Programme-level expertise, no hands-on claim.
NIS2 has applied since December 2025 without a transition period, the KRITIS umbrella act since March 2026, and the IT security catalogue under §5c EnWG requires attack detection in control systems. We translate the obligations into architecture and programme requirements: who registers, who reports, which systems are affected and in which order the grid becomes secure.
Since March 2026 the KRITIS umbrella law requires physical protection of energy facilities. What is legal against drones, and how detection works.
Read →Energy operators must run an attack detection system in the OT network and prove it to the BSI every two years. What the maturity audit requires.
Read →Since 6 December 2025 NIS2 binds municipal utilities too: a reporting cascade of 24 hours, 72 hours and one month after ransomware, plus an evidence duty.
Read →The BSI is ending classical encryption. Migration to post-quantum cryptography for critical energy infrastructure by 2030, 2031 and 2035.
Read →In late 2025 the Sandworm group hit Poland's power supply with the DynoWiper malware, threatening 500,000 customers. What the failed attack means for Europe.
Read →About 80% of Europe's inverters are Chinese. What the EU high-risk vendor list, the 2026 funding ban and the BSI warning mean for grid operators.
Read →From 11 September 2026 the first CRA duties hit energy plants. How IEC 62443, with security levels and zones, turns OT security into a mandatory framework.
Read →The network code on cybersecurity (EU) 2024/1366 obliges grid operators to CSMS, audits and reporting. The deadlines to 2028 and what to do in 2026.
Read →Germany's IT security catalogue under §5c EnWG replaces the §11 catalogues. What grid and facility operators need to know in 2026: ISMS, ISO 27001, reporting.
Read →Two German cyber laws in force in 2026: NIS2 (BSI, fines to 10M euros, management liability) and the KRITIS Umbrella Act (BBK, register from 17 July).
Read →ENISA joins Project Glasswing: first EU institution with Claude Mythos access. 23,000 vulnerabilities in critical infrastructure. NIS2 implications.
Read →