Skip to content
Zyberum Cyber Security Firm
Menu
For your industryOTNIS2

Cybersecurity for Utilities and Critical Infrastructure: NIS2, KRITIS and OT

What municipal utilities and KRITIS operators must do: BSIG duties after NIS2, BSI-KritisV thresholds, the OT attack surface and a first project without downtime.

Updated This page as Markdown

In short

Municipal utilities and other operators in energy, water and waste water are regulated twice: as essential or important entities under the German BSIG since 6 December 2025 and, above the thresholds of the BSI-KritisV, as operators of critical installations with attack detection and proof duties. Grid operators also follow the IT security catalogue under § 11 EnWG. Typical OT assessments find remote maintenance with shared accounts, control protocols reachable from the office network and no detection in the control zone. A sensible first project combines a § 30 BSIG gap analysis, a passive OT assessment and an external pentest.

Which rules apply to you

Utilities are regulated as entities and, above certain sizes, as operators of critical installations. Both regimes live in the German BSIG since the NIS2 implementation act took effect on 6 December 2025.

BSIG as entity law. Energy, drinking water and waste water are sectors of high criticality in Annex I of the NIS2 Directive. A utility with 50 or more employees or more than 10 million euros in turnover and balance sheet total is an important entity, from 250 employees or 50 million euros turnover an especially important entity under § 28 BSIG. § 30 lists the risk management measures: risk analysis, incident handling, business continuity and backups, supply chain security, secure procurement and development, effectiveness measurement, training, cryptography, access control and asset management, multi-factor authentication. § 32 sets the reporting chain of 24 hours, 72 hours and one month. § 33 required registration with the BSI, which had to be completed by 6 March 2026. § 38 makes the management personally responsible for approving and supervising the measures and for attending training.

BSIG as KRITIS law. Above the thresholds of the BSI-KritisV, a utility operates a critical installation. § 31 adds requirements including systems for attack detection, and § 39 requires periodic proof to the BSI that the measures are in place. Sector-specific security standards (B3S) of the water and energy associations describe accepted ways to meet them.

EnWG § 11. Operators of electricity and gas networks implement the IT security catalogue of the Bundesnetzagentur, which rests on an ISO/IEC 27001 information security management system with a certificate, and operators of energy installations follow the corresponding catalogue for generation.

IEC 62443 is the technical standard for the control environment: 62443-3-2 for zoning and risk assessment, 62443-3-3 for system requirements. Auditors and insurers read it as state of the art.

Where attackers start

Most incidents at utilities begin in office IT and end in the control room only if nothing stops them in between.

  • IT to OT boundary: a historian, a reporting server or a shared Active Directory bridging the office network and the control system network.
  • Remote maintenance: SCADA vendor access, integrator VPNs and cellular routers at substations and pumping stations, often with shared accounts and no session recording.
  • Control protocols: IEC 60870-5-104, Modbus TCP and DNP3 carry commands without authentication; whoever reaches the network can send them.
  • Legacy HMIs and engineering stations: operating systems out of support, local administrator rights, USB use for project files.
  • Customer-facing systems: billing, customer portals, smart metering backends and the shared data centre that several utilities use.
  • People: phishing of billing and procurement staff is how most ransomware cases in the sector start.

What assessments typically find

Typical findings from OT and IT assessments in the utility sector, written as industry experience rather than any single customer: remote maintenance accounts shared between the vendor’s technicians and never rotated; IEC 104 and Modbus endpoints reachable from the office network because a historian sat in both zones; default credentials on remote terminal units and protection relays; HMIs on operating systems years out of support with no compensating isolation; backups mounted online in the same domain as the systems they protect; no logging from the control zone, so an intrusion would not be noticed until it caused an outage; and a flat network in which electricity, gas, heat and water control systems could see each other.

Each of these contradicts at least one § 30 measure and, for KRITIS operators, the attack detection requirement in § 31.

A sensible first project

Treat it as one project with three strands, so the result is a single prioritised plan rather than three reports.

  1. Scope and gap analysis: entity classification, KRITIS status, asset inventory of IT and OT, status against the § 30 measures and, where relevant, the IT security catalogue. Three to five days with IT, operations and management.
  2. Technical assessment: an external penetration test of your internet-facing systems, an internal assessment from the office network towards the control zone boundary, and a passive OT assessment of the control network. Active tests touch no live controller. Two weeks.
  3. Zone and conduit model per IEC 62443-3-2 and a plan for segmentation, remote maintenance, attack detection and reporting procedures, ordered by risk and by effort.
  4. Implement, then verify: retest the boundary after segmentation, and set up detection, for example with a managed SOC at a fixed monthly price per device.

Typical effort for steps 1 to 3 is 15 to 25 person-days, which is 18,000 to 40,000 euros at market rates. Monitoring is a separate monthly cost.

What Zyberum does and does not do here

We do the gap analyses against the BSIG and the IT security catalogue, test IT and OT without endangering supply, design zone models and remote maintenance concepts, write the incident response and reporting procedures and run detection and response for IT and OT with Zyberdome. We train operators and IT staff. We are not a certification body and not a testing body for the § 39 proof; we prepare you so that the auditor finds the measures in place. We do not operate your control room and never test a live system without written authorisation from the operator.

FAQ

Frequently asked questions

We supply 80,000 people. Are we KRITIS?

Probably not a critical installation, but almost certainly a regulated entity. The BSI-KritisV sets thresholds per installation category, and the general reference value is 500,000 supplied persons. Below it you are not an operator of a critical installation, but as a utility in energy, water or waste water with 50 or more employees or more than 10 million euros in turnover and balance sheet total you are an important or especially important entity under § 28 BSIG, with the measures of § 30, the reporting duties of § 32 and the registration of § 33.

Can you test our control systems without risking supply?

Yes, by not attacking live controllers. We work passively in the control zone: network captures, configuration and firewall rule reviews, interviews with your operators and the SCADA vendor. Active testing happens on the IT side, on the boundary systems and on spare or test controllers. Everything in the control zone is agreed in writing with your operations lead beforehand.

Does a managed SOC count as attack detection?

It can be the operating part of it. § 31 BSIG requires operators of critical installations to use systems for attack detection, which means sensors that collect the right data, rules that evaluate it and people who react around the clock. A managed SOC covers evaluation and reaction; the sensors in your IT and OT networks still need to be placed and tuned, which is part of the setup.

Sources

Related pages

Get started

What does this mean for your product?

In a free one-hour consultation we go through your product or plant, the regulations that apply and the first steps that bring the most security for the money.

  • Applicable regulations and deadlines for your case
  • Where attackers would start
  • A first project with a fixed price
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usDiscuss your situation

Pick a time that suits you

Open in a new tab