Cybersecurity for Utilities and Critical Infrastructure: NIS2, KRITIS and OT
What municipal utilities and KRITIS operators must do: BSIG duties after NIS2, BSI-KritisV thresholds, the OT attack surface and a first project without downtime.
Updated This page as Markdown
In short
Municipal utilities and other operators in energy, water and waste water are regulated twice: as essential or important entities under the German BSIG since 6 December 2025 and, above the thresholds of the BSI-KritisV, as operators of critical installations with attack detection and proof duties. Grid operators also follow the IT security catalogue under § 11 EnWG. Typical OT assessments find remote maintenance with shared accounts, control protocols reachable from the office network and no detection in the control zone. A sensible first project combines a § 30 BSIG gap analysis, a passive OT assessment and an external pentest.
Which rules apply to you
Utilities are regulated as entities and, above certain sizes, as operators of critical installations. Both regimes live in the German BSIG since the NIS2 implementation act took effect on 6 December 2025.
BSIG as entity law. Energy, drinking water and waste water are sectors of high criticality in Annex I of the NIS2 Directive. A utility with 50 or more employees or more than 10 million euros in turnover and balance sheet total is an important entity, from 250 employees or 50 million euros turnover an especially important entity under § 28 BSIG. § 30 lists the risk management measures: risk analysis, incident handling, business continuity and backups, supply chain security, secure procurement and development, effectiveness measurement, training, cryptography, access control and asset management, multi-factor authentication. § 32 sets the reporting chain of 24 hours, 72 hours and one month. § 33 required registration with the BSI, which had to be completed by 6 March 2026. § 38 makes the management personally responsible for approving and supervising the measures and for attending training.
BSIG as KRITIS law. Above the thresholds of the BSI-KritisV, a utility operates a critical installation. § 31 adds requirements including systems for attack detection, and § 39 requires periodic proof to the BSI that the measures are in place. Sector-specific security standards (B3S) of the water and energy associations describe accepted ways to meet them.
EnWG § 11. Operators of electricity and gas networks implement the IT security catalogue of the Bundesnetzagentur, which rests on an ISO/IEC 27001 information security management system with a certificate, and operators of energy installations follow the corresponding catalogue for generation.
IEC 62443 is the technical standard for the control environment: 62443-3-2 for zoning and risk assessment, 62443-3-3 for system requirements. Auditors and insurers read it as state of the art.
Where attackers start
Most incidents at utilities begin in office IT and end in the control room only if nothing stops them in between.
- IT to OT boundary: a historian, a reporting server or a shared Active Directory bridging the office network and the control system network.
- Remote maintenance: SCADA vendor access, integrator VPNs and cellular routers at substations and pumping stations, often with shared accounts and no session recording.
- Control protocols: IEC 60870-5-104, Modbus TCP and DNP3 carry commands without authentication; whoever reaches the network can send them.
- Legacy HMIs and engineering stations: operating systems out of support, local administrator rights, USB use for project files.
- Customer-facing systems: billing, customer portals, smart metering backends and the shared data centre that several utilities use.
- People: phishing of billing and procurement staff is how most ransomware cases in the sector start.
What assessments typically find
Typical findings from OT and IT assessments in the utility sector, written as industry experience rather than any single customer: remote maintenance accounts shared between the vendor’s technicians and never rotated; IEC 104 and Modbus endpoints reachable from the office network because a historian sat in both zones; default credentials on remote terminal units and protection relays; HMIs on operating systems years out of support with no compensating isolation; backups mounted online in the same domain as the systems they protect; no logging from the control zone, so an intrusion would not be noticed until it caused an outage; and a flat network in which electricity, gas, heat and water control systems could see each other.
Each of these contradicts at least one § 30 measure and, for KRITIS operators, the attack detection requirement in § 31.
A sensible first project
Treat it as one project with three strands, so the result is a single prioritised plan rather than three reports.
- Scope and gap analysis: entity classification, KRITIS status, asset inventory of IT and OT, status against the § 30 measures and, where relevant, the IT security catalogue. Three to five days with IT, operations and management.
- Technical assessment: an external penetration test of your internet-facing systems, an internal assessment from the office network towards the control zone boundary, and a passive OT assessment of the control network. Active tests touch no live controller. Two weeks.
- Zone and conduit model per IEC 62443-3-2 and a plan for segmentation, remote maintenance, attack detection and reporting procedures, ordered by risk and by effort.
- Implement, then verify: retest the boundary after segmentation, and set up detection, for example with a managed SOC at a fixed monthly price per device.
Typical effort for steps 1 to 3 is 15 to 25 person-days, which is 18,000 to 40,000 euros at market rates. Monitoring is a separate monthly cost.
What Zyberum does and does not do here
We do the gap analyses against the BSIG and the IT security catalogue, test IT and OT without endangering supply, design zone models and remote maintenance concepts, write the incident response and reporting procedures and run detection and response for IT and OT with Zyberdome. We train operators and IT staff. We are not a certification body and not a testing body for the § 39 proof; we prepare you so that the auditor finds the measures in place. We do not operate your control room and never test a live system without written authorisation from the operator.
FAQ
Frequently asked questions
We supply 80,000 people. Are we KRITIS?
Probably not a critical installation, but almost certainly a regulated entity. The BSI-KritisV sets thresholds per installation category, and the general reference value is 500,000 supplied persons. Below it you are not an operator of a critical installation, but as a utility in energy, water or waste water with 50 or more employees or more than 10 million euros in turnover and balance sheet total you are an important or especially important entity under § 28 BSIG, with the measures of § 30, the reporting duties of § 32 and the registration of § 33.
Can you test our control systems without risking supply?
Yes, by not attacking live controllers. We work passively in the control zone: network captures, configuration and firewall rule reviews, interviews with your operators and the SCADA vendor. Active testing happens on the IT side, on the boundary systems and on spare or test controllers. Everything in the control zone is agreed in writing with your operations lead beforehand.
Does a managed SOC count as attack detection?
It can be the operating part of it. § 31 BSIG requires operators of critical installations to use systems for attack detection, which means sensors that collect the right data, rules that evaluate it and people who react around the clock. A managed SOC covers evaluation and reaction; the sensors in your IT and OT networks still need to be placed and tuned, which is part of the setup.
Sources
- BSI-Gesetz (BSIG) as amended by the NIS2UmsuCG, §§ 28, 30, 31, 32, 33, 38, 39
- BSI-KritisV (Verordnung zur Bestimmung kritischer Anlagen nach dem BSI-Gesetz)
- Directive (EU) 2022/2555 (NIS2), Annex I sectors of high criticality, Articles 21 and 23
- Energiewirtschaftsgesetz (EnWG), § 11 IT security catalogue of the Bundesnetzagentur
- BSI: NIS-2 regulated companies
- IEC 62443-3-2 and 62443-3-3 (zones and conduits, system security requirements)
Related pages
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
- ServicesNIS2 without the paper mountain.NIS2 applies in Germany since December 2025. Find out if you are affected and implement risk management, incident reporting and testing with hands-on experts.
- ServicesEnterprise-grade protection. SMB-friendly price.24/7 managed security for SMBs: SentinelOne endpoint protection, SOC analysts, incident response and reports at a fixed monthly price per device.
- GlossaryKRITISKRITIS means critical infrastructures: facilities in Germany whose failure would cause supply shortages. Who counts, what the BSIG requires and what changed with NIS2.
- GlossaryZones and conduitsZones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
