Energy as Critical Infrastructure Under NIS2
Energy and utilities are classified as essential entities under NIS2 — the highest regulatory tier. This includes electricity generation, transmission, and distribution; natural gas; oil; district heating; and hydrogen. The sector faces a unique challenge: operational technology (OT) systems that were designed decades before cybersecurity was a concern are now connected to IT networks and increasingly managed by AI-driven optimisation systems.
NIS2 Requirements for Energy Infrastructure
OT/IT Convergence Security
- Network segmentation: Air-gapped or DMZ-separated OT networks. Industrial protocols (Modbus, DNP3, IEC 61850) must not be directly accessible from IT networks.
- Monitoring across boundaries: Security monitoring must cover both IT and OT environments — different tools, different protocols, unified visibility
- Asset inventory: Complete inventory of OT devices (PLCs, RTUs, HMIs, SCADA servers) — many organisations don't know what's on their OT network
- Patch management for OT: OT patching is fundamentally different from IT — systems can't be rebooted during operations. Compensating controls (network segmentation, monitoring) for unpatched systems.
- Remote access security: Vendor and engineer remote access to OT must use jump servers, MFA, session recording, and time-limited access
Smart Grid & AI Security
- AI-driven grid optimisation: ML models that predict load, optimise distribution, and manage renewable integration — these systems have safety implications if compromised
- Smart meter infrastructure: Millions of IoT devices collecting consumption data — supply chain risk, data privacy, and physical security
- Demand response systems: AI controlling load shedding and demand response — adversarial manipulation could cause grid instability
- Weather prediction models: AI forecasting for renewable energy production — data poisoning could cause grid planning failures
Incident Reporting for Energy
Energy sector incidents have cascading effects. NIS2 reporting requirements:
- 24-hour early warning: Notify CSIRT/competent authority within 24 hours of significant incident
- 72-hour notification: Full incident notification with initial assessment, severity, and cross-border impact
- Final report within 1 month: Root cause, mitigation measures, cross-border impact assessment
- Energy-specific consideration: Cross-border impact is common in interconnected electricity grids — incident in one country can affect neighbours
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Implementation Priorities
- OT asset discovery — You can't protect what you don't know about. Deploy passive OT network monitoring (Claroty, Nozomi, Dragos).
- Network segmentation review — Verify IT/OT boundary controls. Implement industrial DMZs per IEC 62443 zones and conduits model.
- Unified SOC — Security operations covering both IT and OT. Requires OT-specific threat intelligence and analysts with industrial control system knowledge.
- Incident response for OT — OT incident response is different: you can't just "isolate and reimage." Response must maintain physical safety and operational continuity.
- Supply chain assessment — Assess OT vendors (Siemens, ABB, Schneider, GE Vernova) against NIS2 supply chain requirements
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton