Energy Utilities & Municipal Providers · EnWG § 11 & KRITIS

Grids that can't go dark
need more than a firewall

As a network operator, you fall under Section 11 (1a) EnWG: certification against the German Federal Network Agency's IT-Sicherheitskatalog has been mandatory since January 31, 2018, with recertification every three years. Larger installations additionally fall under the KRITIS regulation, on top of NIS2. We test where the real risk sits for utilities: OT and remote control systems alongside conventional IT, unmanned substations, and customer-facing portals with wide reach.

Documentation suited for the IT-Sicherheitskatalog Experience with OT/SCADA & remote control systems Free initial consultation
IT meets OT
ITConventional IT
  • Priority: confidentiality of data
  • Patches can usually be rolled out promptly
  • Standard protocols (TCP/IP, HTTPS)
OTOT/SCADA & remote control systems
  • Priority: availability of supply
  • Patches often untouched for years (certification, vendor support)
  • Proprietary and legacy protocols with no built-in security
Section 11 (1a) EnWG

The 3-year cycle behind the IT-Sicherheitskatalog

Since January 31, 2018, operators of electricity and gas distribution networks have had to certify their IT security against the Federal Network Agency's IT-Sicherheitskatalog. Section 11 (1b) additionally covers operators of energy installations under KRITIS rules. Recertifying isn't a one-time formality: operators have to reverify on a recurring basis.

Audit rhythm
Every 3 years

The IT-Sicherheitskatalog explicitly requires regular recertification, not a one-off exercise. If you can't keep the evidence current, you risk regulatory consequences from the Federal Network Agency.

* Larger installations, such as power plants at or above 420 MW, additionally fall under the KRITIS regulation and therefore Section 8a BSIG and NIS2, with their own extra reporting obligations.

Attack surface: energy sector

The attack surface, on two tracks

Utilities combine conventional IT with operational technology spread physically across an entire grid area, often at sites without permanent staff. Each track has its own entry points, and at three spots they sit right next to each other.

ITAdministration & customer interfaces
OTGrid operations & installations
Access

Remote maintenance access

VPN and vendor access points connect the office network to control technology. Without multi-factor authentication and segmentation, they're the bridge from IT into OT.

Substations & unmanned installations

Many substations and secondary sites run entirely unmanned. Access control and physical hardening directly define the attack surface there.

Core

Administrative IT

Office network, email, billing. An attack here can quickly spread to the entire operation, not just administration.

Control rooms & data centers

Central control and data processing come together here, a high-value target that's often thinly staffed outside core hours.

Reach

Customer portals

Portals for contracts, meter readings and billing are publicly reachable and therefore a direct entry point from outside.

SCADA & remote control systems

Control systems and remote control technology run decentralized grid operations. Legacy protocols and missing segmentation from IT are the typical weak points here.

IT vs. OT

Why IT concepts don't carry over to OT

A complete picture of your attack surface only emerges once IT and OT security are assessed together. Both follow different priorities, and that gap between them is exactly what gets tested least in practice.

IT vs. OT ITConventional IT OTOT/SCADA & remote control systems
Priority Confidentiality of data Availability of supply
Patches Patches can usually be rolled out promptly Patches often untouched for years (certification, vendor support)
Protocols Standard protocols (TCP/IP, HTTPS) Proprietary and legacy protocols with no built-in security
Maintenance windows Short maintenance windows are feasible Maintenance only in tightly planned windows, downtime is not an option
Timeline

Three incidents, three entry points

Two cyberattacks that brought entire operations to a halt via administrative IT, and one physical attack on cables. A utility's attack surface doesn't end at the network.

2023-09-24

Stadtwerke Neumünster

Cyberattack

Stadtwerke Neumünster reportedly shut down all systems as a precaution after detecting a cyberattack.

2025

Stadtwerke Schwerte

Cyberattack

At Stadtwerke Schwerte, the internal network and customer portal were reportedly taken offline; the stolen data is said to have later surfaced on the dark web.

01/2026

Lichterfelde power plant, Berlin

Physical, not a cyberattack

An arson attack on power cables near the Lichterfelde power plant reportedly affected around 50,000 households. Not a cyberattack, but a reminder that physical security still matters alongside IT security.

Based on public reporting. accessgranted was not involved in these incidents.

Our approach

Two test tracks, one report

Supply reliability always comes first. That's why we test OT and remote control components noticeably more carefully than plain IT.

ITIT track
  1. 01

    Scoping & reconnaissance

    Customer portals, administrative IT and remote maintenance access go into scope. We gather information from public sources and scan the networks.

  2. 02

    Active testing

    We test manually against the agreed scope: authentication, access rights, segmentation from OT, and the hardening of your central systems.

  3. 03

    Rating

    We rate every finding by severity, exploitability and impact on supply reliability.

OTOT track
  1. 01

    Scoping with grid operations in mind

    Together we define which OT and control systems get actively tested and which are analyzed passively only.

  2. 02

    Passive analysis, agreed windows

    We analyze protocols and network traffic passively. Active tests run only in pre-agreed windows outside critical operating hours.

  3. 03

    Emergency contact & immediate stop

    A defined emergency contact accompanies every test. If grid operations or supply are affected unexpectedly, we stop immediately.

One final report, mapped to the IT-Sicherheitskatalog

Complete documentation with recommendations, a management summary for leadership, IT management and grid operations, and every finding mapped to the IT-Sicherheitskatalog.

Relevant modules

These tests bring your grid IT up to the state of the art

IT and OT can't be covered by a single test. For network operators, this is the combination we rely on.

Also worth watching

Keep an eye on KRITIS and NIS2

Larger network operators and installations above the KRITIS threshold face additional obligations under the BSI Act and NIS2, on top of the IT-Sicherheitskatalog. Our compliance pages explain what that means in practice.

Frequently asked questions

Pentesting for energy utilities: your questions

01

IT-Sicherheitskatalog & KRITIS

The Federal Network Agency's IT-Sicherheitskatalog doesn't name a specific test method, but it does require a certified information security management system and regular proof of adequate protective measures. In practice, a penetration test is the standard way to back that up technically and to find weaknesses before certification.
Certification against the Federal Network Agency's IT-Sicherheitskatalog runs on a recurring three-year cycle, mandatory for network operators since January 31, 2018. A regular pentest ahead of each recertification helps catch gaps early instead of during the audit itself.
The BSI-Kritisverordnung sets sector-specific thresholds, for example based on generation or supply capacity (power plants at or above 420 MW, for instance). Above that threshold, additional obligations under Section 8a BSIG and NIS2 apply. Not sure where you stand? We can work that out in a free initial consultation.
No. The IT-Sicherheitskatalog requires recurring recertification on a three-year cycle, not a one-time project. We recommend building the pentest permanently into your certification rhythm rather than scheduling it right before the next audit.
02

OT & operations

OT systems prioritize availability over confidentiality, often run on legacy protocols with no built-in security, and don't tolerate aggressive scanning. We test more carefully there: usually passive analysis with tightly scoped active testing outside critical operating hours, always with a defined emergency contact.
Yes, as part of our Physical Pentest module. We check access control, fencing and gate security, and whether someone could convincingly pose as a maintenance technician and gain unnoticed access. Before we start, we agree who on your side is in the know and who can call the test off if needed.
Before every test we jointly define which systems get actively tested and which are only analyzed passively. For production OT and control systems, the rule is: test more cautiously or skip it if in doubt. A defined emergency contact and an immediate stop on any unexpected impact are a fixed part of every assessment at network operators.
It depends heavily on scope: number of sites, whether OT/SCADA is included, whether physical testing and customer portals are in scope. Once the free initial call has settled the scope, you get a fixed-price quote with no open items.