The Bottom Line: NIS2 and B3S make legacy systems in hospitals no longer permissible — clinics must implement documented risk management and hardware modernization.
German hospitals operate some decades-old IT infrastructures that are not only outdated from a security perspective, but increasingly fail to meet legal requirements. The implementation of NIS2 and the Federal Cybersecurity Strategy (B3S) forces clinics to establish systematic risk management and modernization programs.
In German hospitals, much of the medical and administrative systems run on hardware and software whose manufacturer support has long since ended. Operating systems without security updates, proprietary legacy software, and outdated servers are the norm in many facilities. Daily operations function only because the systems “still work” — however, this offers no protection against outages, compromises, or data loss.
The EU’s NIS2 Directive obligates operators of critical infrastructure, including healthcare facilities with more than 50 employees, to implement comprehensive cybersecurity measures. In Germany, the Federal Cybersecurity Strategy (B3S) specifies these requirements for the public and critical sectors. Both regulatory frameworks require documented risk analysis, security measures according to state of the art, and emergency plans. Hardware without support and non-patchable software do not meet these criteria.
For CISOs, the situation creates an imperative to act: legacy systems must be systematically inventoried, assessed, and replaced with supported systems within defined timelines. This is not a one-time project but requires continuous asset management with regular audits and prioritized modernization. The investments are substantial, particularly since hospitals simultaneously face budget constraints.
Source: www.heise.de · Published 13 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.