Our recommendations
1. Securing access to resources
Remote access is often the easiest way for attackers to penetrate a network. It is therefore crucial to protect the infrastructure using endpoint security for secure remote connections, careful password management and network firewalls. Access rights should be tailored to each user’s role, with staff granted only the rights necessary for their specific tasks. Implementing multi-factor authentication provides an additional layer of security, making it more difficult for attackers to gain access. These measures are fundamental components of the zero-trust principle, which states that organisations should not automatically regard any network traffic as trustworthy, whether internal or external. Instead, every access attempt must be strictly verified and authorised, regardless of whether it originates from within or outside the network.
2. Transparent visualisation of all network resources
It has proven effective to visualise network structures and identify all devices within them, as well as to identify, analyse and secure the connections between networks, particularly those to untrusted networks such as the internet. If not all devices on the network are visible, it becomes impossible to protect or segment the network adequately. By continuously maintaining an inventory of all network resources and monitoring them, security teams gain precise insight into their devices, connections, communications and protocols.
3. An integrated security approach to IT and OT networks
Taking a joint approach to both system environments can improve resilience and reduce blind spots and security risks in highly interconnected industrial control systems. A consolidated security strategy that encompasses both IT and OT security infrastructure lays the foundation for this. In addition, close communication between the relevant specialists is essential.
4. Establishment of a monitoring control centre: Security Operations Centre
A Security Operations Centre (SOC) enables KRITIS operators to implement a comprehensive, integrated security concept for monitoring their IT and OT infrastructure. Alternatively, a SOC can also be procured from a service provider on an ‘as-a-service’ basis. This monitoring centre brings together technologies, processes and subject matter experts responsible for analysing and maintaining a company’s cyber, data and information security. Within the SOC, security analysts monitor real-time log data from the company’s networks, servers, endpoints and other digital resources. In doing so, they utilise intelligent, AI-based automation to detect and assess anomalies. The experts in the SOC identify potential threats around the clock, prioritise them and report any incidents and anomalies to the company’s decision-makers or to dedicated incident response teams.
5. Conducting regular security training
Human error remains one of the greatest vulnerabilities in cyber security. Phishing via email or telephone is one of the main methods of attack used by cybercriminals. It is therefore particularly important that security officers – especially in critical infrastructure organisations – use training and tests to raise staff awareness of common attacks and the social engineering tactics employed by cybercriminals. In doing so, it is important to address all staff in a manner appropriate to their target group and to impart knowledge in a way that ensures long-term retention
6. Regular data backups
If a company falls victim to ransomware, those in charge can often limit the damage caused by using existing backups. Regular, ideally daily, data backups strengthen resilience and help to restore operations as quickly as possible in the event of an attack. The tried-and-tested 3-2-1 strategy is recommended to ensure reliable data recovery and to guarantee that backup copies are available when needed. This approach involves creating three copies of the data, stored on two different storage media, with one copy kept at an off-site location. In addition, organisations should have a written contingency plan and carry out regular recovery drills to identify potential weaknesses in their security strategy and prepare staff for possible security incidents
Conclusion
By implementing appropriate technical and organisational measures, you can significantly improve your cyber resilience. Robust cyber resilience is not only essential for KRITIS operators and their suppliers today, but is also a legal requirement. KRITIS organisations must meet specific security criteria and deploy appropriate technologies, as determined by the requirements of, amongst others, the EU General Data Protection Regulation, NIS 2 and the BSI Act. Consequently, KRITIS operators are obliged to demonstrate that they have implemented security measures to prevent disruptions to availability and to ensure the integrity, authenticity and confidentiality of information technology systems, components or processes.