Skip to content

Securing Routers and Switches According to BSI Baseline Protection

Summary: Routers and switches must be hardened, monitored and documented in accordance with BSI-IT Baseline Protection to meet both governance requirements and NIS2 Directive compliance obligations.

Routers and switches are central network components whose security is specifically regulated by BSI-IT Baseline Protection. For CISOs, compliant configuration of these devices is a core requirement when fulfilling governance and NIS2 Directive obligations.

Routers and switches function as control points and distribution nodes of network infrastructure. They manage data flows and regulate access between network segments. Compromise of these devices enables attackers to conduct deep lateral movement, gain unauthorized access to sensitive systems, and comprehensively monitor data traffic.

BSI-IT Baseline Protection requires a series of measures for routers and switches: hardening through disabling unused interfaces and services, authentication for administrative access (e.g. SSH instead of Telnet), encryption of management connections, regular firmware updates, and active monitoring for unauthorized configuration changes. These are supplemented by requirements for network segmentation, access controls, and protocol filtering.

For organizations within NIS2 Directive scope, compliant security of these critical infrastructure components is not optional: it forms the foundation for meeting the directive’s requirements and documenting associated audit and evidence obligations. A missing or incomplete hardening process is considered a control deficiency and increases the risk of sanctions during inspections by the competent authorities.


Source: www.computerweekly.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: