The Ground Segment Is the Soft Target: Physical Resilience in the Age of NIS2 and KRITIS
There is a particular kind of vulnerability that survives every cybersecurity budget cycle, because it never appears in one. It isn't a misconfigured firewall or an unpatched server. It's a bolt.
More precisely: it's the fastener holding shut the cabinet at the base of an antenna, the access panel on a remote ground station, the enclosure housing the navigation equipment beside a runway. These are the points where Europe's space and aviation infrastructure meets the open air — and where the resilience frameworks now in force are quietly asking a question that the sector has been slow to answer.
## Two frameworks, one blind spot
Germany's transposition of NIS2 — the NIS2UmsG, in force since 6 December 2025 — is rightly understood as a cybersecurity law. It expanded the BSI's supervised population to roughly 29,500 entities across eighteen sectors and brought serious teeth: risk-management obligations, incident reporting, direct management responsibility, and penalties reaching €10 million or 2% of global turnover.
But NIS2 has a companion that gets far less attention and matters more to the physical world: the KRITIS-Dachgesetz, Germany's implementation of the EU CER Directive. Where NIS2 secures the bits, the KRITIS-Dachgesetz secures the building. It mandates physical resilience — risk analyses, disruption monitoring, and protection obligations that explicitly extend beyond IT security to the facility itself. The Bundesrat approved it on 6 March 2026; it has applied since 17 March 2026, supervised on the physical side by the federal civil-protection agency (BBK) rather than the BSI, with critical-facility operators due to register by mid-2026 and detailed thresholds still set to follow in a separate regulation.
The enforcement split is worth noting, because it signals how seriously the physical layer is now taken: a purely physical breach can draw a fine up to €500,000 on its own, and where the same failure also breaches NIS2, the ceiling rises to the full €10 million or 2% of turnover.
The blind spot lives in the gap between the two laws. A great deal of compliance energy goes into the cyber layer, because that's where the directive language is densest and the audit trail is clearest. The physical layer — the actual tamper-resistance of the equipment in the field — tends to be assumed rather than demonstrated. And in space and aviation, the physical layer is unusually exposed.
## Why the ground segment, specifically
A satellite is one of the best-protected objects humanity builds. It is also, for an attacker, almost entirely out of reach. The economically rational target was never the spacecraft — it's the ground segment: the teleports, antennas, modems, and cabinets that make the orbital asset useful. The point is reinforced by the regulatory design itself: space is named not only as a high-criticality sector under NIS2 but also among the sectors covered by the CER Directive behind the KRITIS-Dachgesetz — so the ground segment now sits inside a *physical* resilience mandate, not only a cyber one. Industry and research voices from the digital-infrastructure and aerospace communities have made the same observation: while satellites are treated as critical infrastructure, only a fraction of their ground stations have historically been regulated as such.
Aviation has the same shape at far greater scale. Air-traffic infrastructure is distributed across navigation aids, surveillance and communication equipment, and field cabinets spread along approach paths and across remote sites — each one a small, accessible, bolted enclosure standing somewhere a person can walk up to. The legislators are moving on this in parallel: the same Bundesrat session that approved the KRITIS-Dachgesetz also approved amendments to the Aviation Security Act covering drone defence and airport security.
These installations share three uncomfortable properties:
- **They are unmanned and remote.** No reception desk, no guard, often no continuous human presence — just a locked cabinet and a hope that the lock is enough.
- **They are assembled with standard hardware.** The same hex and socket-head bolts used across the whole industrial world, openable with a tool anyone can buy.
- **They are economically and operationally attractive.** Copper and component theft from infrastructure cabinets is already a documented, recurring problem across European utilities and telecoms — and a single tampered enclosure can degrade a service the regulator has classified as essential.
## What "physical resilience" actually demands
The resilience mandate doesn't prescribe a specific lock or fastener. What it demands is that an operator can show a structured, defensible account of how a critical service can be degraded — and what has been done about each path. The physical-access path is one of those paths. Under the older, cyber-centric reading of critical-infrastructure rules, an operator could plausibly leave it implicit. Under the KRITIS-Dachgesetz's explicit physical-resilience obligations, that's a harder position to hold.
This is where the conversation gets concrete. Securing the ground segment physically isn't exotic; it's a layered, unglamorous discipline:
- **Designed-out access**, so that opening an enclosure requires more than a commodity tool from a hardware store.
- **Tamper evidence**, so that an interference attempt leaves a trace an inspection or monitoring regime can pick up — feeding directly into the disruption-monitoring obligation the law now imposes.
- **Standardisation across the estate**, so that thousands of distributed cabinets carry a consistent, auditable level of protection rather than a patchwork an assessor can't reason about.
None of this replaces cybersecurity. It sits underneath it — the layer that determines whether the carefully secured electronics inside the box can simply be reached, removed, or interfered with by someone standing in front of it.
## The takeaway for operators
The organisations that will come through the next round of resilience assessments most comfortably are the ones that stop treating physical and cyber security as separate budgets answering to separate directives. NIS2 and the KRITIS-Dachgesetz were written to be read together precisely because a critical service fails the same way whether the breach came down a network cable or through an unscrewed panel.
For space and aviation, where the most valuable assets are in orbit or in the air but the most accessible ones are bolted to the ground, that's not a compliance footnote. It's the part of the threat model that's been hiding in plain sight — at the end of an Allen key.
---
*This article reflects the German regulatory landscape as of mid-2026: the NIS2UmsG (in force 6 December 2025) and the KRITIS-Dachgesetz implementing the EU CER Directive (in force 17 March 2026). Specific scope thresholds under the forthcoming implementing regulation remain pending; operators should verify their classification and obligations against current BSI and BBK guidance.*