Skip to content

KRITIS · Energy

NIS2, KRITIS evidence and the IT security catalogue in one system

KaitoSec brings information security, business continuity and data protection for energy utilities together in one data model. You work to ISO 27001 or BSI IT-Grundschutz, connect the OT landscape through integrations and produce the evidence records under Section 39 BSIG from live operations.

At a glance

Implementation paths
ISO 27001 · BSI
Visibility
IT + OT
Operations
DE · on-prem (or cloud)

The situation

Four rulebooks, the same assets, the same auditor

Each rulebook on its own is manageable. What gets expensive is the duplicated upkeep: the same assets, processes and risks, documented four times and kept current four times.

NIS2

Risk management and reporting duties

NIS2 demands state-of-the-art measures, incident reporting on short deadlines and personal accountability of executive management. Implementation has to be demonstrable, not asserted.

§ 31, § 39 BSIG

Attack detection and evidence every three years

Operators of critical installations have to run attack detection systems that evaluate operating parameters continuously and automatically, and evidence that every three years through security audits, inspections or certifications. What is required is current documentation, not a snapshot from the week before the date.

§ 11 EnWG

IT security catalogue with mandatory certification

For grid operators, the Bundesnetzagentur's IT security catalogue requires a certified ISMS based on ISO 27001. The standard path is often set; the NIS2 duties come on top.

Operations

Resilience counts, not the certificate

Security of supply demands continuity: backup management, crisis organisation and recovery are among the NIS2 minimum measures and part of the audit expectation. A certificate keeps no plant running.

The difference

One data model instead of four binders

You maintain every requirement, every asset and every risk once. KaitoSec maps them to NIS2, ISO 27001, BSI IT-Grundschutz and the KRITIS evidence. Regulatory ballast shrinks because overlaps collapse instead of adding up.

Common today
With KaitoSec
One catalogue per rulebook, maintained in Excel and Word.
One requirement, mapped to NIS2, ISO 27001, BSI IT-Grundschutz and the KRITIS evidence.
The OT landscape lives in a separate list kept by control engineering.
IT and OT sit in the same model as assets with protection needs and dependencies.
BCM is a Word emergency handbook next to the ISMS.
BIA, recovery plans and exercises work on the same assets and processes.
The evidence sprint starts before the KRITIS audit.
Audit documentation accumulates during operations, every change with an audit trail.
Contributions from the group arrive by circular e-mail.
AI interviews and the accountability portal collect contributions in structure.
Every catalogue update becomes a new project.
Updated catalogues flow into the existing mapping; you work through the delta.

IT and OT

The OT landscape belongs in the management system

Grid control, substations and telecontrol carry the same protection needs as any server estate. KaitoSec models both in one structural model.

Assets instead of island lists

Control rooms, substations, telecontrol and business applications sit in the model as assets, with owners, protection needs and dependencies between IT and OT.

Protection needs with inheritance

Protection needs are assessed on the process and inherited along dependencies to installations and systems. The assessment stays consistent as the landscape changes.

Live state through integrations

Connections to EDR and XDR systems feed inventory and state data into the platform. What your systems already know, nobody types in again.

Resilience

BCMS built in, not bolted on

NIS2 explicitly counts continuity among the minimum measures: backup management, crisis management, recovery. In KaitoSec, the BCMS is part of the same system, not a second tool.

BIA on real processes

The business impact analysis uses the same processes and assets as the ISMS. Recovery times and dependencies live on the object, not in a document's annex.

Plans that match the estate

Emergency and recovery plans reference the assets directly. When an installation changes, you see which plan has gone stale.

Exercises with evidence

Exercises are planned, run and documented. Findings return to the management system as measures and are demonstrable at the next audit.

Data collection

Contributions from the group without chasing people

Energy utilities spread accountability across entities: grid, generation, retail, shareholdings. KaitoSec collects the information where it lives.

AI interviews

Subject-matter owners answer questions in a guided interview. Answers land structured on the requirement and the asset, not as free text in an inbox.

Accountability portal

Tasks reach owners as assigned work items with deadline and context. Feedback and evidence return to the management system, documented.

Continuous, not annual

Reviews and resubmissions keep entries current. Collection is routine during operations, not a yearly campaign before the audit date.

Integration

The orchestration layer for governance, continuity and data protection

KaitoSec connects the systems you already run and becomes the central layer above governance, continuity and data protection work.

MCP server for local AI

Your local AI systems access your data through the MCP server: your own dashboards, analyses, patch priorities. You quickly see which systems need patching, and the data stays with you.

Open API for legacy systems

You connect existing systems with an API yourself or together with us. Once connected, they deliver continuously instead of via manual export.

EDR and XDR connected

Security tooling reports status and findings straight into the management system. Controls are checked against the live state instead of the last self-assessment.

Sovereignty

Hosted in Germany, on-premise capable

For KRITIS operators, the place of operation is not a footnote. You decide where the system runs and who has access.

Hosting in Germany

Operations run sovereign in Germany. No dependency on jurisdictions your auditor will question.

On-premise operation

On request, KaitoSec runs in your own infrastructure, behind your network boundary and under your operational control.

Data sovereignty with audit trail

Every change and every approval is documented on the object. You can always see who decided what, and why.

FAQ

Frequent questions from energy utilities

We work to BSI IT-Grundschutz, not ISO 27001. Does that fit?
Yes. KaitoSec ships both paths with the corresponding catalogues, and the NIS2 requirements are mapped to both. The choice of standard stays with you and your auditor.
How does our OT landscape get into the system?
Through the structural model: control technology, substations and telecontrol become assets with protection needs and dependencies. Inventory and state data arrive through integrations and the open API, including from legacy systems with their own interface.
Does KaitoSec support the evidence records under Section 39 BSIG?
The evidence records accumulate from live operations: control status, risk treatment and documents per requirement, with an audit trail. The auditing body and the approval stay with you.
Does KaitoSec run on-premise?
Yes. You choose between sovereign operation in Germany and installation in your own infrastructure.

One system for NIS2, KRITIS evidence and operations.

Bring your standard, your OT landscape and the next audit date. We show you on your concrete case how the data model ends the duplicated upkeep.