NIS2 asks hospitals to prove it. Most of the estate cannot be instrumented.
Back to top
September 6, 2027
NIS2 asks hospitals to prove it. Most of the estate cannot be instrumented.
Hospitals are essential entities under NIS2, regulated at the highest tier. The measures the directive asks them to evidence sit on an estate that will not accept an end point agent.
Under NIS2, hospitals are classified as essential entities. That is the highest tier the directive has, and it comes with proactive supervision, fines up to 10 million euro or 2% of global turnover, and personal accountability for the management body under Article 20. Boards must actively oversee and approve security measures—passive governance is not a defence.
Most healthcare security leaders already know this. What is less discussed is the specific bind NIS2 creates for a hospital, which is different from the obligation it creates for a bank or a utility company.
A bank can put an endpoint agent on nearly everything it owns. A hospital cannot. And NIS2 does not grade on that curve.
The numbers describe an environment built for patient care, not for instrumentation. In a HIMSS survey published in March 2026, 62% of health systems said the inability to protect unpatchable or agentless devices was a critical or significant limitation, and 56% cited poor visibility into their own device inventory. Three quarters said it was highly important that any security solution avoid clinical disruption entirely. Forty percent said fear of workflow disruption was actively blocking segmentation projects they knew they needed.
That is the estate: infusion pumps, imaging systems, patient monitors, lab analysers, and building systems that cannot take an agent, cannot be patched on your schedule, and cannot be taken offline for a maintenance window because someone is on the table. Hospitals often run these unmanaged or legacy medical devices with known security flaws and outdated firmware, while many healthcare networks still run legacy protocols that expose systems to unauthorized access and lateral movement.
Meanwhile the threat picture has not softened. ENISA’s health sector threat landscape puts ransomware at 54% of incidents, with healthcare providers absorbing the majority of them and hospitals specifically accounting for the largest single share. Roughly a fifth of incidents disrupted patient care directly. Only about a quarter of surveyed health organisations had a dedicated ransomware defence programme.
So the sector with the least instrumentable estate is the sector under the most pressure, now regulated at the highest tier.
Read Article 21 with a hospital estate in mind and three paragraphs stand out, not because they are the hardest to write a policy for, but because they are the hardest to evidence.
Article 21(2)(i) requires real-time asset management. The directive mandates an accurate, real-time asset inventory rather than a static list. Hospital asset tracking must encompass biomedical devices brought through clinical procurement, vendor laptops connected inside imaging suites, and unassigned machine identities. A configuration management database (CMDB) represents a static snapshot, whereas real-time asset locations shift whenever staff move equipment between medical wards.
Article 21(2)(f) requires organisations to assess security measure effectiveness. Compliance verification presents challenges for IT teams. A security policy can specify segmentation rules that isolate the imaging VLAN. However, confirming actual network isolation requires security teams to monitor active network traffic and verify whether unauthorised data transfers complete successfully.
Article 21(2)(d) requires supply chain security covering direct suppliers and service providers. Hospitals rely heavily on remote vendor access for equipment maintenance, electronic health record (EHR) support, and outsourced radiology analysis. A signed supplier questionnaire confirms written policy commitments, but paperwork cannot identify active remote connections or track specific vendor actions during live sessions.
Article 23 imposes strict incident reporting timelines. Organisations must submit an initial warning to their Computer Security Incident Response Team (CSIRT) within 24 hours of detecting a significant incident, submit an updated assessment within 72 hours, and deliver a final root-cause report within one month. Security teams have limited time during a 24-hour window to confirm whether radiology ransomware compromised electronic patient records. Inaccurate reporting carries major operational risks: under-reporting breaches regulatory requirements, while over-reporting drains security resources and triggers unnecessary legal obligations.
These four regulatory requirements demand proof based on observed network behaviour rather than target configuration states. This distinction highlights an evidence gap rather than a documentation deficiency.
How ExtraHop helps
If most of your estate cannot host an agent, there is one place left that sees everything anyway. Every device that matters to patient care communicates, and communication is observable without touching the device.
It is agentless and fully out of band. ExtraHop RevealX analyses a mirrored copy of traffic from a SPAN or TAP. It never sits inline, adds no latency, and cannot disrupt a clinical workflow. RevealX runs outside inline traffic paths, adds zero network latency, and prevents clinical workflow disruptions. This out-of-band architecture satisfies the core requirement for the 76% of health systems demanding zero impact on patient care.
It builds a continuous asset inventory for NIS2 compliance. The system discovers and classifies every communicating device continuously, including unmanaged and unpatchable equipment. RevealX maps active communications across all assets, generating Article 21(2)(i) compliance evidence automatically through ongoing network monitoring rather than annual audit cycles.
It reads encrypted east-west traffic. Lateral movement inside a hospital network hides in the same protocols clinical systems use every day. RevealX decrypts and analyses that traffic at line rate rather than inferring from the outside, which is where credential abuse, privilege escalation, and ransomware staging become visible before encryption starts. ExtraHop also decodes critical healthcare protocols—including HL7 v2 for system integration, DICOM for imaging, and FHIR for modern standards—providing deep visibility into the essential data streams that power patient care.
It shows intended state against observed state. When the segmentation policy says the imaging network is isolated and flows completed anyway, that shows up. This is the most direct answer to Article 21(2)(f) available, and it is equally useful the day a cyber insurer asks for proof of segmentation, which 28% of health systems have already been asked for.
It makes third-party access visible as it happens. Vendor remote sessions, maintenance tunnels, and outbound dependencies appear as observed connections with the transactions attached, which turns Article 21(2)(d) from a paperwork exercise into something you can actually supervise.
It attaches evidence to every detection. Structured transaction records across more than 90 protocols and full packet capture sit one click from the detection, and retrospective detection re-checks past traffic when a new indicator emerges. This is what makes a 24-hour significance call something other than a guess, and what makes the one-month root cause report an evidence chain rather than a narrative.
How is this approach different?
- Reading the traffic rather than inferring from it. Some NDR vendors position explicitly against decryption and rely on behavioural inference alone. Behavioural analysis matters and RevealX does it, but in an environment where an attacker moves through encrypted clinical protocols, inference gives you a suspicion and decryption gives you the transaction.
- Detection that can stay inside the hospital. Behavioural machine learning runs on-prem without a separate dedicated appliance. For health systems facing patient-data residency constraints, or running sovereign or partially isolated environments, that removes the choice between modern detection and keeping patient-adjacent data in the building.
- One view for the SOC and the NOC. The same platform that surfaces the intrusion surfaces the failing link, the latency spike, and the imaging system that stopped responding. In a hospital, availability is a patient safety issue, and NIS2 treats continuity as a security measure under Article 21(2)(c). Two teams reasoning over one real-time view is materially different from two teams reconciling two tools during an incident.
No single platform alone makes a hospital NIS2 compliant. The obligations apply directly to the entity and are judged under each member state’s transposing legislation. Also, much of Article 21 addresses organisational requirements—such as staff training, HR security, backup testing, supplier contracting, and board governance—none of which can be solved purely at the network level.
The defensible argument is more targeted as several critical measures mandated by NIS2 cannot be demonstrated without observable network evidence. In healthcare specifically, the network is the sole place that evidence can be gathered because the estate will not accept anything else.
NIS2 asks hospitals to prove it. Start with the one source of truth that covers the devices you cannot touch.

Senior Product Marketing Manager
Alexis Robbins is a Principal Product Marketing Manager at ExtraHop with 20+ years of experience launching high-growth cybersecurity and digital investigation technologies. Alexis Robbins previously directed global go-to-market strategies for enterprise SaaS security firms and currently specializes in positioning Network Detection and Response (NDR) for modern security operations. View Alexis Robbins’ complete professional profile on LinkedIn.
Share
Key Takeaways
- The Compliance Dilemma: NIS2 classifies hospitals as "essential entities" with severe penalties and board liability, yet up to 62% of health systems struggle because medical devices cannot support endpoint agents or traditional patching.
- Evidence vs. Documentation: Articles 21 and 23 require proof of real-time asset tracking, actual segmentation enforcement, vendor access monitoring, and 24-hour incident notifications—outcomes impossible to prove via static policies alone.
- Agentless Network Visibility: Passive Network Detection and Response (NDR) is the only non-disruptive way to continuously discover assets, inspect encrypted clinical protocols (HL7, DICOM, FHIR), and verify security controls without risk to patient care.


