NIS2
Risk management and reporting duties
NIS2 demands state-of-the-art measures, incident reporting on short deadlines and personal accountability of executive management. Implementation has to be demonstrable, not asserted.
KRITIS · Energy
KaitoSec brings information security, business continuity and data protection for energy utilities together in one data model. You work to ISO 27001 or BSI IT-Grundschutz, connect the OT landscape through integrations and produce the evidence records under Section 39 BSIG from live operations.
At a glance
The situation
Each rulebook on its own is manageable. What gets expensive is the duplicated upkeep: the same assets, processes and risks, documented four times and kept current four times.
NIS2
NIS2 demands state-of-the-art measures, incident reporting on short deadlines and personal accountability of executive management. Implementation has to be demonstrable, not asserted.
§ 31, § 39 BSIG
Operators of critical installations have to run attack detection systems that evaluate operating parameters continuously and automatically, and evidence that every three years through security audits, inspections or certifications. What is required is current documentation, not a snapshot from the week before the date.
§ 11 EnWG
For grid operators, the Bundesnetzagentur's IT security catalogue requires a certified ISMS based on ISO 27001. The standard path is often set; the NIS2 duties come on top.
Operations
Security of supply demands continuity: backup management, crisis organisation and recovery are among the NIS2 minimum measures and part of the audit expectation. A certificate keeps no plant running.
The difference
You maintain every requirement, every asset and every risk once. KaitoSec maps them to NIS2, ISO 27001, BSI IT-Grundschutz and the KRITIS evidence. Regulatory ballast shrinks because overlaps collapse instead of adding up.
IT and OT
Grid control, substations and telecontrol carry the same protection needs as any server estate. KaitoSec models both in one structural model.
Control rooms, substations, telecontrol and business applications sit in the model as assets, with owners, protection needs and dependencies between IT and OT.
Protection needs are assessed on the process and inherited along dependencies to installations and systems. The assessment stays consistent as the landscape changes.
Connections to EDR and XDR systems feed inventory and state data into the platform. What your systems already know, nobody types in again.
Resilience
NIS2 explicitly counts continuity among the minimum measures: backup management, crisis management, recovery. In KaitoSec, the BCMS is part of the same system, not a second tool.
The business impact analysis uses the same processes and assets as the ISMS. Recovery times and dependencies live on the object, not in a document's annex.
Emergency and recovery plans reference the assets directly. When an installation changes, you see which plan has gone stale.
Exercises are planned, run and documented. Findings return to the management system as measures and are demonstrable at the next audit.
Data collection
Energy utilities spread accountability across entities: grid, generation, retail, shareholdings. KaitoSec collects the information where it lives.
Subject-matter owners answer questions in a guided interview. Answers land structured on the requirement and the asset, not as free text in an inbox.
Tasks reach owners as assigned work items with deadline and context. Feedback and evidence return to the management system, documented.
Reviews and resubmissions keep entries current. Collection is routine during operations, not a yearly campaign before the audit date.
Integration
KaitoSec connects the systems you already run and becomes the central layer above governance, continuity and data protection work.
Your local AI systems access your data through the MCP server: your own dashboards, analyses, patch priorities. You quickly see which systems need patching, and the data stays with you.
You connect existing systems with an API yourself or together with us. Once connected, they deliver continuously instead of via manual export.
Security tooling reports status and findings straight into the management system. Controls are checked against the live state instead of the last self-assessment.
Sovereignty
For KRITIS operators, the place of operation is not a footnote. You decide where the system runs and who has access.
Operations run sovereign in Germany. No dependency on jurisdictions your auditor will question.
On request, KaitoSec runs in your own infrastructure, behind your network boundary and under your operational control.
Every change and every approval is documented on the object. You can always see who decided what, and why.
FAQ
Bring your standard, your OT landscape and the next audit date. We show you on your concrete case how the data model ends the duplicated upkeep.