04.05.2023
Blog
Regulatory
Cyber Security

Stricter IT Security Act to come into force in May 2023

What exactly does the new IT Security Act 2.0 mean, not only for KRITIS operators: what requirements need to be implemented, what technologies are necessary, and what measures must be demonstrated? Our subsidiary, RADAR Cyber Security, summarises key information in this guest article.

Lothar Hänsler
Operations Officer

In principle, reporting and documentation requirements for operators of critical infrastructure are nothing new. Companies and organisations that provide essential services to the public have been required since 2019 to demonstrate to the Federal Office for Information Security (BSI) that they are equipped to defend against cyber-attacks in accordance with the ‘state of the art’.

The IT Security Act 2.0 has been in force for two years now. The transitional period set out therein for the obligation to demonstrate attack detection expired on 1 May 2023. This takes the regulation to a new level, as the second version of the IT Security Act (IT-SiG for short) significantly tightens the requirements:

  1. The scope of organisations classified as critical infrastructure has expanded significantly: the regulation applies not only to KRITIS operators themselves, but also to their suppliers.
  2. Companies of ‘particular public interest’ are now also included: for example, defence contractors or companies of ‘particular economic significance’ must implement certain IT security measures.
  3. The state and regulatory authorities are granted greater powers: for example, the BSI can itself classify companies as KRITIS.

What exactly does the IT Security Act 2.0 now require?

KRITIS operators must have implemented systems and processes for attack detection by the deadline of 1 May 2023 at the latest; these now form an explicit part of the technical and organisational security measures. These include, for example, a Security Information and Event Management (SIEM) system or a Security Operations Centre (SOC). With the defence centre – also known as a ‘Cyber Defence Centre’ (CDC) – KRITIS operators can implement a comprehensive security concept for their IT and OT infrastructure. This centre combines technologies and processes with the expertise of the specialists responsible for monitoring, analysing and maintaining a company’s information security.

Furthermore, the organisations referred to in the second point – those of particular public interest – are obliged to submit a self-declaration on a regular basis: they must detail which IT security certifications have been carried out over the past two years and how they have secured their IT systems.

Should any incidents occur, the BSI must be informed immediately. The authority uses these reports to support those affected and to warn other organisations of potential risks. Failure to report incidents or a lack of registration may result in substantial fines for those concerned. Furthermore, if an inspection reveals inadequate implementation of attack detection, fines of up to two million euros may be imposed – in the case of deliberate breaches, a fine of up to 20 million euros may even be incurred. These are severe penalties; after all, supply bottlenecks or even complete system failures would have dramatic consequences for the state, the economy and society.

It is therefore all the more important that the organisations in question use integrated solutions that comply with the IT Security Act 2.0, the BSI Act and the ISO 27000 standards on information security. In addition to providing evidence of security audits or certifications such as ISO 27001, the use of European security technologies is recommended in order to fully comply with legal requirements such as the General Data Protection Regulation (GDPR) and the BSI Act.

Legislative initiatives such as the IT Security Act 2.0 demonstrate that policymakers have recognised the urgency of the resilience challenge in today’s digital age. Organisations have a great deal of work to do, and this will continue to be the case after 1 May 2023.

Lothar Hänsler
Operations Officer

Lothar Hänsler ist Operations Officer bei der Materna Tochter RADAR Cyber Security. Er hält regelmäßig Vorträge zu den Themen Security Operations Center, Threat Intelligence und Angriffserkennung. RADAR Cyber Security betreibt eines der größten Cyber Defense Center Europas, basierend auf einer eigenentwickelten Cyber-Detection-Platform Kerntechnologie zum Schutz der Infrastruktur von Marktführern in allen Branchen sowie im öffentlichen Dienst.