic.
This aligns with the EU NIS2 Directive, which emphasises “risk management measures” covering the physical environment. Availability is defined as ensuring authorised users have access when required. For many providers, availability is threatened by the gradual wear and tear of components manufactured fifteen years ago. When a power supply fails in a legacy DEC or OpenVMS system (more to be shared about this system soon!) holding critical data, the impact is immediate. If there is no plan to repair or replace that component quickly, the organisation fails the availability test set by regulators. The CSRB demands that such risks be mitigated through regular audits of the physical estate, ensuring spare parts are available and maintenance schedules are followed with the same rigour as cybersecurity protocols.
For businesses in these sectors, the message is clear: compliance cannot be achieved by buying the latest antivirus software alone. You must prove your physical infrastructure can withstand stress over extended periods. This involves maintaining legacy systems with professional expertise, ensuring cooling, power, and connectivity remain stable as components age. It means recognising that a server room where dust goes unchecked or obsolete drives run until failure is a compliance risk itself.
Compliance lies in balancing modern security overlays with dedicated infrastructure maintenance. Organisations must invest in keeping existing hardware reliable, preventing the degradation that leads to outages. By focusing on physical resilience—ensuring every piece of equipment, from new AI accelerators to old transactional mainframes, is maintained to the highest standards—they meet the stringent continuity requirements of the CSRB and NIS2. Where the cost of downtime is measured in public safety, the most effective resilience strategy ensures the lights stay on and data remains accessible, regardless of the machine’s age.
References:
- Draft Guidance for the UK Cyber Security and Resilience Bill (2026), sections on “Availability” and “Infrastructure Resilience”.
- National Audit Office Report on “NHS Digital Supply Chain Vulnerabilities” (Early 2026).
- Rail Delivery Group Incident Review on Control System Failures (February 2026).
- EU NIS2 Directive Text: Articles on Risk Management Measures and Physical Security.
- Department for Science, Innovation and Technology statement on “Critical Infrastructure Availability” (June 2026).







