Cybersecurity & resilience

Topic field

Cybersecurity & resilience

Digitalising the energy transition

Programme-level expertise, no hands-on claim.

NIS2 has applied since December 2025 without a transition period, the KRITIS umbrella act since March 2026, and the IT security catalogue under §5c EnWG requires attack detection in control systems. We translate the obligations into architecture and programme requirements: who registers, who reports, which systems are affected and in which order the grid becomes secure.

Services for this field

Tools and frameworks

Articles in this field (11)

7 September 2026 · 8 min read

Counter-drone defense at energy facilities: what Germany's KRITIS umbrella law now requires

Since March 2026 the KRITIS umbrella law requires physical protection of energy facilities. What is legal against drones, and how detection works.

Read →

2 September 2026 · 8 min read

Attack Detection in OT Networks: Audit and Proof

Energy operators must run an attack detection system in the OT network and prove it to the BSI every two years. What the maturity audit requires.

Read →

26 August 2026 · 9 min read

Ransomware Resilience for Municipal Utilities: Reporting and Evidence Duties under NIS2

Since 6 December 2025 NIS2 binds municipal utilities too: a reporting cascade of 24 hours, 72 hours and one month after ransomware, plus an evidence duty.

Read →

21 August 2026 · 8 min read

Post-quantum cryptography for critical energy infrastructure

The BSI is ending classical encryption. Migration to post-quantum cryptography for critical energy infrastructure by 2030, 2031 and 2035.

Read →

15 August 2026 · 8 min read

DynoWiper and Sandworm: Wiper Malware Against Energy Plants

In late 2025 the Sandworm group hit Poland's power supply with the DynoWiper malware, threatening 500,000 customers. What the failed attack means for Europe.

Read →

7 August 2026 · 9 min read

Chinese PV Inverters as a Security Risk

About 80% of Europe's inverters are Chinese. What the EU high-risk vendor list, the 2026 funding ban and the BSI warning mean for grid operators.

Read →

31 July 2026 · 8 min read

OT Security for Energy Plants: IEC 62443 and the CRA

From 11 September 2026 the first CRA duties hit energy plants. How IEC 62443, with security levels and zones, turns OT security into a mandatory framework.

Read →

21 July 2026 · 8 min read

NCCS: Cybersecurity Code for TSOs and DSOs

The network code on cybersecurity (EU) 2024/1366 obliges grid operators to CSMS, audits and reporting. The deadlines to 2028 and what to do in 2026.

Read →

7 July 2026 · 7 min read

IT Security Catalogue under §5c EnWG 2026

Germany's IT security catalogue under §5c EnWG replaces the §11 catalogues. What grid and facility operators need to know in 2026: ISMS, ISO 27001, reporting.

Read →

12 June 2026 · 12 min read

NIS2 & KRITIS Umbrella Law 2026: Deadlines & Liability

Two German cyber laws in force in 2026: NIS2 (BSI, fines to 10M euros, management liability) and the KRITIS Umbrella Act (BBK, register from 17 July).

Read →

3 June 2026 · 7 min read

Project Glasswing: ENISA and NATO Join AI Security Program

ENISA joins Project Glasswing: first EU institution with Claude Mythos access. 23,000 vulnerabilities in critical infrastructure. NIS2 implications.

Read →
All articles in the Insights filter →

Glossary terms

Talk to us about this field

Book a conversation