When heat becomes a cyber threat

Why climate risks should be on every CISO’s agenda

Extreme weather events and more frequent heatwaves are increasingly coming under the spotlight as a threat – posing a serious risk to the availability of critical IT systems and, consequently, to the cyber resilience of organisations. The real danger lies not so much in overheated servers as in the knock-on effects: increased cooling requirements in data centres, greater strain on the electricity grids, potential supply restrictions and accelerated ageing of electronic components. This can be just as business-critical as a successful cyber-attack – leading to service interruptions, production downtime and breaches of regulatory requirements.

This is not a theoretical risk.

During the heatwave in the UK in July 2022, when temperatures rose above 40°C for the first time, several major cloud providers reported cooling-related outages at their London data centres. Amongst other things, compute and storage services were affected for several hours. For businesses reliant on these services, the weather conditions became a tangible availability issue, regardless of any firewall. Computers also failed at two leading British hospitals during the 2022 heatwave, resulting in the cancellation of operations and specialist appointments.*

This therefore raises a new question for CISOs: Is the organisation as well prepared for climate-related operational disruptions as it is for digital attacks?

Availability is more than just cyber defence

Information security is based on the three classic security objectives: confidentiality, integrity and availability. The latter aspect is usually associated with redundancies, backup strategies or DDoS protection – yet physical environmental conditions also have a decisive influence on it. Rising outdoor temperatures significantly increase cooling requirements, whilst cables and transformers lose efficiency in hot conditions. Companies with their own server rooms should check whether their cooling and emergency power systems are designed to cope with extreme conditions. Users of colocation or cloud services should ask what measures their service providers have implemented and how resilient these are.

ISO/IEC 27001 already provides the appropriate framework

The good news is that no new management system is required; the requirements are already in place. The ISO/IEC 27001 requires a risk-based approach that explicitly includes physical and environmental hazards. Specifically relevant sections include, amongst others:

  • A.7.5 – Protection against physical and environmental threats
  • A.7.11 – Utility systems (power, cooling, water)
  • A.5.30 – ICT readiness for business continuity

These controls make it clear that information security does not end at the firewall, but also encompasses the resilience of the physical infrastructure. In addition, ISO 22301 (Business Continuity Management) requires critical processes to be analysed and measures to be put in place to deal with exceptional disruptions. Heatwaves and regional power cuts are typical scenarios for business impact analyses and emergency drills.

NISG 2026 (NIS-2) broadens the perspective on resilience

The issue is also gaining prominence from a regulatory perspective. Article 21 of the NISG 2026 Directive requires affected organisations to implement a risk management framework that explicitly covers not only cyber threats but also business continuity, crisis management and physical security. Extreme weather events are therefore no longer purely a facilities management issue, but are explicitly part of the information security risk analysis.

Action required for security managers

CISOs should work with IT operations, facilities management and BCM to assess whether existing risk analyses still take account of current climate developments:

  • Assess cooling capacities and emergency power plans for extreme conditions
  • Examine the resilience of cloud and data centre service providers
  • Incorporate climate-related failure scenarios into contingency plans and crisis exercises
  • Involve supply chains, as regional extreme weather events can also affect service providers

Conclusion

Nowadays, cyber resilience means more than just protection against digital attacks. Climate risks must be systematically integrated into information security and business continuity management – the tools for this are already provided by ISO/IEC 27001, ISO 22301 and NIS-2. It is crucial to apply them consistently in a changing environment.

Would you like to check whether your ISMS adequately addresses climate-related risks? CIS Certification can support you with an ISO 27001 certification, which systematically integrates precisely these kinds of physical and environmental threats into your risk management.