Buildings and water networks across Europe are becoming increasingly connected. Property owners use digital platforms to monitor consumption and detect leaks, while water utilities rely on meters, sensors and analytics to manage critical infrastructure.
These technologies create significant operational and environmental benefits. They also introduce more systems, data flows and technology providers that organisations need to understand and protect.
The EU’s NIS2 Directive establishes a common cybersecurity framework across the European Union. It introduces requirements relating to risk management, incident reporting, business continuity, supply-chain security and management responsibility.
Water utilities operate in sectors directly addressed by NIS2. Property companies are not automatically covered, but they may fall within scope depending on their size, activities and national legislation.
Whether an organisation is directly regulated or not, cybersecurity is becoming a fundamental part of managing connected buildings and water infrastructure.
NIS2 applies across the EU, but each Member State implements it through national legislation. The fundamental principles are shared, while the exact scope, supervisory authorities and reporting procedures may differ between countries.
Organisations operating in several European markets may therefore need to assess their responsibilities separately in each country.
Drinking water and wastewater are among the sectors covered by NIS2. Depending on factors such as size, role and national implementation, water utilities may therefore be subject to formal cybersecurity requirements.
This reflects their essential role in society. A cyber incident affecting a water utility could reduce operational visibility, disrupt important processes and, in a serious case, affect its ability to maintain essential services.
Modern utilities increasingly depend on digital infrastructure, including remotely read meters, connected sensors, cloud-based analytics and integrations between operational and administrative systems.
Each connection can improve efficiency and decision-making. It also becomes part of the utility’s wider risk environment.
For water utilities, cybersecurity is therefore more than a compliance exercise. It is an essential part of operational resilience.
Owning or managing property does not automatically place a company within the scope of NIS2. The assessment depends on the organisation’s size, activities and applicable national legislation.
NIS2 may become relevant if a property company, for example, produces or sells electricity, operates charging infrastructure, provides charging services or offers electronic communications services.
Property companies may also be affected indirectly. Customers, investors, insurers, public-sector partners and regulated organisations are likely to introduce stronger cybersecurity requirements throughout their supply chains.
Even when NIS2 does not create a direct legal obligation, it can therefore influence how property companies select systems, manage risks and evaluate technology providers.
Digital water management increasingly depends on meters, sensors, communications networks, cloud services, alerts and integrations.
Organisations must consider more than the confidentiality of individual consumption values. They also need to know whether systems will be available when needed, whether the data can be trusted and what happens if a supplier or integration experiences an incident.
If water data becomes unavailable, delayed or unreliable, leaks and abnormal consumption may remain undetected. For a utility, reduced visibility could also make it more difficult to understand network behaviour, prioritise maintenance or respond to operational events.
Reliable water management therefore depends on three basic principles:
Availability: Systems and information are accessible when needed.
Integrity: Data is accurate and protected against unauthorised changes.
Confidentiality: Access is limited to authorised users.
Collecting more data is not enough. Organisations must also be able to trust the systems that collect, transmit and analyse it.
Supply-chain security is a central part of NIS2.
Property companies and water utilities depend on software providers, cloud services, equipment manufacturers and other technology partners. Their resilience is therefore also influenced by how suppliers manage security and continuity.
When evaluating connected water solutions, organisations should ask:
How are data and communications protected?
How are identities and permissions managed?
How are vulnerabilities and security updates handled?
What happens if the service becomes unavailable?
How will customers be informed about an incident?
How are responsibilities divided between customer and supplier?
Not every technology provider is automatically covered by NIS2. Suppliers may nevertheless need to support customers that have obligations under the legislation.
Transparent processes, clear responsibilities and relevant security documentation are therefore becoming increasingly important in technology procurement.
Smartvatten provides digital water management solutions for property owners and water utilities across Europe. Because our solutions support customers’ daily operations and decision-making, cybersecurity, reliability and data protection are fundamental parts of how we operate.
Smartvatten complies with the NIS2 requirements applicable to our business and is certified according to ISO/IEC 27001, the internationally recognised standard for information security management systems.
Our certified approach provides a structured framework for identifying and managing risks, protecting information, maintaining service continuity and continuously improving our security practices. It includes systematic risk management, defined responsibilities and access controls, incident-management processes, continuity planning and security requirements for relevant suppliers and partners.
For our customers, security is not an additional feature. It is embedded in how we manage our platforms, processes and partnerships.
No technology provider can make a customer NIS2-compliant on its own. Each organisation remains responsible for its governance, systems, processes and risk management. However, selecting suppliers with established security practices and recognised certifications can make it easier to build a secure and resilient technology environment.
For water utilities operating critical infrastructure, this is particularly important. Analytical capabilities and access to reliable data must be supported by strong security, continuity and transparent processes.
NIS2 may initially appear to be another regulatory burden. It also creates an opportunity to better understand and manage digital dependencies.
Clear responsibilities, stronger supplier requirements and tested incident procedures do more than support compliance. They make organisations better prepared when something goes wrong.
As buildings and water networks become more connected, digitalisation and cybersecurity must develop together. The objective is not simply to collect more data, but to create a water ecosystem in which the systems, information and decisions can be trusted.
At Smartvatten, we believe that better use of water data must be built on trust. Our compliance with applicable NIS2 requirements and our ISO/IEC 27001-certified information security management system help us provide digital water-management solutions designed for both insight and resilience.
Want to learn more about how Smartvatten protects your data and supports secure digital water management? Contact our team.
Related articles
See all articlesPreparing water utilities for a new era of cybersecurity requirements
Smartvatten strengthens information security with ISO 27001 certification
The Pitfalls for water utilities of Solely Relying on SCADA Systems for Data Analytics
Cybersecurity in the cloud: Protecting our water infrastructure for the future
Guest column: Digitalisation is cooperation