Back to Industries
INDUSTRIES · ENERGY & GRID OPERATIONS

Grid work is operations. So is security.

We come out of the energy world: overlay networks across grown infrastructure, secure integration of third-party systems, PAM for privileged access, and SCADA gateways with protocol inspection. We design architecture and segmentation, harden it, and keep running it, along Section 5c EnWG and the Bundesnetzagentur IT security catalogues.
Section 5c EnWG ISO 27019 SCADA gateways · PAM · overlays

What we find

The BSI describes the situation in the energy sector accurately, but from above: decentralisation, sector coupling, supply-chain attacks on inverters and grid control technology. What we find inside the estates is more specific, and older.

The poor man's overlay. OpenVPN is almost everywhere, because it was already in the device. Authentication is weak, the tunnel is not monitored, and nobody sees what happens inside it. The gateways carry no policies or rudimentary ones — lateral movement works practically every time. On top of that, a master key: in once, in everywhere.

That the single key stays is not an oversight. It keeps operations simple and it avoids key rotation. These installations are built to last twenty years and more, and the people who built them retire with them — that is the real motivation behind much of what we find. Our counter-position: the people on these systems should change every five to seven years, and the systems and principles themselves belong under review every three to five.

Segmentation that is not segmentation. Separation runs by IP range, not by application and role. The split between generation and consumption side, which would matter most, is missing entirely in most estates. There are firewalls from the leading vendors, often on good hardware — with no zone concept behind them. The rule set has grown over years, nobody keeps a single source of truth, and everything was built so that it runs.

The servers are the blind spot. Linux and Solaris, in isolated cases still Tru64 as the host system. Whoever has insight there is rarely the same person who owns the networks. Over the years, silent overlays and administrative access paths appear that are in no documentation. On individual systems Telnet is still running, because it works and because people know it.

Physical access is trivial. Boxes in the field sit where anyone can reach them. Often a serial console is enough and the system hands over a root shell. Cold boot attacks — reading memory immediately after a restart — stop being a laboratory scenario at that point. No firewall helps against either.

And where detection exists, it is too slow. EDR or XDR are often in place. What is missing is somebody whose job it is to look, and a process that acts in hours rather than weeks. An exfiltration is long finished before the first approval is granted.

The BSI requires three tiers. They still have to be built.

In its position paper on the energy sector, the BSI calls for a three-tier approach: base protection across the whole OT and IT estate, targeted hardening of central components such as grid control technology, virtual power plants, storage and inverters, and high-assurance protection of exposed systems such as grid coupling points and control centres.

There is nothing to add to that. The question is what becomes of it in operations — and in practice the sequence usually ends at tier one, because tiers two and three cannot be bought.

Base protection means one source for identities and rules. Not five user directories, not one rule set per tool. As long as every system keeps its own truth, nobody reconciles them after six months, and the master key stays, because it is the only path that works everywhere.

Hardening central components means terminating rather than passing through. Between process network, plant network and office IT we put a system that terminates the protocol, inspects it and passes on only what is permitted — a proxy, a jump point or a protocol-aware SCADA gateway. A firewall rule that simply hands a network along satisfies the requirement on paper, not in an incident.

Exposed systems mean access that ends. Vendor remote maintenance runs through a PAM path with approval per assignment, a fixed time window and session recording. No standing credentials, and no silent tunnel that has been open for years.

On that basis we have run anomaly detection with machine learning. Process traffic is highly regular in normal operation — fixed peers, fixed function codes, fixed cycles. That makes it one of the few environments where a learned baseline genuinely holds. The models run at the gateway and at the handover point, not on field devices, and they do not intervene in control: they raise the deviation to the person who can judge it.

These three steps are not a product and not a migration. They are architecture work, and then operations — which is exactly why they are the work that gets left undone.

Charging infrastructure is an IT problem

In May 2026 the BSI published a dedicated report on the security of public charging infrastructure. Its finding inverts the usual story: the standards are fine. ISO 15118 and OCPP now largely match the state of the art. What is missing is the implementation — transport encryption, revocation lists and modern cryptography are, in the report's words, "häufig nur eingeschränkt oder optional implementiert, teilweise aus Gründen der Abwärtskompatibilität": often implemented only partially or optionally, in part for backwards compatibility.

That matches what we see. OCPP is a denial-of-service vector in itself: the decoders do not cleanly separate valid from invalid messages. Whoever is allowed to speak once can send whatever they want and overload the host. In OCPP 1.5, card IDs still travel unencrypted over HTTP, with everything that implies for replay.

The BSI's second finding is the more interesting one: the backend side — billing and load management — has barely been examined. That is where the business sits. A charge point that bills incorrectly costs more than one that does not charge.

So we treat charging infrastructure as a distributed application landscape rather than as power engineering: clean tenant separation, controlled interfaces to roaming and billing partners, a traceable rollout path across hundreds of field devices, and the same rule as everywhere else — the crossing terminates, inspects and passes on.

The BSI also calls the regulatory picture confusing: many technical specifications are non-binding, there are few specific IT security requirements for authentication, payment and data security, and for areas such as the public key infrastructure or energy management systems no defined test processes exist yet. Anyone waiting for that to become an obligation will build it later, under time pressure.

Where it pays to start

The first step is almost always an honest picture of the crossings. Not a new tool, but the question: which zone talks to which, over what, and who approved it. Then, in this order: remote maintenance onto one controlled path, one leading source for identities, configuration baselines from code rather than from memory — and, for the charging side, backend hardening.

Sources: BSI, position paper "Cybersicherheit im Energiesektor Deutschlands"; BSI, "Bericht zur IT-Sicherheit der öffentlichen Ladeinfrastruktur", published on 07.05.2026.

Concrete offerings

What you can hand off

  • Energy segmentation assessment

    Review zones and crossings between process network, plant network and office IT — including where separation has to happen at the protocol layer.

  • PAM for privileged access

    Privileged access management for vendor, contractor and administrator access: per-session approval, time window, session recording, no permanently stored credentials.

  • Overlay networks across grown infrastructure

    A dedicated encrypted transport layer for sites and installations, without mixing the networks underneath — deliverable in stages rather than as one rebuild.

  • SCADA gateway with protocol inspection

    A crossing into the process network that terminates the protocol, inspects it and passes on only what is permitted. Secure integration of third-party and vendor systems runs the same path.

  • Anomaly detection for process traffic

    A learned baseline of peers, function codes and cycles; deviations go to the handover point and to the person who judges them.

  • ISMS build-out to ISO 27019

    Scope, risk register, controls and evidence for the IT security catalogue — prepared for the external auditor.

  • Single source of truth for identities

    One leading directory that supplies network, servers, endpoints and applications.

  • Automated operations with Ansible and Terraform

    Rule sets, configuration baselines and patch rollout — reproducible, versioned and reversible.

  • Operations for charging and billing platforms

    Backend hardening, tenant separation, controlled partner interfaces and traceable field device rollouts.

Regulatory framework

The four that actually bite

Energy has its own chain of standards. Four documents decide what you actually have to do — the rest applies too, but rarely changes the order of the work. Also relevant: NIS2, the KRITIS duties of the BSI Act, ISO 27001, and for the charging side CRA and AFIR.

  • Section 5c EnWG
    German Energy Industry Act · Section 5c, IT security in installation and grid operations, power to issue determinations

    The legal basis: appropriate protection of telecommunications and data processing systems, measured against the Bundesnetzagentur's IT security catalogues. Operationally it means naming the scope, describing the crossings, and keeping both true while the estate runs — not once, for the audit.

  • Grid catalogue
    IT security catalogue for electricity and gas grids · Bundesnetzagentur, August 2015

    A certified ISMS for the systems needed for secure grid operation, plus a named IT security contact. The expensive part is the boundary: what belongs in scope when office IT and the process network are coupled in thirteen places? We work through the crossings before the scope is written down.

  • Installations catalogue
    IT security catalogue for energy installations · Bundesnetzagentur, December 2018

    Applies to KRITIS energy installations and likewise requires a certified ISMS covering plant control. We keep the plant scope separate from the office IT scope, because the risk profiles and the maintenance windows are not the same — a joint scope produces conditions nobody can meet in plant operations.

  • ISO 27019
    ISO/IEC 27019 · information security for energy utilities

    The energy-specific supplement to ISO 27002: process control, telecontrol, substation automation, remote maintenance. The reason a standard office-IT ISMS is not enough here. The controls land where they take effect — at the crossing and in the process network, not in a document about the process network.

Sector facts

As of 2026-09 · Source: dynexo Operations
Typical engagementsGrid operations · energy installations · municipal utilities · charging and billing platforms
Most common triggersAudit preparation under the IT security catalogue, rebuilding remote maintenance, merging grown networks
Typical operating modelOn-premise for process and plant networks, EU-hosted or on-premise for the IT side
Core regulationSection 5c EnWG · Bundesnetzagentur IT security catalogues · ISO 27019
What we touch firstCrossings, remote maintenance, one leading identity source
Recurring building blocksOverlay networks · SCADA gateways with protocol inspection · PAM · anomaly detection on process traffic
Maintenance windowsScarce and rare · every change tested and reversible
Operating levelsManual, automated or by playbook — selectable per area
Asked often

Asked before the briefing

  • Do we need an ISO 27001 certificate?
    For grid operators and for KRITIS energy installations, the Bundesnetzagentur catalogues require a certified management system — there it is mandatory, not optional. Our position still holds: a certificate shows that controls were applied, not how well. We build the operations first, and let the evidence fall out of it.
  • Can you roll out agents in control systems?
    Usually not, and it is rarely necessary. On telecontrol and substation-level devices we work without agents: separation at the protocol layer, terminating crossings, inspection and analysis at the gateway. Agents go where they belong — on servers, workstations and engineering systems.
  • How do you handle vendor remote maintenance?
    One path for everyone, through PAM. Access via a controlled jump point, approval per assignment, a fixed time window, session recording. The vendor gets no permanent tunnel into the plant network and no permanently stored credentials, and you get a record of what happened.
  • Where do you use machine learning — and where not?
    In anomaly detection on process traffic. There the baseline is narrow and stable, and a deviation from it is a usable signal. The models run at the gateway and at the handover point, not on field devices, and they do not intervene in control. What they produce is a pointer for the person who judges it — not an automatic reaction inside the process network.
  • Do you also operate the charging infrastructure side?
    Yes, as an IT platform: backend, interfaces to roaming and billing partners, tenant separation, rollout and operation of the field device connection. For the metrology and calibration law requirements around billing we work with your subject matter owners — that is a legal and metrological question, not a purely technical one.
Next step

What does the separation between grid, plant and office IT actually look like at your site?

In the industry briefing we walk through your zones and crossings, map them against Section 5c EnWG and the applicable IT security catalogue, and name the points that need work first.