
Sector
Energy Supply
Energy suppliers form part of critical infrastructure (KRITIS). NIS2, the KRITIS umbrella act (KRITIS-Dachgesetz), the IT security catalogue, and the CER Directive unite cybersecurity, operational technology (OT) security, and physical resilience into a single obligation — integrated across all levels into a robust security architecture.
Overview
A Sector in Transition
Energy supply ranks among the most highly interconnected and simultaneously most vulnerable infrastructures in modern society. Grid control centres, substations, generation assets, and storage facilities now operate in close conjunction with digital control and automation technology — operational technology (OT), encompassing SCADA systems, programmable logic controllers (PLCs), and remote control technology. The energy transition is accelerating this development. Every new wind and solar installation, every storage unit, and every controllable load introduces additional digital interfaces and expands the attack surface. What was once regarded as a closed, air-gapped operational environment has become a distributed, remotely controllable system. This is IT/OT convergence: corporate IT and plant control systems are growing together. With that, the boundary between an IT incident and a genuine supply disruption becomes increasingly indistinct.
The Threat Landscape
That attacks on energy networks produce physical consequences is now an established fact. In December 2015, attackers used compromised remote access to seize the control systems of three Ukrainian distribution network operators, opened breakers at approximately 30 substations, and left more than 200,000 people without electricity — the first publicly confirmed power outage caused by a cyberattack (threat actor: Sandworm, malware: BlackEnergy). One year later, in December 2016, Industroyer became the first malware purpose-built for power grids, disabling a substation in Kyiv for more than an hour — capable of communicating directly with industrial protocols such as IEC 60870-5-104. These tools have not disappeared. In April 2022, the same actors attempted to shut down Ukrainian high-voltage substations using Industroyer2; the attack was stopped in time. In October 2022, the same group succeeded in causing a brief blackout by manipulating the control technology of a substation (analysis by Mandiant).
Germany has been affected on two fronts. First, as collateral damage from interconnected systems: in February 2022, on the day of the Russian invasion of Ukraine, an attack on the Viasat KA-SAT satellite network simultaneously disrupted the remote monitoring of thousands of wind turbines in Germany. According to the German Energy Agency (dena), at least approximately 3,000 installations lost remote control capability. This serves as an instructive case study in supply chain and third-party risk: a single compromised service provider can affect thousands of installations simultaneously. Second, through direct attacks on utilities and municipal energy suppliers. The municipal utility TWL in Ludwigshafen lost approximately 500 GB of data in a ransomware attack (Clop) in April 2021 — executed via double extortion, combining encryption with data exfiltration. Enercity Hannover was targeted in October 2022, Stadtwerke Karlsruhe in February 2023, and the Deutsche Energie-Agentur (dena) in November 2023 (LockBit). At Stadtwerke Burg, an attack in August 2024 paralysed core digital services for more than three months. At the renewable energy supplier Tibber, data belonging to approximately 50,000 German customers was exfiltrated in November 2024.
In the majority of these cases, electricity supply itself remained stable — owing to consistent network segmentation between IT and OT. What was compromised was billing, communications, and customer service. This is the central lesson: the most probable risk today is not the spectacular blackout, but the gradual erosion of controllability, situational awareness, and operational capacity.
The figures support this assessment. In its 2024 situation report, the Federal Office for Information Security (BSI) recorded a total of 726 attacks on critical infrastructure for the period from mid-2023 to mid-2024 — 236 more than in the preceding period. A hybrid dimension further compounds this picture: sabotage of electricity and gas infrastructure and physical attacks on critical installations have reached a new level of severity in Europe. Cyber-physical threats — the deliberate combination of digital and physical attack vectors — are no longer a theoretical category.
The Regulatory Drivers
Legislators have responded on multiple fronts simultaneously. The NIS2 Implementation Act, in force since December 2025 and transposed into the BSI Act, establishes binding obligations regarding cybersecurity, risk management, and incident reporting. The number of entities in scope has grown from approximately 4,500 to around 30,000, now encompassing many smaller and medium-sized utilities and municipal energy suppliers — with fines of up to EUR 10 million or 2% of global group turnover. The KRITIS umbrella act (KRITIS-Dachgesetz), in force since March 2026 and the transposition of the European CER Directive (EU 2022/2557), makes the physical resilience of critical installations a standalone obligation for the first time: requiring a risk analysis, a resilience plan, and executive liability under Section 20 directed at demonstrable effectiveness of the measures taken. Network operators are additionally subject to the IT security catalogue issued by the Federal Network Agency under Section 11 of the Energy Industry Act (EnWG), which mandates a certified information security management system (ISMS).
The underlying rationale is significant. The objective of protection has shifted from individual systems to the continuity of supply itself — resilience rather than pure prevention, meaning the capacity to continue operating and to recover, even when an attack succeeds. With executive liability in place, the comprehensive auditability of risk analysis, resilience planning, and effectiveness monitoring becomes a direct responsibility of senior management.
Where the Critical Risks Reside
The most challenging risks rarely reside within a single domain. They arise at the interfaces — where conventional IT, operational technology, physical security, and supply chains converge, and where, in practice, accountability is often fragmented across separate organisational silos. The managing director of Stadtwerke Neumünster described this aptly following the attack on his organisation: the assumption had been that a robust security perimeter around the building was sufficient, without accounting for the possibility that an attacker might break into the caretaker's flat and take the keys from there. This is precisely the lateral movement technique that attackers exploit — traversing through legitimate connections and overlooked access paths.
Operational technology (OT) environments cannot be secured using conventional IT security methods. In IT, confidentiality takes precedence; in OT, the priorities are reversed — availability and integrity come first. Patch cycles are long, and a direct path from an office client to plant control systems must not exist at all. This is where defence in depth applies: layered, mutually independent protection tiers structured on the onion-skin principle, complemented by zone and conduit models in accordance with IEC 62443 and the Zero Trust paradigm — no implicit trust for users or connections alike. At the same time, cloud platforms, remote maintenance access, and external service providers extend the attack surface beyond the boundaries of the organisation itself. The Viasat incident demonstrated how an attack on a single service provider can affect thousands of installations simultaneously. Standards such as ISO/IEC 27001, the energy-sector-specific ISO/IEC 27019, and IEC 62443 define the technical framework. They give concrete form to what regulation demands — but they do not substitute for the security architecture that holds everything together.

