01 Oct 2026
by Martin Franke

Euralarm and CoESS publish updated Cybersecurity Guidelines for the security and fire safety industry

Euralarm and the Confederation of European Security Services (CoESS) have published an updated edition of their Cybersecurity Guidelines for the Security and Fire Safety Industry. The revised publication provides practical guidance for organisations across the sector as cybersecurity becomes an increasingly important operational, technical and regulatory requirement.

The growing connectivity of fire safety and security systems brings significant benefits, including remote monitoring and maintenance, faster access to information and greater integration between systems. At the same time, connectivity introduces cybersecurity risks that need to be addressed throughout the complete lifecycle of systems and services.

Download Euralarm.png

The updated guidelines of Euralarm and CoESS therefore take a broad approach to cybersecurity. They are intended for organisations involved in product development, system design, installation and maintenance, monitoring and alarm response services. The publication combines organisational recommendations with practical technical measures and guidance for working with customers and other partners in the security chain.

Responding to a changing regulatory environment

An important reason for updating the publication is the rapidly developing European cybersecurity regulatory framework. The new edition provides an overview of legislation relevant to the fire safety and security sector, including the NIS2 Directive and the Cyber Resilience Act (CRA). The guidelines also address other relevant European legislation, including the EU Cybersecurity Act, GDPR, the Radio Equipment Directive and the AI Act.

Cybersecurity throughout the security chain

Rather than treating cybersecurity solely as a product or IT issue, the updated publication considers risks and responsibilities throughout the security and fire safety value chain. A central element is a five-pillar lifecycle approach covering products, project design, installation and maintenance, monitoring, and alarm response. For each stage, the guidelines identify relevant risks and provide practical recommendations for reducing them.

Technology alone is not enough

The updated guidelines also emphasise the human and organisational dimensions of cybersecurity. Companies are encouraged to establish clear cybersecurity governance, define responsibilities, maintain inventories of connected IT and OT assets, conduct regular risk assessments and put business-continuity and incident-response procedures in place.

Training and awareness are equally important. Recommendations include cybersecurity training for management, compliance, procurement and technical personnel, as well as ongoing awareness programmes for employees. The guidelines also underline the importance of cooperation between customers, suppliers and service providers so that cybersecurity responsibilities are maintained throughout the lifetime of a system or service. To support organisations in implementing these measures, the publication includes references to relevant cybersecurity standards and work in progress.

The updated ‘Cybersecurity Guidelines for the Security and Fire Safety Industry’ is available for download from the websites of Euralarm and CoESS.