IT Advisory for Energy & Critical Infrastructure
For energy suppliers and other critical infrastructure operators, the legal baseline shifted at the end of 2025: the German NIS2 implementation act and the recast BSI Act (BSIG) took effect on 6 December 2025 with no transition period.
IT in Energy
The registration duty under section 33 BSIG expired on 6 March 2026, and the extended deadline granted by the BSI on 31 July 2026. Section 30 BSIG prescribes ten minimum measures, from risk analysis and incident handling through backup management and supply chain security to cryptography and access control. Operators of critical installations must additionally deploy attack detection systems under section 31 BSIG and prove the effectiveness of their measures to the BSI every three years (section 39 BSIG).
Incidents follow the three-stage reporting chain of section 32 BSIG: initial report within 24 hours, follow-up report within 72 hours, final report within one month. Management is personally liable and must undergo regular training under section 38 BSIG. Grid operators additionally fall under section 5c of the German Energy Industry Act; until the Federal Network Agency has adapted its IT security catalogue accordingly, the existing catalogue under section 11(1a) continues to apply, requiring a certified ISMS to ISO/IEC 27001 in conjunction with ISO/IEC TR 27019.
Technically this comes down to four layers: identities without standing administrator rights, with phishing-resistant sign-in and privileged access only through a jump host; segmentation between control technology and office IT; immutable backups that no administrator can delete; and logging that makes an incident provable inside the reporting deadlines. Alendris works on exactly those layers. For a critical infrastructure operator we delivered a NIS2 programme from gap analysis through Microsoft Defender XDR, Microsoft Sentinel and Entra ID Governance to audit-ready documentation.
At an energy provider we consolidated the Azure logging and alerting architecture entirely as infrastructure as code, so evidence stays reproducible. Managed SOC and on-call cover are contractual add-ons; regular service hours are Monday to Friday, 08:00 to 17:00.
Typical pain points
- NIS2 obligations with hard deadlines and significant fines (up to EUR 10M or 2% turnover)
- OT/IT convergence: Industrial Control Systems (ICS / SCADA) on the same network as office IT
- Heightened threats from state-sponsored APTs and ransomware actors
- Personal liability of management under NIS2
- 24/7 availability requirements vs. limited security personnel capacity
Relevant compliance frameworks
Service focus in this industry
From our work in this industry
- Replacement of Citrix environment with Azure Virtual DesktopFull migration of 8,000 Citrix users to a highly automated AVD target architecture.
- Development of an AI Platform based on Microsoft AzureSecure and scalable AI usage in the company is created through a central Enterprise Search that bundles information from systems such as SharePoint, ServiceNow, and SAP.
- Security Modernization with a Focus on Microsoft 365 & SOC ReadinessSustainable improvement of the security posture in the Microsoft ecosystem with a focus on identity protection, tenant hardening, and SOC readiness.
- Evolution of an Enterprise Monitoring Solution on AzureRedesign of the Azure Monitoring architecture with a Dedicated Azure Monitor Cluster, standardized DCR Rules, and complete Infrastructure as Code automation.