Two operators in a municipal utility control room sit in front of a wall of screens showing grid schematics and a large overview display, one pointing at a monitor

Ransomware Resilience for Utilities: Report, Prove, Recover

A ransomware attack on a utility does not just knock out the IT. It hits the control room, billing and citizen services at once. And since December 2025 it also starts a clock that no one can stop.

Germany's NIS2 transposition turns an IT emergency into a reportable event with fixed deadlines. This article shows how the cascade of 24 hours, 72 hours and one month runs, what the evidence duty every three years requires, and which resilience measures actually cushion an attack.

Summary

Germany's NIS2 transposition (the NIS2 Implementation Act) has applied since 6 December 2025, and around 29,500 companies fall under it, many of them municipal utilities. Ransomware is the incident type that triggers the new duties most often. The reporting cascade under Section 32 BSIG has three stages: an early warning within 24 hours, a notification within 72 hours, and a final report within one month, with interim reports on request. The clock starts when the incident is noticed, at night and on weekends included. Operators of critical installations must also prove, under Section 39, every three years that their risk management works, through an audit or a certification such as ISO 27001. The full audit power takes effect from December 2028. Skip the registration or a report and you risk fines up to 10 million euros or 2 percent of worldwide turnover, with management personally liable. Germany's BSI situation report for 2025 counts 950 documented ransomware attacks, 72 percent with data theft, and around 48 percent of critical infrastructure operators run no attack detection system. The 2023 attack on Südwestfalen-IT shows the scale: more than 100 municipalities affected, recovery dragging into September 2024, costs of around 2.8 million euros. Resilience is mostly about recoverability: immutable backups, network segmentation and a restore chain that has actually been rehearsed.

Why NIS2 now puts utilities on the hook

For municipal utilities, cybersecurity is no longer optional. It is law. Germany's NIS2 transposition has applied since 6 December 2025; the Bundestag passed it on 13 November 2025, the Bundesrat confirmed it a week later. Around 29,500 companies now fall under it. Utilities are well represented, some as important entities, some as essential ones, the large ones as operators of critical installations.

Who is caught depends on sector and size. The duties start from about 50 employees or 10 million euros in turnover. And the registration window has long closed, it ended on 6 March 2026. The BSI has reserved the right to impose fines ever since. That is the frame the NIS2 Implementation Act and the KRITIS umbrella law set up together.

6 Dec 2025
NIS2 transposition applies
registration ended on 6 March 2026
24 / 72 h
deadlines for the first reports
final report follows after one month
€10m
fine for a breach
or 2 percent of worldwide turnover
48 %
of critical operators lack attack detection
BSI situation report 2025

Why does ransomware hit this so hard? Because it goes after exactly what a utility needs: systems that keep running. An encrypted grid, a stalled billing run, a blocked citizen portal, and there it is, the significant incident that triggers the reporting duty. The sector already knows the pattern from energy regulation, for example the Network Code on Cybersecurity.

The cascade: 24 hours, 72 hours, one month

The moment the utility notices the incident, the clock runs. Three fixed stages sit in the reporting cascade under Section 32 BSIG, each one heavier than the last. The starting point is the catch. Not the end of the forensics counts, but the awareness.

Flow diagram of the NIS2 reporting cascade after a ransomware incident with five stations: incident detected, early warning after 24 hours, notification after 72 hours, interim report on request, and final report after one month, joined by arrows
The three-stage cascade under Section 32 BSIG. Every deadline runs from the moment the incident is noticed, not from the end of the analysis.

The stages in detail:

  • Early warning, within 24 hours: without undue delay after awareness. It is brief and mainly says that something significant has happened and whether an unlawful attack is suspected.
  • Notification, within 72 hours: a first assessment. Type of incident, systems affected, indicators of compromise and the severity belong here.
  • Interim reports, on request: as long as the incident continues, the BSI can ask for status updates.
  • Final report, within one month: the full account with causes, measures taken and any cross-border effects.

Operators of critical installations report on top which installations and which critical services are hit. A lot of paperwork mid-crisis? Yes. And the wrong moment to invent it. The real case is decided earlier, by whether roles, contacts and templates are already sitting there. Start wondering mid-attack who actually calls the BSI, and the 24 hours are already gone.

Evidence duty: proof every three years

Reporting alone is not enough. You also have to prove the protection works. For operators of critical installations that sits in Section 39 BSIG: proof to the BSI every three years that the risk management measures are actually running.

Evidence duty under Section 39 BSIG is the obligation on operators of critical installations to show the BSI on a regular basis that their security measures work. The proof is provided every three years through audits, tests or certifications such as ISO 27001.

That audit power takes full effect three years after entry into force, from December 2028. No reason to wait, though. Credible proof does not appear in a few weeks. It is the by-product of a management system that has been maintained for years. And for essential entities the BSI can order an audit any time it likes, an incident being a fine excuse. Anyone who already knows the duties under the OT security regime for energy plants will spot familiar building blocks here.

Why utilities make a worthwhile target

Operational technology, billing, citizen services, a municipal utility holds all of it together. Often on grown IT, often on a tight budget. So one attack does not hit a single line of business, it hits several at once. And when a shared IT service provider goes down, dozens of municipalities go with it.

Four staff at a municipal utility in a meeting room during an incident briefing, one person standing and explaining at a blank whiteboard, a closed laptop and coffee cups on the table
The emergency is first an organisational task. Who reports, who decides, who coordinates the recovery: that belongs settled before the attack, not during it.

Südwestfalen-IT shows how fast this escalates. Late October 2023, a municipal IT service provider, the Akira ransomware encrypts the systems. More than 100 municipalities offline or barely working for days. Citizen offices, vehicle registration, payments, all frozen. Recovery dragged into September 2024, and it cost around 2.8 million euros. Only afterwards came multi-factor authentication across the board and tighter segmentation.

The case is no one-off, it is part of a trend. Germany's BSI situation report for 2025 counts 950 ransomware attacks documented by the BKA, 72 percent of them with data theft. Energy, water and transport are hit hardest. And nearly half of critical infrastructure operators run no attack detection system. That is the genuinely worrying figure: not that attacks happen, but that in many places no one notices in time.

Resilience: backup, segmentation, rehearsed recovery

Against ransomware one question matters most. How fast are you back in operation? Section 30 BSIG calls that business continuity. Its core is recoverability, and that stands or falls with the backup. One that gets encrypted along with everything else is none.

IT technician at a municipal utility kneeling in a small server room in front of an open rack, checking a cable connection on a storage unit with a handheld tester, a second rack and a fire extinguisher in the background
Recovery decides the downtime. Immutable copies kept offline and a rehearsed restart are the core of resilience.

Four building blocks carry the resilience:

  • Immutable backups: the 3-2-1 rule as a minimum, three copies on two media with one held off-site, extended by an immutable copy kept offline. In an attack it can be neither encrypted nor deleted.
  • Network segmentation: keep operational technology and office IT apart. Then an infection cannot jump from a compromised office machine into the control room.
  • Multi-factor authentication: a mandatory measure under Section 30. It stops the bulk of attacks that run on stolen credentials.
  • Rehearsed restart: with defined RTO and RPO targets, tested regularly. A plan no one has ever run rarely survives the real thing.

How much speed matters shows in one figure from the IBM 2025 study. 170 days, on average, for German companies to even detect and contain an incident. 170 days. Each one costs, in money and in trust. So the security of the connected systems belongs in the plan from day one, the way the enterprise guide to security and data protection lays it out.

Challenges and risks

The duties are clearly worded. The implementation rarely is. Four points make it hard in practice.

First, the reporting threshold. What counts as a significant incident? The line is open to interpretation. Report too much and you tie up resources, report too little and you risk the fine. Only clear internal criteria resolve that uncertainty.

Second, time. The deadline runs from awareness, at three in the morning and on a public holiday too. Without a 24/7 reporting path staffed by reachable owners, the 24-hour deadline is hard to hold.

Third, responsibility. Many municipal utilities do not run their own IT but use a municipal service provider. Who reports then, and who is liable? That belongs in the contract, otherwise everyone points at each other when it counts.

Fourth, budget and skills. Evidence, audits and an attack detection system cost money and people, and smaller providers feel that. The responsibility still sits with management personally. Delegating to a provider does not remove the duty of oversight. Data protection comes on top, since a data leak is at the same time a GDPR case.

What utilities should do now

The most important step happens before the incident. Not during it. Rehearse the reporting cascade once, and you lose no hours to basic questions when it counts. Four steps put a utility in shape.

  1. Set up registration and a reporting path

    First check whether the BSI registration is done, and complete it if not. Then set up a 24/7 reporting path with templates and named owners for the three stages of 24 hours, 72 hours and one month. A report that comes out of the drawer in an emergency buys time.

  2. Make backups immutable and test them

    Introduce the 3-2-1 rule plus an immutable, offline copy. And test the restore at least once a year against clear RTO and RPO targets. A backup that has never been restored is an assumption, not protection.

  3. Shrink the attack surface

    Segment operational technology from office IT, make multi-factor authentication mandatory, and deploy an attack detection system. Nearly half of critical operators still have none, and that is the biggest open gap.

  4. Build evidence capability and clarify roles

    Plan audits or an ISO 27001 certification for the Section 39 evidence duty before the audit power takes full effect in 2028. And set the responsibility between the utility and its IT service provider in writing, including reporting and restart duties.

Key point

NIS2 turns a ransomware incident into a reportable event with a clock: 24 hours, 72 hours, one month. Keep a reporting path, immutable backups and a rehearsed restart ready, and you meet the duty while cutting the downtime that really matters. The evidence duty from 2028 rewards exactly those who start now.

Further reading

Frequently asked questions

Does NIS2 apply to municipal utilities? +

Yes. Since 6 December 2025 Germany's NIS2 transposition applies, and many municipal utilities fall under it as important or essential entities, larger ones as operators of critical installations. Sector and size decide: the duties kick in from around 50 employees or 10 million euros in turnover, and large providers serving 500,000 people count as critical infrastructure.

What reporting deadlines apply after a ransomware incident? +

The reporting cascade under Section 32 BSIG has three stages. An early warning goes to the BSI without undue delay, at the latest within 24 hours of awareness. After 72 hours an assessing notification follows, interim reports come on request, and within one month the final report sets out causes and measures. The clock starts when the incident is noticed.

What is the evidence duty under Section 39 BSIG? +

Operators of critical installations must prove to the BSI every three years that their risk management works. Evidence takes the form of audits, tests or certifications such as ISO 27001. The full audit power under Section 39 takes effect three years after entry into force, so from December 2028. For essential entities the BSI can order audits on top of that.

What fine applies for breaching NIS2? +

For essential entities, fines can reach up to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. Failing to register or to report a significant incident on time risks these sanctions. Management is personally liable for oversight and cannot delegate that responsibility away.

How do you protect backups against ransomware? +

A backup that gets encrypted along with everything else is no backup. The minimum standard is the 3-2-1 rule, three copies on two media with one held off-site, extended by an immutable copy kept offline. Just as important, test the restore regularly instead of only documenting it.