SCADA and control system security with zones under IEC 62443
Asset inventory and risk assessment under IEC 62443-3-2
More on thisIndustries / Dams
Monitor water infrastructure and secure remote access to control systems.
Consulting. Integration. Operations.

Built around your industry.
Your priorities
We map the control and telecontrol technology of your reservoirs, weirs, and pumping stations and divide the networks into protected zones according to IEC 62443.
Asset inventory and risk assessment under IEC 62443-3-2
More on thisData architecture with measuring point catalog and data diode
More on thisCrypto inventory with migration assessment per outstation
More on thisFrom strategy to implementation
Six fields of expertise. Explore the scope that fits your project.
Our approach
Control systems and programmable logic controllers at dams were built for closed networks and do not report attacks on their own. We inventory all components and connections, assess risks under IEC 62443-3-2 and divide the network into zones and conduits, such as control room, telecontrol, gate control and office IT. Industrial firewalls and data diodes govern every conduit, and passive sensors only read network traffic and detect anomalies without intervening in the controls. Events flow into a SIEM with reporting channels that fit KRITIS and NIS2.
A dam association separates gate control, control room and office network into their own zones; since then intrusion detection reports every new device in the control network to the on-call team.
Our approach
Weirs, pumping stations and flood retention basins are remote and are operated from a distance by the control room, on-call staff and maintenance contractors. We route all access through a central access point with multi-factor authentication, time-limited approval and recording of every session. We connect the sites through IPsec tunnels and mobile networks with a private APN, with a second transmission path for outages. Service providers reach only the systems they maintain, and we derive the requirements for them from IEC 62443-2-4.
A water association replaces permanently open VPN connections of its maintenance contractors with approvals per session; every intervention at an unmanned pumping station is recorded and assigned to a person.
Our approach
Water levels, pore water pressure, seepage, plumb line measurements and GNSS deformation data show how a dam behaves under changing loads. We merge these readings from data loggers, remote terminal units and measuring stations into a time series platform that receives values from the control systems through a data diode and cannot send commands back. The platform runs in your data center or in German data centers, built with Kubernetes and infrastructure as code. Limits, plausibility checks and dashboards are available to the control room immediately, and evaluations for the safety report under DIN 19700 are produced automatically.
A dam operator merges plumb line, water level and seepage measurements from several data loggers into one platform; the safety report draws its charts directly from the validated time series.
Our approach
Dam readings follow water level, season and aging, so fixed limits hide gradual changes. We train statistical models based on the HST approach and machine learning models that calculate the expected value for each measuring point and report deviations early. For inflow we combine precipitation forecasts from the German Weather Service, upstream gauges and snow data into forecasts that support reservoir management ahead of floods. The models give recommendations, decisions on releases and gates stay with the operations staff, and the classification under the EU AI Act is documented.
An operator detects rising pore water pressure at an unchanged water level before the next inspection; the warning names the affected measuring points and the expected value.
Our approach
Control commands to gates and pumps often travel unencrypted over IEC 60870-5-104 or Modbus, so an attacker in the network can read or inject commands. We secure the connections between control room and outstations with TLS under IEC 62351 or with IPsec and authenticate every peer with certificates from a dedicated PKI whose keys reside in hardware security modules. Firmware and configurations are signed before they reach a controller. Because telecontrol equipment stays in the field for decades, we set a roadmap for ML-KEM, ML-DSA and hash-based signatures aligned with the replacement cycles of the devices.
A hydropower operator switches the telecontrol connections of its run-of-river plants to TLS with device certificates; the issuing CA resides in the HSM, and firmware updates are verified before installation.
Our approach
Dams and hydraulic structures can count as critical infrastructure when they serve drinking water supply or power generation and reach the thresholds, and many operators also fall under NIS2. We bring together applicability check, risk management and an ISMS under ISO 27001 or BSI IT-Grundschutz, set up intrusion detection, reporting channels and incident response, and prepare the evidence for the BSI. For an emergency we plan and practice emergency operation with manual operation of the gates, recovery of the control systems from tested backups and clear responsibilities between control room, on-call staff and authorities.
A dam association practices a failure of its control systems after an attack; the gates are operated by hand, the report to the BSI goes out on time and recovery runs from offline backups.

Typical project situations
A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.
Illustrative situations, not customer references.
01 / Dams
Control system, telecontrol and office IT share one network, the KRITIS audit is due and intrusion detection is missing.
Passive inventory, risk assessment under IEC 62443-3-2, zones with industrial firewalls and data diode, intrusion detection connected to the SIEM.
Separate zones in operation, intrusion detection with reporting channels, complete evidence files for the audit.
02 / Dams
Maintenance contractors use permanently open VPN connections with shared passwords to unmanned pumping and drainage stations.
Central access point with FIDO2, approval per session and recording, site connectivity via private APN, requirements for service providers under IEC 62443-2-4.
Every intervention traceable and time-limited, no shared accounts, service providers only on their own systems.
03 / Dams
Readings sit in separate data loggers, anomalies only surface in the safety report, inflow forecasts are made by hand.
Time series platform behind a data diode, expectation models per measuring point, inflow forecast from weather and gauge data.
Early warnings with explanations, automated evaluations for the safety report, forecasts as a basis for reservoir management.
Working together
From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.
How we work
Facilities, networks, remote access, measurement data and obligations under KRITIS and NIS2
Zone model, remote access, PKI, data platform, emergency operation
Segmentation, access point, PKI and platform in maintenance windows
Monitoring, certificates, exercises, knowledge transfer
Before our first conversation
Start with a concrete challenge. These four questions help us find the right direction together.
Book a first consultationYour current challenge and the outcome you are aiming for.
An overview of sites, applications and interfaces.
Project dates, maintenance windows and known dependencies.
The right people from IT, security and operations.
Six modules from control system zoning to a post-quantum roadmap, planned, integrated and operated by OTOKO® for reservoirs, weirs and pumping stations. Every remote access is approved, recorded and limited to the systems in scope. The entire solution runs in German data centers.
Cybersecurity for dams and hydraulic structures protects the control and telecontrol systems that regulate water levels, gates, turbines and spillways, and keeps the facility manageable even during an attack. OTOKO® covers six modules: SCADA and control system security with zones under IEC 62443, hardened remote access for unmanned sites, sensor data platforms for structural and water level monitoring, anomaly detection and inflow forecasting with machine learning, encrypted control communication with HSM-backed keys and a post-quantum roadmap, and KRITIS and NIS2 compliance with incident response and emergency operation.
The difference from a pure IT security project lies in respect for facility operation and in evidence. Every measure is agreed with your operations staff, implemented in maintenance windows and documented as KRITIS, NIS2 and the supervisory authority require. Cryptography and hardware security modules are our core competence. Certificates and keys for control commands and remote access therefore sit in certified devices instead of on servers in the control room.
Cryptography and hardware security modules are our core competence. That is why certificates for telecontrol connections, signing keys for firmware and the post-quantum roadmap come from one source.
The entire solution runs in German data centers. This covers PKI, intrusion detection and sensor data platform, while the control systems themselves stay at the facility.
We work with operators of critical infrastructure and regulated industries. We know what the BSI, dam safety authorities and information security expect of hydraulic structures.
One team accompanies you from consulting to operations. OT security architects, cryptography specialists and data engineers remain your contacts, including during flood season.
Most operators do not fail on missing technology but on flat networks, grown remote access paths and controllers that run for decades without security updates.
01
Control system, remote terminal units, office computers and video surveillance share one network, so a compromised computer reaches every controller.
02
Manufacturers, maintenance contractors and on-call staff use their own access paths with shared passwords, and nobody sees who accessed which controller and when.
03
Water level, pore water pressure and deformation readings accumulate in separate data loggers, evaluations are made by hand and anomalies only surface in the safety report.
04
Manual operation of the gates is described but has never been practiced with a cyberattack as the trigger, and the reporting channels to the BSI and the supervisory authority are unclear.
| On-Premises | German cloud | Hyperscaler | |
|---|---|---|---|
| Data location | Facility and your data center, control data stays on site | Data centers in Germany under ISO 27001 for measurements, forecasts and PKI | Azure, AWS or Google Cloud only for data without control functions |
| Operation | Your team or OTOKO® as managed service inside your zones | OTOKO®, with evidence for the KRITIS audit and NIS2 | Shared, platform services by the provider |
| Tools | Industrial firewalls, data diodes, OT monitoring and HSMs at the facility | Hosted PKI with HSM, time series and forecasting platform, SIEM | Managed data and ML services, test environments |
| Suited for | Control systems, gate control, central remote access point | Sensor data platform, forecasts, intrusion detection for several facilities | Analyses, model training with historical measurement series, reports |
| Compliance | Full control, evidence from your ISMS | Processing agreement under GDPR, KRITIS contract, location Germany | Processing agreement, standard contractual clauses, no control path from the cloud into the control systems |
Collaboration
Project
Clearly scoped undertaking such as a zone model for a dam, a central remote access point or a sensor data platform with a defined result, milestones and acceptance.
Team reinforcement
OT security architects, cryptography specialists or data engineers work with your control systems, in your maintenance windows and under your approval processes.
Managed service
OTOKO® operates intrusion detection, remote access point, PKI or sensor data platform with agreed service levels, reports and the evidence that KRITIS and NIS2 require.
Five requirements shape cybersecurity at dams and hydraulic structures, shown here with what they demand and what OTOKO® delivers for them.
| Requirement | Demands | OTOKO® delivers |
|---|---|---|
| IEC 62443 | Zones and conduits, security levels per zone, the operator's security program and requirements for integrators, maintenance service providers and components | Risk assessment under IEC 62443-3-2, zone and conduit model, requirements for service providers under IEC 62443-2-4, evidence under IEC 62443-3-3 |
| KRITIS | Appropriate technical and organizational measures matching the current state of technology, systems for attack detection, regular evidence to the BSI and reporting of significant disruptions | Applicability check, intrusion detection in the control systems, reporting channels, evidence documentation and support during the audit |
| NIS2 | Risk management, supply chain security, staged reporting of significant incidents, registration and management accountability | Applicability check under the German implementation act, registration with the BSI, reporting processes, supplier requirements and reports for management |
| BSI IT-Grundschutz | Information security under BSI Standards 200-1 to 200-3 with modeling by modules, including industrial IT, and business continuity management under BSI Standard 200-4 | Modeling of the facilities with the modules for industrial IT and remote maintenance, IT-Grundschutz check, emergency operation concept under BSI Standard 200-4 |
| ISO 27001 | Information security management system with risk treatment, controls under Annex A, supplier management and regular internal and external audits | ISMS setup or extension to control systems and outstations, risk register, statement of applicability, operation of our services under ISO 27001 |
FAQ
15 answers about your industry, the project and ongoing operations.
The portfolio covers securing SCADA and control systems with zones under IEC 62443, hardened remote access for unmanned sites, sensor data platforms for structural and water level monitoring, anomaly detection and inflow forecasting, encrypted control communication with HSM-backed keys, and KRITIS and NIS2 compliance with emergency operation. Each module can be commissioned on its own or as a package, with operation in German data centers.
No, if they are planned together with operations. Inventory and intrusion detection work passively and only read network traffic without sending commands to the controllers. We implement firewalls, access point and encryption in agreed maintenance windows, test them beforehand with operations staff and maintenance contractors and keep a way back ready for every step.
Remote maintenance runs through a central access point with multi-factor authentication and is approved per session. Every session is recorded and can be terminated immediately, and service providers reach only the systems they actually maintain. We set down the requirements for manufacturers and maintenance contractors in the contract under IEC 62443-2-4.
That depends on purpose and size. Reservoirs for drinking water supply and hydropower plants can reach the KRITIS thresholds, and under the German NIS2 implementation act many water utilities and power producers count as important or essential entities. We check applicability for each facility and, where needed, deliver registration, risk management and reporting channels. We work with operators of critical infrastructure and regulated industries. That is why these checks are part of our daily work.
Not in our projects. The models calculate expected values and forecasts and send warnings and recommendations to the control room, while the operations staff decides on releases and gates according to the operating rules. The EU AI Act classifies AI systems as high-risk when they serve as safety components in the operation of water supply, so we document purpose, classification and limits of every model.
Remote terminal units and controllers often stay in the field for decades and will probably still be running when capable quantum computers can break today's algorithms. Certificates and firmware signatures based on RSA or elliptic curves must therefore be convertible to ML-KEM, ML-DSA or hash-based signatures at the next device replacement. The roadmap defines which devices and connections go first and ties the migration to renewals that are planned anyway.
Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.
A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.
OT security architect: Zone model, intrusion detection, IEC 62443. Cryptography specialist: PKI, HSM integration, PQC roadmap. Integration developer: Remote access point, site connectivity, measurement data interfaces. Data engineer: Time series platform, anomaly models, inflow forecasts. Compliance consultant: KRITIS, NIS2, IT-Grundschutz, emergency operation. Project lead: Milestones, maintenance windows, acceptance, reporting.
We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.
Facilities, networks, remote access, measurement data and obligations under KRITIS and NIS2 Asset inventory, crypto inventory, gap analysis, list of measures prioritized by impact on facility safety
Project: Clearly scoped undertaking such as a zone model for a dam, a central remote access point or a sensor data platform with a defined result, milestones and acceptance. Team reinforcement: OT security architects, cryptography specialists or data engineers work with your control systems, in your maintenance windows and under your approval processes. Managed service: OTOKO® operates intrusion detection, remote access point, PKI or sensor data platform with agreed service levels, reports and the evidence that KRITIS and NIS2 require.
Monitoring, certificates, exercises, knowledge transfer Intrusion detection in regular operation, certificate renewal, emergency exercises, stepwise handover
We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.
Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.
Dams
Let us examine together where the control systems and remote access of your hydraulic structures are exposed today.
Book a first consultation