Blog header + LinkedIn link (1200×628)@1x

CER Risk Assessments: What the Law Actually Asks For

Under the CER Directive, a CER risk assessment is not a record of what you already have. It is an analysis of what could go wrong, why, and what it would do to your essential service.

Over the summer, competent authorities across the EU have been identifying the organisations they consider critical entities. For those organisations a clock is now running, and the first thing it counts down to is a risk assessment.

Most will produce one on time. The more useful question is whether it will meet the definition the Directive actually uses. That definition is more demanding than many people assume.

What CER is, and who it reaches

Directive (EU) 2022/2557, CER for short, obliges designated organisations to be resilient against all hazards. Not just cyber. Not just natural disasters. All of them.

The Directive defines resilience broadly. It means being able to prevent, protect against, respond to, resist, absorb and recover from incidents that disrupt an essential service.

It covers 11 sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, food, digital infrastructure, public administration and space.

Organisations do not designate themselves. The national competent authority does it, based on three tests. The entity provides an essential service. It operates critical infrastructure in that Member State. And an incident would cause significant disruption.

Two points are worth getting right early. Article 8 identifies entities in banking, financial market infrastructure and digital infrastructure but exempts them from the substantive duties. Their resilience obligations sit mainly under DORA and NIS2. And CER does not apply in the UK, but it still reaches UK organisations through the EU operations they run, or as suppliers to EU critical entities.

When the CER risk assessment is due

The most common misreading I see is that the risk assessment was due on 17 July 2026. It was not. That was the date by which Member States had to identify their critical entities (Article 6(1)).

The authority then notifies each entity within a month, and the entity’s own clock starts on that date. From there:

DutyDueArticle
Risk assessmentWithin 9 months of notification12(1)
Resilience measures, resilience plan, liaison officerFrom 10 months after notification6(3), 13
Incident notification (initial report within 24 hours)From 10 months after notification6(3), 15
Review of the risk assessmentWhenever necessary, and at least every 4 years12(1)

Take an entity notified on the last possible date, 17 August 2026. Its risk assessment would be due by 17 May 2027, with resilience measures in place from 17 June 2027. Earlier notification brings both dates forward. National transposition laws can also vary the mechanics, so check the law in each Member State where you operate.

Notice how little time separates the two. Article 13(1) requires the resilience measures to rest on the risk assessment. So the assessment is not a box ticked in May. It is the foundation everything due in June is built on.

What the law means by a risk assessment

CER is precise about this. Article 2(7) defines a risk assessment as:

“the overall process for determining the nature and extent of a risk by identifying and analysing potential relevant threats, vulnerabilities and hazards which could lead to an incident and by evaluating the potential loss or disruption of the provision of an essential service caused by that incident”

Read it slowly and three things stand out. You must identify and analyse threats, vulnerabilities and hazards, not simply list them. You evaluate impact against one yardstick, the essential service. And the Directive defines risk as the magnitude of the loss or disruption combined with the likelihood of the incident.

Article 12 then sets out what the assessment must take into account:

  • Inputs: the Member State risk assessment and other relevant sources of information.
  • Scope: all relevant natural and man-made risks, including cross-sectoral and cross-border risks, accidents, natural disasters, public health emergencies, and hybrid threats and other antagonistic threats, including terrorist offences.
  • Outward dependencies: how far other sectors depend on the essential service you provide.
  • Inward dependencies: how far you depend on essential services from other sectors, including in neighbouring Member States and third countries.

It is worth being careful with language here. The articles name hybrid and antagonistic threats, including terrorism. Sabotage appears only in the recitals, and the word insider does not appear in the risk assessment articles at all. Insider risk enters through the employee security measures in Article 13(1)(e) and the background checks in Article 14. That is why a good assessment treats people as part of the threat and vulnerability picture, not as a separate HR matter.

Where assessments are likely to fall short

The good news is that existing work counts. Article 12(2) lets you reuse risk assessments and documents produced under other legal obligations. The competent authority may also declare an existing assessment compliant, in whole or in part.

That reuse carries a trap, though. Many organisations hold excellent business continuity plans, hazard registers, incident logs and control inventories. Those documents tend to be strong on natural hazards, accidents and dependencies. They are often much weaker on the two things the definition names first: threats and vulnerabilities.

An incident log tells you what has happened. It tells you very little about a capable, motivated adversary who has not yet acted. Nor does it reveal a hybrid campaign that blends cyber, physical and human activity. A control inventory tells you what exists. It does not tell you whether those controls would hold against the threats your site actually faces.

So the risk is not that organisations produce nothing. It is that they compile records and call the result a risk assessment. Then they build a resilience plan on a picture that never analysed the threat at all.

What a compliant CER risk assessment looks like

If you build the method from the definition outwards, the shape of a compliant assessment becomes fairly clear. In our own work we follow this sequence. It maps directly onto what Articles 2, 12 and 13 ask for.

First, build the picture

  • Start with the essential service. Define what the entity delivers and the sites, systems, processes and people behind it. Set out what loss or disruption would actually look like. Map dependencies in both directions, including cross-border and third-country suppliers.
  • Assess the threat. Use the Member State risk assessment as a formal input. Then add current intelligence: location-based crime data, open source reporting and the wider geopolitical and hybrid picture. For antagonistic threats, ask who could act against this specific service, and with what intent and capability. Assess natural hazards and accidents alongside them, on the same basis.
  • Test vulnerabilities against those threats. A structured risk library of assets, threats and controls makes this repeatable. Physical, cyber and people vulnerabilities belong in one converged view, because that is how a capable adversary will look at you. The question is not whether a control exists. It is whether the control would stop the threats you have just identified, including where contractors’ staff have access.

Then evaluate, trace and review

  • Evaluate the risk against the service. Score likelihood and the magnitude of disruption on a consistent, ISO 31000-aligned scale. That lets you compare and prioritise sites and assets across a whole portfolio.
  • Trace every measure back to a risk. Link each resilience measure to a specific risk and to one of the six Article 13 areas: prevent, protect, respond, recover, employee security and awareness. That trail turns a resilience plan into evidence.
  • Define your review triggers. At least every four years is the minimum. Set out what else counts as “whenever necessary”: a change in the threat picture, a change to the estate, an incident, or a revised Member State assessment.
  • Make it readable at board level. CER places accountability on the entity. Show leadership where the exposure sits and why the measures are proportionate, in language they can act on.

Where technology fits

Technology helps a great deal with threat, vulnerability and risk evaluation, particularly across large portfolios. AI can take on much of the heavy lifting in gathering and structuring threat data. But judging what a threat means for a specific essential service still needs an experienced security professional. The law asks for analysis, and analysis is a human responsibility.

If you supply critical entities

CER places no direct duties on suppliers, but that does not mean suppliers are untouched. Critical entities must assess how far they depend on others (Article 12(2)), plan for alternative supply chains (Article 13(1)(d)), and manage the security of external service providers’ personnel (Article 13(1)(e)).

In practice, security providers, facilities contractors and specialist suppliers should expect questions. Clients will ask about continuity, access control, vetting and exercising, and add contract terms that pass those requirements down. You may not be designated, but you will very likely be asked for evidence.

The real test

The test of a CER risk assessment is not whether it exists by the deadline. It is whether you can trace every measure in your resilience plan back to a threat, a vulnerability or a hazard you actually analysed.

If your competent authority asked you tomorrow to show that trail, could you?


Source: Directive (EU) 2022/2557 on the resilience of critical entities, EUR-Lex. Article references are to the Directive; national transposition laws may vary the detail.

wrench_toolkit_blog_header

Wrench Attacks: A Basic Personal Security Toolkit for Crypto Investors

Initial, high-level considerations for protecting yourself and your family from wrench attacks and other forms of physical coercion

Today the BBC reported on a crypto-linked home invasion in Solihull, in the West Midlands. In December 2025, three masked men forced their way into a couple’s home, beat the husband with hammers and threatened his heavily pregnant wife. Only then did they demand that he unlock his phone. A fourth man, watching on a video call, had them go through his apps until he found a crypto wallet. The threats escalated, and the husband transferred his savings, hundreds of thousands of pounds, before the attackers left.

The industry calls this a “wrench attack”. The name comes from a simple idea. You can invest heavily in encryption, hardware wallets and multi-factor authentication, but none of it matters if someone is in your home threatening your family. The attacker doesn’t break the cryptography. They break the person.

I live and work in France, and I’ve spent many years working in converged security, where physical, cyber and human risk meet. Watching this unfold, what strikes me most is not that the threat is new. It is that the answers are not.

What follows are initial, high-level thoughts rather than a security plan. Any effective security strategy has to fit the needs of the individual or organisation it protects. That said, the principles below follow the way a security risk assessment would approach the problem, validated against what official agencies and other sources already say.

Wrench attacks are not isolated incidents

Solihull is one case among many, and the trend is escalating across several countries.

  • France has become the global hotspot. The Interior Minister reported 77 crypto-linked kidnapping and extortion cases in the first half of 2026, up from 45 in the whole of 2025. Victims have included senior figures at Ledger, Binance France, The Sandbox and Paymium.
  • The UK is now seeing violent robberies linked to digital assets, as Solihull shows.
  • The US, Brazil and Thailand are also identified as hotspots, and US prosecutors have brought cases against organised home invasion crews.
  • Canada has seen it too. A court in British Columbia heard how masked intruders held a bitcoin investor’s family hostage overnight, an ordeal that ended only when his daughter escaped.

Globally, CertiK verified 52 wrench attacks in the first half of 2026, a third more than a year earlier. Home invasions rose from a single reported case in the first half of 2025 to 20, making the home the most common setting. Chainalysis warns that 2026 is on course to be the worst year on record for violent crypto theft.

The true numbers are likely higher. Police often record attacks simply as robberies or home invasions, with no mention of crypto.

1. Understand how targets are chosen

Before anyone reaches for a weapon, an attacker has to answer three questions. Who has the wealth? Who are they? Where can they be found?

Break any link in that chain and you become a much harder target. That means not advertising your holdings online, keeping wallet addresses separate from your identity, and thinking carefully about what family members share, because attackers increasingly go after relatives rather than the holder.

French prosecutors have urged crypto holders to be extremely careful about their exposure on social media. It’s sound advice, but it has a limit. You control your own posts. You don’t control the customer database held by an exchange, a tax service or a hardware wallet supplier, and once that data has leaked it cannot be recalled.

So a sensible approach assumes you can be found, and asks what happens next. This is defence in depth.

2. Accept that duress beats any technical control

Multi-factor authentication assumes the person entering the code is acting freely. When your family is being threatened, you will override every control you have, and you would be right to.

The simplest mitigation is separation. The phone you carry every day should hold no wallets and no crypto apps. When attackers demand your phone and search it, which is often their first move, there should be nothing to find.

Solihull shows exactly why. The attackers knew their victim held crypto, but not how to reach it. His everyday phone gave them the answer.

There’s a refinement worth making. If you were targeted through leaked data, attackers already believe you hold crypto, and a suspiciously clean phone may not convince them. The position you can actually hold under pressure is not “I don’t have any”. It is “I can’t move it”.

Multi-signature arrangements, a trusted co-signer and time-locked withdrawals all support that position. A French prosecutor has suggested measures that slow transfers, ideally by around seven days. Banks have used this principle for decades. Time-lock safes exist so that staff can honestly say they cannot open them.

3. Buy time with physical security

Delay only works if it lasts longer than the response. The question is not whether your front door is strong, but how many minutes it buys you, and how many minutes it will take for help to arrive. In rural areas that response can take a while, so the specification has to reflect reality.

In Solihull, home security cameras recorded the whole 45-minute attack. Recording an attack is not the same as stopping it. Surveillance only helps if it triggers a response.

Layer it:

  • A hardened external door, with a firm rule of verifying callers before opening. Attackers frequently pose as delivery drivers, tradespeople or police officers.
  • An internal safe room where the family can shelter and where crypto devices are kept.
  • Communications that don’t rely on a single landline that can be cut.
  • Monitored surveillance, with alarm verification through a receiving centre so that police can prioritise the response.

Start at the front door

The front door is your first delay. That means a security-rated door and frame, not just a stronger lock, and a way to see and speak to callers without opening it, such as a door viewer or video doorbell. Many of these attacks begin with someone at the door pretending to be a courier or a police officer, so the rule is simple. If in doubt, don’t open it.

My own suggestion goes one step further. Make the safe room the room where the family already spends its evenings, such as the lounge or TV room, ideally without accessible windows, or with lockable security shutters where there are windows.

A dedicated panic room depends on spotting the threat early and getting there in time. If you are already in the protected room when someone attacks the front door, the plan is simple. Shut the door, lock it, lower the shutter and call for help.

Making the everyday room work as a safe room

A few basics turn an ordinary lounge into somewhere that buys real time.

  • Choose the right room. An internal room with solid walls is best. Ideally it has no ground-floor windows, or windows you can cover with lockable security shutters.
  • Upgrade the door. Fit a solid, security-rated door and frame that locks quickly from the inside, with reinforced hinges. It should look like an ordinary door.
  • Keep a way to call for help inside. A charged phone and a panic alarm linked to a monitored alarm centre, neither relying on the house landline.
  • Store your crypto devices there. Hardware wallets and any device that can access your crypto should live in the safe room, not on you or around the house. Combined with multisig or a time lock, no single device in the room can move everything on its own.
  • Watch from inside. A screen showing the entrances and the area just outside the room tells you what is happening and helps you brief the police.
  • Don’t compromise fire safety. You still need a way out if there is a fire, and ventilation if you’re in there for a while. NPSA’s guidance stresses that one security improvement must not undermine another aspect of safety.
  • Rehearse it. Everyone in the household, children included, should know the trigger, what to do and who closes the door. A plan nobody has practised rarely works under stress.

If a professional is helping you, ask them to measure the delay. The time it takes to get through the front door and then the safe room door should exceed the time it realistically takes for help to arrive.

The safe room protects people first. The devices kept in it should never be able to move everything on their own.

4. None of this is new, and that’s the point

The UK’s National Protective Security Authority (NPSA) published guidance in May 2025 on preparing and using safer areas to protect high-risk individuals. It treats a safer area as one layer of home security, measures delay as the total time needed to force entry into the property and then into the safer area, flags accessible windows as a vulnerability to address, and recommends cameras that can be monitored from inside the room.

The French Interior Ministry advises crypto holders to plan in advance how they would handle access to their assets in a situation involving physical risk, and to keep recovery phrases offline.

US court cases show the same attack chain described above. In one, a home invasion crew compromised victims’ email accounts and carried out physical surveillance before attacking.

Banks, cash-in-transit firms and executive protection teams solved most of this problem years ago. The gap isn’t technique. It’s that cyber specialists have largely shaped crypto security, while the threat has moved into the physical world. Cyber, physical and human security can’t keep working in separate rooms.

Crypto holders don’t need a new kind of security. They need the old kind, joined up with the new.

Going further

These are high-level thoughts, not a substitute for a proper assessment. The right answer for any household, family office or business depends on its exposure, its property, its routines and how quickly help can reach it.

If you or your organisation would like a tailored security risk assessment and protection strategy, I’m happy to talk it through. You can reach me at paul@hawksightsrm.com.

Paul Mercer MPhil CSyP, Founder, HawkSight Security Risk Management

This article was written with AI assistance.

Sources