Since January 31, 2018, operators of electricity and gas distribution networks have had to certify their IT security against the Federal Network Agency's IT-Sicherheitskatalog. Section 11 (1b) additionally covers operators of energy installations under KRITIS rules. Recertifying isn't a one-time formality: operators have to reverify on a recurring basis.
The IT-Sicherheitskatalog explicitly requires regular recertification, not a one-off exercise. If you can't keep the evidence current, you risk regulatory consequences from the Federal Network Agency.
* Larger installations, such as power plants at or above 420 MW, additionally fall under the KRITIS regulation and therefore Section 8a BSIG and NIS2, with their own extra reporting obligations.
Utilities combine conventional IT with operational technology spread physically across an entire grid area, often at sites without permanent staff. Each track has its own entry points, and at three spots they sit right next to each other.
VPN and vendor access points connect the office network to control technology. Without multi-factor authentication and segmentation, they're the bridge from IT into OT.
Many substations and secondary sites run entirely unmanned. Access control and physical hardening directly define the attack surface there.
Office network, email, billing. An attack here can quickly spread to the entire operation, not just administration.
Central control and data processing come together here, a high-value target that's often thinly staffed outside core hours.
Portals for contracts, meter readings and billing are publicly reachable and therefore a direct entry point from outside.
Control systems and remote control technology run decentralized grid operations. Legacy protocols and missing segmentation from IT are the typical weak points here.
A complete picture of your attack surface only emerges once IT and OT security are assessed together. Both follow different priorities, and that gap between them is exactly what gets tested least in practice.
| IT vs. OT | ITConventional IT | OTOT/SCADA & remote control systems |
|---|---|---|
| Priority | Confidentiality of data | Availability of supply |
| Patches | Patches can usually be rolled out promptly | Patches often untouched for years (certification, vendor support) |
| Protocols | Standard protocols (TCP/IP, HTTPS) | Proprietary and legacy protocols with no built-in security |
| Maintenance windows | Short maintenance windows are feasible | Maintenance only in tightly planned windows, downtime is not an option |
Two cyberattacks that brought entire operations to a halt via administrative IT, and one physical attack on cables. A utility's attack surface doesn't end at the network.
Stadtwerke Neumünster reportedly shut down all systems as a precaution after detecting a cyberattack.
At Stadtwerke Schwerte, the internal network and customer portal were reportedly taken offline; the stolen data is said to have later surfaced on the dark web.
An arson attack on power cables near the Lichterfelde power plant reportedly affected around 50,000 households. Not a cyberattack, but a reminder that physical security still matters alongside IT security.
Based on public reporting. accessgranted was not involved in these incidents.
Supply reliability always comes first. That's why we test OT and remote control components noticeably more carefully than plain IT.
Customer portals, administrative IT and remote maintenance access go into scope. We gather information from public sources and scan the networks.
We test manually against the agreed scope: authentication, access rights, segmentation from OT, and the hardening of your central systems.
We rate every finding by severity, exploitability and impact on supply reliability.
Together we define which OT and control systems get actively tested and which are analyzed passively only.
We analyze protocols and network traffic passively. Active tests run only in pre-agreed windows outside critical operating hours.
A defined emergency contact accompanies every test. If grid operations or supply are affected unexpectedly, we stop immediately.
Complete documentation with recommendations, a management summary for leadership, IT management and grid operations, and every finding mapped to the IT-Sicherheitskatalog.
IT and OT can't be covered by a single test. For network operators, this is the combination we rely on.
Simulated access attempts on substations, control rooms and data centers. Covers the physical attack surface that matters most at unmanned sites.
Targeted testing of SCADA, remote control systems and control technology, with particular care for supply availability.
Network segmentation between IT, OT and administration, access rights, and hardening of your central systems.
Larger network operators and installations above the KRITIS threshold face additional obligations under the BSI Act and NIS2, on top of the IT-Sicherheitskatalog. Our compliance pages explain what that means in practice.