When service communications go down, the first people to notice are rarely the IT team watching a monitoring dashboard. They are customers, and they notice immediately. Yet in many mid-sized businesses, the contact centre appears nowhere in the continuity plan. ERP, inventory and file servers are covered. The question of how customers reach the company when those systems are offline is left open.
The NIS2 directive has changed that calculation across the EU. Operational continuity is no longer discretionary good practice; it is one of ten mandatory risk-management measures, backed by management accountability.
A note on scope: NIS2 is an EU directive, and the obligations that bind a specific company come from its national transposition. Timelines, registration duties and supervisory authorities differ by member state. The German figures below illustrate the pattern rather than defining it — readers should confirm the position in their own jurisdiction.
What NIS2 actually asks for
The directive covers 18 sectors and generally reaches organisations from 50 employees or €10 million in annual turnover. Affected entities must register with their national authority, report significant security incidents on a staged timetable — early warning within 24 hours, a fuller report within 72 hours, a final report within a month — and evidence their risk-management measures. Fines reach €10 million or 2% of global annual turnover.
Germany offers a concrete example of what national transposition looks like in practice: the NIS2 implementing act took effect on 6 December 2025, bringing roughly 29,500 organisations into scope, with registration at the federal cyber security authority required by 6 March 2026.
Business continuity is named explicitly among the required measures: backups, documented emergency plans, rehearsed crisis procedures. This is precisely where service communications become relevant, because the channels used to inform customers, partners and regulators during an incident are often the same channels the incident has just disrupted.
Why customer service stays the blind spot
The causes of an outage are more mundane than the cybersecurity debate suggests. With VoIP telephony, a disrupted internet connection is enough to sever reachability entirely. Add power cuts, carrier faults, a mistaken configuration change — and, yes, attacks on IT systems.
Without a prepared fallback, the worst case follows: calls simply go nowhere. No engaged tone, no announcement, no information. Customers read silence as indifference. A second wave of damage arrives after the fault is fixed, when the accumulated demand hits a team that is already behind. Organisations that fail to plan for the backlog stretch a two-hour outage into a service-level problem lasting days.
The three layers of resilience
Resilience in service communications is not a single product. It is three layers that build on one another:
- Technical redundancy: multiple connection paths rather than one line, a platform operated across redundant data centres, failover that does not wait for manual intervention.
- Channel redundancy: when one channel fails, others must absorb the load. A team that already handles chat, email and messaging daily can switch within minutes. A telephone-only team cannot.
- Organisational redundancy: defined roles, pre-written announcements and auto-responders, a status message for customers, clear escalation paths, and a plan for working through the backlog.
The third layer is skipped most often and costs the least. A pre-drafted outage announcement costs nothing — but it has to exist beforehand and be stored in the system, not written under pressure.
The supply chain route into scope
Many smaller companies fall outside NIS2 directly, yet are pulled in indirectly. Supply chain security provisions require covered organisations to actively manage and evidence the security of their service providers and suppliers. In practice this means questionnaires, contract clauses and evidence requests travelling down the chain. Any supplier, software vendor or service provider working for a covered organisation should be able to give a credible answer to one question: how long does our own reachability survive an outage?
What this looks like with myContactCenter
myContactCenter from ilogixx brings telephony, chat, email, WhatsApp and ticketing onto a single platform. For resilience this has three practical effects. First, the communication logic does not sit on a box in the server room but in a redundantly operated cloud environment, so a local incident does not automatically take reachability with it. Second, routing rules, emergency announcements and diversions can be configured in advance and activated during an incident without an engineer on site. Third, the reporting provides the evidence base to document afterwards which channels were affected, when, and how long recovery took — exactly the kind of record that notification and evidence obligations call for.
Because every channel runs in the same interface, switching between them is not an emergency measure that needs rehearsing. It is what the team does every day.
Conclusion
NIS2 has turned a sound commercial habit into a regulatory expectation: organisations must remain able to operate when technology fails. For customer service this is less an added burden than an overdue prompt to answer a simple question — how reachable are we on the worst day of the year? Companies with a documented answer are not only meeting requirements; they are protecting customer relationships at the moment those relationships are most fragile.
Want to know how well your service communications would hold up? Book a no-obligation consultation through the online calendar at ilogixx.de. We will look at your channels, routing rules and outage scenarios together, and show you how myContactCenter secures your reachability.