Navigation

Get in touch
Logo
News

Industries / Dams

Resilient infrastructure. Secure control.

Monitor water infrastructure and secure remote access to control systems.

Consulting. Integration. Operations.

gray concrete dam under blue sky during daytime — illustrative image

Built around your industry.

  • Dam and water associations
  • Hydropower operators
  • Authorities and state agencies in hydraulic engineering
  • Municipal utilities with pumping stations

Your priorities

Understand the challenge. Shape the solution.

We map the control and telecontrol technology of your reservoirs, weirs, and pumping stations and divide the networks into protected zones according to IEC 62443.

01

SCADA and control system security with zones under IEC 62443

Asset inventory and risk assessment under IEC 62443-3-2

More on this
02

Sensor data platform for structural and water level monitoring

Data architecture with measuring point catalog and data diode

More on this
03

Encrypted control communication with HSM-backed keys and PQC roadmap

Crypto inventory with migration assessment per outstation

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01SCADA and control system security with zones under IEC 62443IEC 62443 · Microsoft Defender for IoT · OPSWAT MetaDefender Industrial Firewall

Our approach

Control systems and programmable logic controllers at dams were built for closed networks and do not report attacks on their own. We inventory all components and connections, assess risks under IEC 62443-3-2 and divide the network into zones and conduits, such as control room, telecontrol, gate control and office IT. Industrial firewalls and data diodes govern every conduit, and passive sensors only read network traffic and detect anomalies without intervening in the controls. Events flow into a SIEM with reporting channels that fit KRITIS and NIS2.

Full scope
  • Inventory of all control systems, PLCs, remote terminal units and network connections using passive capture instead of active scans
  • Risk assessment under IEC 62443-3-2 with a target security level per zone and conduit
  • Zone and conduit model with industrial firewalls between control room, telecontrol and gate control
  • Data diodes for readings that flow from the control systems into office IT and the data platform
  • Passive intrusion detection in the control network, connected to the SIEM and to reporting channels under KRITIS and NIS2

A dam association separates gate control, control room and office network into their own zones; since then intrusion detection reports every new device in the control network to the on-call team.

What you get

  • Asset inventory and risk assessment under IEC 62443-3-2
  • Zone and conduit model with firewall rule set
  • Intrusion detection in operation with documented reporting channels
Discuss this topic
02Hardened remote access for unmanned sitesOPSWAT MetaDefender OT Access · Privileged Access Management · FIDO2

Our approach

Weirs, pumping stations and flood retention basins are remote and are operated from a distance by the control room, on-call staff and maintenance contractors. We route all access through a central access point with multi-factor authentication, time-limited approval and recording of every session. We connect the sites through IPsec tunnels and mobile networks with a private APN, with a second transmission path for outages. Service providers reach only the systems they maintain, and we derive the requirements for them from IEC 62443-2-4.

Full scope
  • Central access point with jump server, multi-factor authentication via FIDO2 and approval per session
  • Privileged access management with session recording, four-eyes approval for switching operations and emergency accounts
  • Site connectivity via IPsec and mobile networks with a private APN, redundant transmission path for outages
  • Requirements for manufacturers and maintenance contractors under IEC 62443-2-4 with contractually defined access rights
  • Hardening of routers, gateways and remote terminal units at outstations with a documented configuration baseline

A water association replaces permanently open VPN connections of its maintenance contractors with approvals per session; every intervention at an unmanned pumping station is recorded and assigned to a person.

What you get

  • Remote access concept with roles, approval process and emergency access
  • Central access point with session recording in operation
  • Requirements catalog for service providers under IEC 62443-2-4
Discuss this topic
03Sensor data platform for structural and water level monitoringOPC UA · MQTT · TimescaleDB

Our approach

Water levels, pore water pressure, seepage, plumb line measurements and GNSS deformation data show how a dam behaves under changing loads. We merge these readings from data loggers, remote terminal units and measuring stations into a time series platform that receives values from the control systems through a data diode and cannot send commands back. The platform runs in your data center or in German data centers, built with Kubernetes and infrastructure as code. Limits, plausibility checks and dashboards are available to the control room immediately, and evaluations for the safety report under DIN 19700 are produced automatically.

Full scope
  • Connection of data loggers, remote terminal units and measuring stations via OPC UA, MQTT and IEC 60870-5-104
  • Time series platform with a data diode from the control systems, plausibility checks and flagging of data gaps
  • Build on Kubernetes with Terraform in your data center or in German data centers, with backup and recovery
  • Dashboards and limit alarms for control room, on-call staff and the supervisory authority
  • Automated evaluations and charts for the safety report under DIN 19700

A dam operator merges plumb line, water level and seepage measurements from several data loggers into one platform; the safety report draws its charts directly from the validated time series.

What you get

  • Data architecture with measuring point catalog and data diode
  • Time series platform with dashboards and limit alarms
  • Operations manual with backup and recovery concept
Discuss this topic
04Anomaly detection and inflow forecasting with machine learningPython · XGBoost · LSTM

Our approach

Dam readings follow water level, season and aging, so fixed limits hide gradual changes. We train statistical models based on the HST approach and machine learning models that calculate the expected value for each measuring point and report deviations early. For inflow we combine precipitation forecasts from the German Weather Service, upstream gauges and snow data into forecasts that support reservoir management ahead of floods. The models give recommendations, decisions on releases and gates stay with the operations staff, and the classification under the EU AI Act is documented.

Full scope
  • Preparation of measurement series with cleanup of data gaps, sensor replacements and calibrations
  • Expectation models per measuring point based on the HST approach and gradient boosting, validated against historical anomalies
  • Inflow forecast from DWD precipitation forecasts, upstream gauges and snow data with uncertainty bands
  • Explanation per warning with the readings that triggered it, for operations staff and supervisory authority
  • Model operations with versioning, drift monitoring and classification under the EU AI Act

An operator detects rising pore water pressure at an unchanged water level before the next inspection; the warning names the affected measuring points and the expected value.

What you get

  • Expectation models per measuring point with model card
  • Inflow forecast with uncertainty bands in the control room dashboard
  • Warning log with an explanation per anomaly
Discuss this topic
05Encrypted control communication with HSM-backed keys and PQC roadmapIEC 62351 · EverTrust PKI · Utimaco u.trust GP HSM Se-Series

Our approach

Control commands to gates and pumps often travel unencrypted over IEC 60870-5-104 or Modbus, so an attacker in the network can read or inject commands. We secure the connections between control room and outstations with TLS under IEC 62351 or with IPsec and authenticate every peer with certificates from a dedicated PKI whose keys reside in hardware security modules. Firmware and configurations are signed before they reach a controller. Because telecontrol equipment stays in the field for decades, we set a roadmap for ML-KEM, ML-DSA and hash-based signatures aligned with the replacement cycles of the devices.

Full scope
  • Crypto inventory across telecontrol protocols, VPN, certificates and firmware signatures of all outstations
  • TLS under IEC 62351-3 for IEC 60870-5-104, or IPsec tunnels where devices do not support TLS
  • Dedicated PKI with offline root CA and issuing CA in the HSM, certificate distribution via EST or SCEP
  • Signed firmware and configurations with signing keys in the HSM and verification before installation
  • PQC roadmap with hybrid methods, LMS for firmware signatures and priorities by device lifetime

A hydropower operator switches the telecontrol connections of its run-of-river plants to TLS with device certificates; the issuing CA resides in the HSM, and firmware updates are verified before installation.

What you get

  • Crypto inventory with migration assessment per outstation
  • PKI and HSM concept with recorded key ceremony
  • Post-quantum roadmap for telecontrol and firmware
Discuss this topic
06KRITIS and NIS2 compliance with incident response and emergency operationMicrosoft Sentinel · Microsoft Defender for IoT · Veeam

Our approach

Dams and hydraulic structures can count as critical infrastructure when they serve drinking water supply or power generation and reach the thresholds, and many operators also fall under NIS2. We bring together applicability check, risk management and an ISMS under ISO 27001 or BSI IT-Grundschutz, set up intrusion detection, reporting channels and incident response, and prepare the evidence for the BSI. For an emergency we plan and practice emergency operation with manual operation of the gates, recovery of the control systems from tested backups and clear responsibilities between control room, on-call staff and authorities.

Full scope
  • Applicability check against KRITIS thresholds and the NIS2 implementation act, registration with the BSI
  • ISMS under ISO 27001 or BSI IT-Grundschutz with the modules for industrial IT and remote maintenance
  • Security monitoring with SIEM, incident response plan and staged reporting under NIS2
  • Emergency operation concept under BSI Standard 200-4 with manual operation, offline backups and recovery of the control systems
  • Exercises with control room, on-call staff and authorities, plus evidence files for the KRITIS audit

A dam association practices a failure of its control systems after an attack; the gates are operated by hand, the report to the BSI goes out on time and recovery runs from offline backups.

What you get

  • Applicability analysis, ISMS documents and evidence files for the BSI
  • Incident response plan with reporting channels under NIS2
  • Emergency operation concept with exercise report
Discuss this topic
architectural photography of water dam — illustrative image
Dams

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Dams

Zone model at a dam association

Control system, telecontrol and office IT share one network, the KRITIS audit is due and intrusion detection is missing.

Solution

Passive inventory, risk assessment under IEC 62443-3-2, zones with industrial firewalls and data diode, intrusion detection connected to the SIEM.

Separate zones in operation, intrusion detection with reporting channels, complete evidence files for the audit.

Discuss this topic

02 / Dams

Remote access at a water utility with pumping stations

Maintenance contractors use permanently open VPN connections with shared passwords to unmanned pumping and drainage stations.

Solution

Central access point with FIDO2, approval per session and recording, site connectivity via private APN, requirements for service providers under IEC 62443-2-4.

Every intervention traceable and time-limited, no shared accounts, service providers only on their own systems.

Discuss this topic

03 / Dams

Measurement data and forecasts at a hydropower operator

Readings sit in separate data loggers, anomalies only surface in the safety report, inflow forecasts are made by hand.

Solution

Time series platform behind a data diode, expectation models per measuring point, inflow forecast from weather and gauge data.

Early warnings with explanations, automated evaluations for the safety report, forecasts as a basis for reservoir management.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Facilities, networks, remote access, measurement data and obligations under KRITIS and NIS2

    Asset inventory, crypto inventory, gap analysis, list of measures prioritized by impact on facility safety
  2. 02

    Concept

    Zone model, remote access, PKI, data platform, emergency operation

    Zone model, remote access and PKI concept, data architecture, emergency operation concept, operating model
  3. 03

    Implementation

    Segmentation, access point, PKI and platform in maintenance windows

    Separate zones, access point and PKI in operation, tests, documentation, approval per stage
  4. 04

    Operations

    Monitoring, certificates, exercises, knowledge transfer

    Intrusion detection in regular operation, certificate renewal, emergency exercises, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What is cybersecurity for dams and hydraulic structures?

Six modules from control system zoning to a post-quantum roadmap, planned, integrated and operated by OTOKO® for reservoirs, weirs and pumping stations. Every remote access is approved, recorded and limited to the systems in scope. The entire solution runs in German data centers.

Cybersecurity for dams and hydraulic structures protects the control and telecontrol systems that regulate water levels, gates, turbines and spillways, and keeps the facility manageable even during an attack. OTOKO® covers six modules: SCADA and control system security with zones under IEC 62443, hardened remote access for unmanned sites, sensor data platforms for structural and water level monitoring, anomaly detection and inflow forecasting with machine learning, encrypted control communication with HSM-backed keys and a post-quantum roadmap, and KRITIS and NIS2 compliance with incident response and emergency operation.

The difference from a pure IT security project lies in respect for facility operation and in evidence. Every measure is agreed with your operations staff, implemented in maintenance windows and documented as KRITIS, NIS2 and the supervisory authority require. Cryptography and hardware security modules are our core competence. Certificates and keys for control commands and remote access therefore sit in certified devices instead of on servers in the control room.

Why OTOKO® for dams and hydraulic structures

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. That is why certificates for telecontrol connections, signing keys for firmware and the post-quantum roadmap come from one source.

  • German data centers

    The entire solution runs in German data centers. This covers PKI, intrusion detection and sensor data platform, while the control systems themselves stay at the facility.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the BSI, dam safety authorities and information security expect of hydraulic structures.

  • One team through to operations

    One team accompanies you from consulting to operations. OT security architects, cryptography specialists and data engineers remain your contacts, including during flood season.

Delivery and details

Most operators do not fail on missing technology but on flat networks, grown remote access paths and controllers that run for decades without security updates.

One network from control room to gate

Control system, remote terminal units, office computers and video surveillance share one network, so a compromised computer reaches every controller.

Remote access without control

Manufacturers, maintenance contractors and on-call staff use their own access paths with shared passwords, and nobody sees who accessed which controller and when.

Measurement data in isolated systems

Water level, pore water pressure and deformation readings accumulate in separate data loggers, evaluations are made by hand and anomalies only surface in the safety report.

Emergency operation only on paper

Manual operation of the gates is described but has never been practiced with a cyberattack as the trigger, and the reporting channels to the BSI and the supervisory authority are unclear.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationFacility and your data center, control data stays on siteData centers in Germany under ISO 27001 for measurements, forecasts and PKIAzure, AWS or Google Cloud only for data without control functions
OperationYour team or OTOKO® as managed service inside your zonesOTOKO®, with evidence for the KRITIS audit and NIS2Shared, platform services by the provider
ToolsIndustrial firewalls, data diodes, OT monitoring and HSMs at the facilityHosted PKI with HSM, time series and forecasting platform, SIEMManaged data and ML services, test environments
Suited forControl systems, gate control, central remote access pointSensor data platform, forecasts, intrusion detection for several facilitiesAnalyses, model training with historical measurement series, reports
ComplianceFull control, evidence from your ISMSProcessing agreement under GDPR, KRITIS contract, location GermanyProcessing agreement, standard contractual clauses, no control path from the cloud into the control systems

Collaboration

Project

Clearly scoped undertaking such as a zone model for a dam, a central remote access point or a sensor data platform with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for KRITIS preparation, remote access redesign and measurement data integration

Team reinforcement

OT security architects, cryptography specialists or data engineers work with your control systems, in your maintenance windows and under your approval processes.

  • Onboarding into facilities, operating rules and on-site safety rules
  • Scalable by project progress and flood season
  • Suited for operators with in-house control engineering and capacity gaps

Managed service

OTOKO® operates intrusion detection, remote access point, PKI or sensor data platform with agreed service levels, reports and the evidence that KRITIS and NIS2 require.

  • Monitoring, certificate renewal, updates and on-call support
  • Support during incidents and reports to the BSI
  • Suited for associations and utilities without their own OT security team

Five requirements shape cybersecurity at dams and hydraulic structures, shown here with what they demand and what OTOKO® delivers for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
IEC 62443Zones and conduits, security levels per zone, the operator's security program and requirements for integrators, maintenance service providers and componentsRisk assessment under IEC 62443-3-2, zone and conduit model, requirements for service providers under IEC 62443-2-4, evidence under IEC 62443-3-3
KRITISAppropriate technical and organizational measures matching the current state of technology, systems for attack detection, regular evidence to the BSI and reporting of significant disruptionsApplicability check, intrusion detection in the control systems, reporting channels, evidence documentation and support during the audit
NIS2Risk management, supply chain security, staged reporting of significant incidents, registration and management accountabilityApplicability check under the German implementation act, registration with the BSI, reporting processes, supplier requirements and reports for management
BSI IT-GrundschutzInformation security under BSI Standards 200-1 to 200-3 with modeling by modules, including industrial IT, and business continuity management under BSI Standard 200-4Modeling of the facilities with the modules for industrial IT and remote maintenance, IT-Grundschutz check, emergency operation concept under BSI Standard 200-4
ISO 27001Information security management system with risk treatment, controls under Annex A, supplier management and regular internal and external auditsISMS setup or extension to control systems and outstations, risk register, statement of applicability, operation of our services under ISO 27001

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which cybersecurity services for dams and hydraulic structures does OTOKO® offer?

The portfolio covers securing SCADA and control systems with zones under IEC 62443, hardened remote access for unmanned sites, sensor data platforms for structural and water level monitoring, anomaly detection and inflow forecasting, encrypted control communication with HSM-backed keys, and KRITIS and NIS2 compliance with emergency operation. Each module can be commissioned on its own or as a package, with operation in German data centers.

Do security measures affect ongoing facility operation?

No, if they are planned together with operations. Inventory and intrusion detection work passively and only read network traffic without sending commands to the controllers. We implement firewalls, access point and encryption in agreed maintenance windows, test them beforehand with operations staff and maintenance contractors and keep a way back ready for every step.

How do we secure remote maintenance by manufacturers and maintenance contractors?

Remote maintenance runs through a central access point with multi-factor authentication and is approved per session. Every session is recorded and can be terminated immediately, and service providers reach only the systems they actually maintain. We set down the requirements for manufacturers and maintenance contractors in the contract under IEC 62443-2-4.

Does our dam fall under KRITIS or NIS2?

That depends on purpose and size. Reservoirs for drinking water supply and hydropower plants can reach the KRITIS thresholds, and under the German NIS2 implementation act many water utilities and power producers count as important or essential entities. We check applicability for each facility and, where needed, deliver registration, risk management and reporting channels. We work with operators of critical infrastructure and regulated industries. That is why these checks are part of our daily work.

May anomaly detection and forecasting models intervene in the controls?

Not in our projects. The models calculate expected values and forecasts and send warnings and recommendations to the control room, while the operations staff decides on releases and gates according to the operating rules. The EU AI Act classifies AI systems as high-risk when they serve as safety components in the operation of water supply, so we document purpose, classification and limits of every model.

Why does telecontrol equipment need a post-quantum roadmap today?

Remote terminal units and controllers often stay in the field for decades and will probably still be running when capable quantum computers can break today's algorithms. Certificates and firmware signatures based on RSA or elliptic curves must therefore be convertible to ML-KEM, ML-DSA or hash-based signatures at the next device replacement. The roadmap defines which devices and connections go first and ties the migration to renewals that are planned anyway.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

OT security architect: Zone model, intrusion detection, IEC 62443. Cryptography specialist: PKI, HSM integration, PQC roadmap. Integration developer: Remote access point, site connectivity, measurement data interfaces. Data engineer: Time series platform, anomaly models, inflow forecasts. Compliance consultant: KRITIS, NIS2, IT-Grundschutz, emergency operation. Project lead: Milestones, maintenance windows, acceptance, reporting.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Facilities, networks, remote access, measurement data and obligations under KRITIS and NIS2 Asset inventory, crypto inventory, gap analysis, list of measures prioritized by impact on facility safety

Operations & development4 questions

How can we work together?

Project: Clearly scoped undertaking such as a zone model for a dam, a central remote access point or a sensor data platform with a defined result, milestones and acceptance. Team reinforcement: OT security architects, cryptography specialists or data engineers work with your control systems, in your maintenance windows and under your approval processes. Managed service: OTOKO® operates intrusion detection, remote access point, PKI or sensor data platform with agreed service levels, reports and the evidence that KRITIS and NIS2 require.

What happens at handover to operations?

Monitoring, certificates, exercises, knowledge transfer Intrusion detection in regular operation, certificate renewal, emergency exercises, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Dams

Let's discuss your next step.

Let us examine together where the control systems and remote access of your hydraulic structures are exposed today.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.