Skip to main content
Industry

IT Advisory for Energy & Critical Infrastructure

For energy suppliers and other critical infrastructure operators, the legal baseline shifted at the end of 2025: the German NIS2 implementation act and the recast BSI Act (BSIG) took effect on 6 December 2025 with no transition period.

Overview

IT in Energy

The registration duty under section 33 BSIG expired on 6 March 2026, and the extended deadline granted by the BSI on 31 July 2026. Section 30 BSIG prescribes ten minimum measures, from risk analysis and incident handling through backup management and supply chain security to cryptography and access control. Operators of critical installations must additionally deploy attack detection systems under section 31 BSIG and prove the effectiveness of their measures to the BSI every three years (section 39 BSIG).

Incidents follow the three-stage reporting chain of section 32 BSIG: initial report within 24 hours, follow-up report within 72 hours, final report within one month. Management is personally liable and must undergo regular training under section 38 BSIG. Grid operators additionally fall under section 5c of the German Energy Industry Act; until the Federal Network Agency has adapted its IT security catalogue accordingly, the existing catalogue under section 11(1a) continues to apply, requiring a certified ISMS to ISO/IEC 27001 in conjunction with ISO/IEC TR 27019.

Technically this comes down to four layers: identities without standing administrator rights, with phishing-resistant sign-in and privileged access only through a jump host; segmentation between control technology and office IT; immutable backups that no administrator can delete; and logging that makes an incident provable inside the reporting deadlines. Alendris works on exactly those layers. For a critical infrastructure operator we delivered a NIS2 programme from gap analysis through Microsoft Defender XDR, Microsoft Sentinel and Entra ID Governance to audit-ready documentation.

At an energy provider we consolidated the Azure logging and alerting architecture entirely as infrastructure as code, so evidence stays reproducible. Managed SOC and on-call cover are contractual add-ons; regular service hours are Monday to Friday, 08:00 to 17:00.

Context

Typical pain points

  • NIS2 obligations with hard deadlines and significant fines (up to EUR 10M or 2% turnover)
  • OT/IT convergence: Industrial Control Systems (ICS / SCADA) on the same network as office IT
  • Heightened threats from state-sponsored APTs and ransomware actors
  • Personal liability of management under NIS2
  • 24/7 availability requirements vs. limited security personnel capacity
Regulation

Relevant compliance frameworks

NIS2 / NIS2 implementation actsBSI ActBSI IT-GrundschutzKRITIS regulationSector-specific standardsISO 27001