Skip to main content
DAKS® Blog

Risk Mitigation Strategies in Hospitals

Published on September 1, 2026

Implementing Alarm Systems in Hospitals in a Responsible Manner and in Compliance with Regulations

As a critical infrastructure, hospitals are subject to specific security standards, which are outlined in the NIS-2 Directive, hospital-specific security standards and B3S 1.3, taking into account current technologies and threat scenarios.

The guidelines contain requirements for risk management and for ensuring critical services, but remain relatively technology-neutral and allow for a variety of architectures as long as availability and resilience are guaranteed. When implementing resilient and sustainable alerting concepts, it is therefore the responsibility of the organization to identify and apply suitable technologies. Key strategic approaches should include the principles of self-sufficiency, redundancy, diversification, and regular drills.

Self-Sufficiency

Public utility infrastructures have become a very popular target – both for cyberattacks and physical sabotage. In addition to the power grid, this particularly affects telecommunications infrastructure. The risk of network outages is correspondingly high, and authorities estimate that it will continue to rise.

One effective measure is the deployment of self-sufficient systems capable of maintaining essential communications even in the event of public network outages. Emergency communication systems are particularly well-suited as self-sufficient fallback solutions. They can provide their own central communication network for various locations or continue to operate communications locally using server hardware.

Proprietary communications infrastructure

Alarm communication systems already integrate the necessary stakeholders and decision-makers, as well as various technical systems. This ensures that all key communication channels and requirements are fully operational – for example, for convening crisis management team meetings and emergency conferences, as well as for broadcast messages and targeted alerts to authorized personnel. The company’s own communication infrastructure, which can operate independently of the public network, thus ensures the company’s ability to act even during a crisis.

Redundancy

The second component for ensuring business continuity is redundant system designs. In the event of an attack or a failure of one system, critical processes can continue to run on an identical second, i.e., redundant, system. It is important for business continuity that all components and extensions of the deployed system are designed for redundancy from the outset and integrated into the redundancy design.

For the alarm communication system, various redundancy concepts are used – depending on the hospital’s needs and specifications – such as a hot-standby configuration or active parallel operation of the redundant servers.

Schematische Darstellung von Redundanzoptionen mit DAKS: Active-Active, Hot-Standby und Hot-Standby geosepariert

Spatially Separated Locations

Providers of cloud-based solutions often argue that, because local alarm servers are tied to a specific location, they are vulnerable to power outages, infrastructure failures, or cyberattacks, which is why purely local redundancy systems are insufficient. However, this is not the case when the redundancy system is installed at a different location. This geo-redundant strategy is not only generally recommended; it is also already being implemented by the majority of critical infrastructures.

Diversification

If different technologies are available, why not deliberately combine them to generate benefits for resilience? This approach to risk diversification can increase the organization’s resilience at various levels within the alerting plan: 

Alarm Systems Today: On-Premise – Cloud – Hybrid

“Don't put all your eggs in one basket” – a warning that holds true in many ways, especially when it comes to security. In terms of implementing a resilient alerting system, this means that using a variety of technologies can reduce risks. Accordingly, both purely local and exclusively cloud-based solutions are potentially more vulnerable.

It’s also worth noting that cloud systems are more vulnerable than locally installed systems. Cloud outages occur time and again and affect even major providers, as recent examples from AWS, Microsoft and Cloudflare demonstrate. Cloud providers are also a more attractive target for potential attackers than a local hospital system. 

A suitable strategy, then, is a combination of on-premise and virtual alerting solutions. Providers that natively support multiple operating models offer companies corresponding advantages in the simple and effective implementation of a resilient alerting infrastructure.

Communications Infrastructure: Integration Skills Are in Demand

B3S 1.3, Section 3.2.2.2 requires that various systems be included in the risk assessment, including call systems, telephony terminals based on various technology standards and intercom systems. Here, too, alarm systems that are capable of integrating the different technologies within a communications infrastructure are particularly well-suited. This kind of integration capability enhances resilience by enabling the system to seamlessly fall back on other available systems in the event of a failure of individual technologies, thereby ensuring that critical processes remain undisturbed. For example, if an attack on the local radio system prevents the use of cell phones, the alerting system can still function via landline phones and public address systems.

A person in a hoodie interacts with a digital cloud marked by warning symbols, symbolizing cybersecurity risks.

Regular Drills

Finally, a successful risk mitigation strategy includes conducting regular emergency drills. According to NIS-2, emergency plans must be in place for crisis situations, such as those that may arise from attacks. However, plans alone are not enough – they must be frequently reviewed and practiced to ensure that everything functions as intended in the event of an actual crisis. 

Testing and Practicing

Here, too, alarm communication systems provide valuable support by implementing the established emergency plans through automated processes. These processes can be triggered and rehearsed at the push of a button for training purposes. Regular drills not only ensure smooth operations in the event of a crisis but also help identify process errors before they become a problem. 

Unfortunately, with cloud-based alerting solutions, important drills are often skipped because each alert incurs a cost. Owners of self-operated alarm communication systems have an advantage here: they can conduct drills as often as they like at no additional cost.

Conclusion

Reliability is no longer just a feature

B3S 1.3 does not make any recommendations as to which of the technologies currently available are more suitable. However, from the perspective of risk diversification, it is clear that a local alerting infrastructure for critical services, such as those found in all critical infrastructure organizations and particularly in hospitals, remains indispensable. Only in this way can a consistent isolation be achieved in the event of an attack while simultaneously maintaining internal communication, which is indispensable right now for managing the crisis and keeping the organization operational. Local alerting infrastructures thus enable those responsible to provide truly resilient structures in accordance with NIS-2 and B3S 1.3, while also offering financial and organizational advantages. 

The DAKS alarm server meets both the NIS-2 and B3S requirements by

  • flexible and customizable redundancy concepts
  • multiple operating models (on-premise and virtual) for implementing a risk diversification strategy
  • integration of a wide variety of communication infrastructure technologies
  • support for regular emergency drills to test and practice procedures
  • sophisticated architectures and robust technology backed by over 30 years of market experience
  • unmatched quality – Made in Germany

DAKS by tetronik: Reliable solutions, reliable information!
DAKS – it's all about responsibility

Learn more about DAKS and how it can support you in your risk management. 

© tetronik GmbH. All rights reserved.