Navigation

Get in touch
Logo
News

Industries / Energy

Secure networks. Reliable supply.

Protect grid control systems and securely integrate smart meter gateways.

Consulting. Integration. Operations.

three white windmill during daytime — illustrative image

Built around your industry.

  • Distribution and transmission system operators
  • Municipal utilities and metering point operators
  • Generators and direct marketers
  • Gas network and district heating operators

Your priorities

Understand the challenge. Shape the solution.

We protect grid control systems, generation assets and intelligent metering systems with security architecture based on IEC 62443, hardware security modules and PKI for smart meter gateways, and controlled interfaces between control room and corporate IT.

01

Grid control systems and plants under IEC 62443

Zone model with risk assessment and security level per zone

More on this
02

KRITIS evidence, ISMS under ISO 27019 and intrusion detection

ISMS documentation with risk analysis and action plan

More on this
03

Forecasting load and generation with data platforms

Data platform connected to control system, metering systems and weather data

More on this

From strategy to implementation

Six service modules

Six fields of expertise. Explore the scope that fits your project.

01Grid control systems and plants under IEC 62443IEC 62443 · IEC 62351 · IEC 60870-5-104

Our approach

Control systems and telecontrol were built for isolated networks and today connect to office IT, service providers and distributed plants. We record plants and connections, divide control center, substations and corporate IT into zones under IEC 62443-3-2 and define a security level and the permitted conduits for each zone. We implement hardening, segmentation and protocol security under IEC 62351 in maintenance windows without touching the approved configuration of the plant. Intrusion detection reads IEC 60870-5-104 and IEC 61850 so that it can tell operator error from attack in the control systems.

Full scope
  • Asset inventory of the control systems and zone model under IEC 62443-3-2 with security level and risk assessment per zone
  • Segmentation between process network, control center and corporate IT with conduits, DMZ and industrial firewall
  • Hardening of control system, HMI, telecontrol devices and engineering workstations under IEC 62443-3-3 and the BSI ICS Security Compendium
  • Securing IEC 60870-5-104 and IEC 61850 under IEC 62351 with TLS, certificates and role-based access
  • Intrusion detection for control system protocols with passive network monitoring, connected to SIEM and reporting process

A distribution system operator separates control center, substations and office IT into zones under IEC 62443; telecontrol connections run through secured conduits, and intrusion detection reads the control system protocols.

What you get

  • Zone model with risk assessment and security level per zone
  • Segmented and hardened control systems with test evidence
  • Operations manual for patches and changes in maintenance windows
Discuss this topic
02Smart meter gateway PKI and HSMs under BSI TR-03109BSI TR-03109 · Smart metering PKI · Utimaco u.trust GP HSM Se-Series

Our approach

Intelligent metering systems communicate only over TLS with certificates from the smart metering PKI, whose structure the technical guideline BSI TR-03109 defines. We plan sub-CAs for gateway administration and market participants, choose vendor-neutrally between Utimaco u.trust GP HSM, Thales Luna 7 and Entrust nShield 5c and conduct key ceremonies with roles, quorums and records. Certificates for gateways, control boxes and the CLS channel under section 14a EnWG receive a lifecycle with renewal, revocation and monitoring. The evidence for the ISMS certification of the gateway administrator is produced in the same project.

Full scope
  • PKI architecture with sub-CA under BSI TR-03109-4, certificate profiles and registration under the root of the smart metering PKI
  • HSM selection and integration for sub-CA keys, key ceremonies with roles, quorums, witnesses and record templates
  • Connection of gateway administration and external market participants over TLS with certificates from the PKI
  • Certificate lifecycle with renewal, revocation and monitoring for gateways, control boxes and CLS channel under section 14a EnWG
  • Evidence for the ISMS certification of the gateway administrator under ISO 27001 and BSI TR-03109-6

A metering point operator brings its sub-CA for smart meter gateways in-house from a service provider; the keys are generated in a recorded ceremony inside the HSM, and gateway administration and market participants receive certificates from its own PKI.

What you get

  • PKI concept with certificate profiles under BSI TR-03109-4
  • HSM-protected sub-CA with recorded key ceremonies
  • Operations manual for certificate lifecycle and revocation
Discuss this topic
03KRITIS evidence, ISMS under ISO 27019 and intrusion detectionISO 27019 · IT security catalog under section 11 EnWG · Microsoft Sentinel

Our approach

Grid operators need a certified ISMS under the IT security catalog pursuant to section 11 EnWG, and KRITIS operators additionally need intrusion detection systems and regular evidence to the BSI. NIS2 extends registration, risk management and reporting obligations to further energy companies. We build the ISMS under ISO 27001 with the ISO 27019 extensions for process control or extend its scope to grid control. We set up intrusion detection along the BSI guidance, with logging, detection and response for IT and control systems. Reporting processes to the BSI and the Federal Network Agency are rehearsed with templates and deadlines before the audit takes place.

Full scope
  • Gap analysis against the IT security catalog under section 11 EnWG, ISO 27001 and ISO 27019 with grid control in scope
  • ISMS setup or extension with network structure plan, risk analysis, action plan and certification preparation
  • Intrusion detection system along the BSI guidance with logging, detection and response for IT and control systems
  • Reporting processes for the BSI and the Federal Network Agency with the stages and deadlines of the BSI Act and NIS2, exercises with records
  • Audit documents with the implementation level of intrusion detection and support during the KRITIS audit

A municipal utility merges IT and control systems into one ISMS under ISO 27019 and evidences the implementation level of its intrusion detection before the next KRITIS audit date.

What you get

  • ISMS documentation with risk analysis and action plan
  • Intrusion detection in operation with evidence of implementation level
  • Reporting process with templates and exercise records
Discuss this topic
04Remote maintenance and connection of distributed plantsIEC 60870-5-104 · IEC 61850 · OPC UA

Our approach

Photovoltaics, wind farms, storage and combined heat and power plants deliver measurements and accept control commands, often over public networks and components from many vendors. We connect these plants to control system, direct marketers and Redispatch 2.0 via IEC 60870-5-104, IEC 61850, Modbus TCP and OPC UA, with data diodes and protocol gateways at the transitions. Remote maintenance by vendors and service providers runs through a central access point with jump server, multi-factor authentication, time-limited approval and session recording. Edge devices in substations and parks receive hardened operating systems, certificates and remote updates with signed firmware.

Full scope
  • Interface catalog for generation plants, storage and control boxes with IEC 60870-5-104, IEC 61850, Modbus TCP and OPC UA
  • Remote maintenance access with jump server, multi-factor authentication, session recording and time-limited approvals per service provider
  • Data diodes and protocol gateways for transitions from process network to control center and corporate IT with OPSWAT MetaDefender NetWall
  • Edge devices in substations and parks with hardened operating system, certificates and signed remote updates
  • Connection to control system, direct marketers and Redispatch 2.0 with test and record per interface

A wind farm operator replaces vendor modem access with a central remote maintenance access point and jump server; every session is assigned to a service provider, time-limited and recorded.

What you get

  • Interface catalog with data contracts per plant
  • Remote maintenance concept with roles, approvals and session log
  • Tested transitions with data diodes and protocol gateways
Discuss this topic
05Forecasting load and generation with data platformsApache Kafka · Apache Spark · TimescaleDB

Our approach

Feed-in from photovoltaics and wind, heat pumps and charging infrastructure make load and generation harder to plan, and deviations cost balancing energy and redispatch. We build data platforms that combine control system history, smart meter gateway readings, weather data from the German Meteorological Service and market data, and train forecasting models on them with uncertainty bands per grid area and local substation. The models run outside the control systems, and their forecasts reach grid operations, balancing group management and trading as a proposal. Versioning, monitoring of forecast quality, retraining and classification under the EU AI Act are part of operations.

Full scope
  • Data platform connected to control system history, gateway administration, weather data from the German Meteorological Service and market data
  • Forecasting models for load, photovoltaics and wind with uncertainty bands for balancing group, redispatch and trading
  • Grid state estimation and congestion forecast per grid area from measurements and forecasts for grid operations
  • Model operations with versioning, monitoring of forecast quality, retraining and classification under the EU AI Act
  • Data protection concept for smart meter gateway readings with pseudonymization under GDPR and the Metering Point Operation Act

A distribution system operator forecasts photovoltaic feed-in per local substation from weather and metering data; grid operations sees congestion the day before instead of during the fault.

What you get

  • Data platform connected to control system, metering systems and weather data
  • Versioned forecasting models with quality report and model card
  • Operations manual for model operations and retraining
Discuss this topic
06Post-quantum readiness for long-lived assetsML-KEM (FIPS 203) · ML-DSA (FIPS 204) · LMS and XMSS

Our approach

Capable quantum computers will break RSA and elliptic curves, on which telecontrol connections, firmware signatures and the smart metering PKI rely today, and telecontrol devices, gateways and substation equipment stay in the field far longer than office IT. We inventory cryptographic algorithms, keys and certificates across control systems, PKI and plants, rate them by device lifetime and plan the migration to ML-KEM and ML-DSA in stages. Firmware signatures move first to hash-based schemes such as LMS and XMSS, while HSM firmware and PKI follow with hybrid certificates in line with BSI TR-02102. The roadmap ties every step to rollout and renewal cycles in the grid.

Full scope
  • Crypto inventory across control systems, telecontrol connections, smart metering PKI, firmware signatures and TLS endpoints with rating by lifetime
  • Review of HSMs and PKI software for ML-KEM, ML-DSA and hash-based signatures with LMS and XMSS for firmware
  • Crypto agility in certificate management and protocol gateways so that algorithms can change without replacing field devices
  • Hybrid certificates and migration plan for root CA and sub-CA in line with BSI TR-02102
  • Roadmap in stages, tied to rollout cycles for gateways, control boxes and telecontrol devices

A gas network operator inventories the cryptography in its telecontrol systems and PKI; firmware signatures move first to hash-based schemes, and the sub-CA follows with hybrid certificates at the next device replacement.

What you get

  • Crypto inventory with risk rating by asset lifetime
  • Migration roadmap for PKI, HSMs and field devices
  • Crypto agility concept for certificate management and gateways
Discuss this topic
a person working on a solar panel — illustrative image
Energy

Typical project situations

Where change becomes tangible.

A specific challenge is often the starting point. These examples connect a typical situation with a possible approach and the intended result.

Illustrative situations, not customer references.

01 / Energy

Zone model at a distribution system operator

Control center, substations and office IT on one network, firewall rules from commissioning, KRITIS audit date announced.

Solution

Asset inventory, zones and conduits under IEC 62443-3-2, hardening in maintenance windows, intrusion detection with control system protocols in the SIEM.

Separated zones in operation, intrusion detection with proven implementation level, audit documents ready before the date.

Discuss this topic

02 / Energy

Sub-CA at a metering point operator

Smart meter rollout under way, certificates come from a service provider without transparency, the operator wants the keys of its own sub-CA in-house.

Solution

PKI concept under BSI TR-03109-4, HSM selection, recorded key ceremony, connection of gateway administration and market participants.

Own sub-CA with HSM-protected keys, certificate lifecycle in the operations manual, evidence for the ISMS certification.

Discuss this topic

03 / Energy

Feed-in forecast at a municipal utility

Photovoltaic feed-in exceeds spreadsheet forecasts, balancing energy and redispatch effort rise, measurements sit unused in the control system.

Solution

Data platform with control system history, measurements and weather data, forecasting models per local substation with uncertainty bands, model operations with quality report.

Forecasts with uncertainty bands for grid operations and balancing group, congestion visible the day before, models with version state and evidence.

Discuss this topic

Working together

A clear path. With your team.

From an initial assessment to ongoing operations, we agree on priorities, responsibilities and the results of each stage.

How we work

  1. 01

    Assessment

    Plants, networks, interfaces and obligations under KRITIS, NIS2 and the IT security catalog

    Asset inventory, crypto inventory, gap analysis, prioritized list of measures by impact on supply
  2. 02

    Concept

    Zone model, PKI architecture, intrusion detection, operating model

    Zone model, PKI and HSM concept, detection concept, operating model, audit concept
  3. 03

    Implementation

    Segmentation, PKI, remote access and data platform in maintenance windows

    Separated zones, sub-CA with recorded ceremony, tested interfaces, documentation, approval per stage
  4. 04

    Operations

    Monitoring, certificates, audits, knowledge transfer

    Intrusion detection in daily operations, certificate renewal, audit support, stepwise handover

Before our first conversation

You do not need all the answers yet.

Start with a concrete challenge. These four questions help us find the right direction together.

Book a first consultation
  1. 01

    What should change?

    Your current challenge and the outcome you are aiming for.

  2. 02

    Which systems are involved?

    An overview of sites, applications and interfaces.

  3. 03

    What sets the boundaries?

    Project dates, maintenance windows and known dependencies.

  4. 04

    Who needs to be involved?

    The right people from IT, security and operations.

Background & decision criteria

What is cybersecurity for the energy sector?

Six fields of action from control systems under IEC 62443 to post-quantum cryptography for long-lived assets, planned, integrated and operated by OTOKO®. Every measure can be evidenced to the BSI, the Federal Network Agency and auditors. The entire solution runs in German data centers.

Cybersecurity for the energy sector protects control systems, generation plants and metering systems against outages and attacks and evidences every measure to the BSI and the Federal Network Agency. OTOKO® covers six fields of action: grid control systems and plants under IEC 62443, smart meter gateway PKI and HSMs under BSI TR-03109, KRITIS evidence with an ISMS under ISO 27019, remote maintenance and connection of distributed plants, forecasting of load and generation with data platforms, and post-quantum readiness for long-lived assets. Keys and certificates reside in hardware security modules, HSMs for short.

The difference from a pure consulting project lies in operations and evidence. Every zone, every telecontrol connection and every certificate comes with documentation, a version state and the records that the KRITIS audit and the IT security catalog of the Federal Network Agency require. Cryptography and hardware security modules are our core competence. Keys of the smart meter PKI and of telecontrol systems therefore reside in certified devices instead of software.

Why OTOKO® for the energy sector

  • Cryptography and HSM

    Cryptography and hardware security modules are our core competence. We plan and operate the smart meter PKI sub-CA, telecontrol certificates and firmware signatures in certified devices, as BSI TR-03109 requires.

  • German data centers

    The entire solution runs in German data centers. This applies to the PKI, intrusion detection and the data platform for forecasts.

  • Critical infrastructure and regulated industries

    We work with operators of critical infrastructure and regulated industries. We know what the BSI, the Federal Network Agency, auditors and information security expect in energy supply.

  • One team through to operations

    One team accompanies you from consulting to operations. OT security architects, cryptography specialists and data engineers stay on board without handover to third parties.

Delivery and details

Most utilities do not fail for lack of technology but on legacy control systems, gaps in evidence and deadlines from KRITIS and NIS2.

Control systems without zones

Control system, telecontrol and office IT share one network, engineering workstations reach every controller and the firewall rules date from commissioning.

Certificates without management

Certificates for gateways, telecontrol devices and control boxes live in spreadsheets, the sub-CA keys sit in software and an expiry only surfaces during an outage.

Intrusion detection without control systems

The SIEM collects events from office IT but not the control system protocols IEC 60870-5-104 and IEC 61850, and reporting to the BSI depends on a single person.

Remote maintenance without logging

Vendors and service providers reach plants through their own modems and VPN access, without approval, time window or session recording.

Three operating models
On-PremisesGerman cloudHyperscaler
Data locationYour control center, your data center, your HSMs and sub-CAData centers in Germany, operated under ISO 27001Azure, AWS or Google Cloud, region Germany selectable
OperationYour team or OTOKO® as managed serviceOTOKO®, with audit rights and evidence for the KRITIS auditShared, platform services by the provider
ToolsControl system, OT monitoring, HSMs and PKI on site, Kafka, KubernetesHosted PKI, HSM as a service, data platform for forecastsCloud HSM services, managed data and ML services
Suited forGrid operations, telecontrol, sub-CA of the smart meter PKIKRITIS operators with a need for sovereignty and audit evidenceForecasts, analytics, market communication, peak loads
ComplianceFull control, evidence from your ISMS under ISO 27019Processing agreement under GDPR, KRITIS contract, location GermanyProcessing agreement, standard contractual clauses, no control commands from the cloud

Collaboration

Project

Clearly scoped initiative such as a zone model under IEC 62443, the setup of a sub-CA or preparation for the KRITIS audit, with a defined result, milestones and acceptance.

  • Assessment, concept, implementation, handover
  • Fixed price or effort by milestone
  • Suited for audit preparation, PKI setup and segmentation projects

Team reinforcement

OT security architects, cryptography specialists or data engineers work in your teams, tools and approval processes, directly in the control center if needed.

  • Onboarding into your plants, processes and maintenance windows
  • Scalable as the project progresses
  • Suited for utilities with their own team and capacity gaps

Managed service

OTOKO® operates intrusion detection, PKI and HSMs or the data platform with agreed service levels, regular reports and the evidence that KRITIS auditors and the Federal Network Agency require.

  • Monitoring, certificate renewal, updates and support
  • Audit rights, service levels and reporting channels in the contract
  • Suited for utilities without their own operations team for OT security or PKI

Five regulations that bind grid operators, generators and metering point operators, with their requirements and what OTOKO® delivers for them.

Standards and evidence
RequirementDemandsOTOKO® delivers
IT Security Act 2.0 and KRITISCurrent technical safeguards for plants above the thresholds of the KRITIS Ordinance, intrusion detection systems, regular evidence to the BSI, reporting of significant incidentsClassification of plants, intrusion detection for IT and control systems along the BSI guidance, audit documents with implementation level, reporting process with templates
NIS2Registration, risk management measures for supply chain, cryptography and access, staged reporting with early warning, notification and final report, accountability of managementGap analysis of the measures, cryptography and access concept, reporting process with deadlines and exercises, training evidence for management
ISO 27019 and IT security catalogISMS under ISO 27001 with the ISO 27019 extensions for process control, grid control in scope under section 11 EnWG, certification and a contact person for IT securityISMS setup or extension with network structure plan, risk analysis and action plan, certification preparation and audit support
IEC 62443Zones and conduits with security levels, system requirements for control systems, hardening of components, patch and change processes for automation systemsZone model with risk assessment, segmentation and hardening, test evidence per zone, operations manual for patches in maintenance windows
BSI TR-03109Certified smart meter gateways under protection profile, smart metering PKI with sub-CAs, TLS with certificates from the PKI, requirements for the gateway administrator and its ISMSPKI concept and sub-CA with HSM, certificate profiles and lifecycle, connection of gateway administration and market participants, ISMS evidence

FAQ

Good questions. Clear answers.

15 answers about your industry, the project and ongoing operations.

Industry & expertise6 questions

Which services does OTOKO® offer for the energy sector?

The portfolio covers zone model and hardening of control systems under IEC 62443, PKI and HSMs for smart meter gateways under BSI TR-03109, KRITIS evidence with an ISMS under ISO 27019 and intrusion detection, remote maintenance and connection of distributed plants, forecasts for load and generation, and post-quantum readiness. Each field of action can be commissioned individually or as a complete package, with operation in German data centers.

Is our municipal utility a KRITIS operator or does it fall under NIS2?

Whether a plant counts as critical depends on the thresholds of the KRITIS Ordinance per plant category, for example for power grids, generation, gas supply and district heating. NIS2 additionally covers energy companies by size and sector, also below these thresholds. We classify your plants, derive the obligations with deadlines and determine which evidence must be produced first.

Can security be retrofitted into existing control systems without changing the plant?

Yes, that is the normal case. Older control systems and telecontrol devices rarely receive updates, so we protect them with zones, upstream industrial firewalls, data diodes, controlled remote access and passive monitoring of network traffic. These measures take effect without touching the approved configuration of the plant and are introduced in maintenance windows. We work with operators of critical infrastructure and regulated industries. There this approach is everyday practice.

What does BSI TR-03109 require from the operator of a smart meter gateway PKI?

The technical guideline specifies that gateways, gateway administration and market participants communicate only over TLS with certificates from the smart metering PKI. Operating a sub-CA requires registration under the BSI root, certificate profiles under TR-03109-4, an ISMS under ISO 27001 and keys that are generated and stored in an HSM. We deliver PKI concept, HSM integration, key ceremony and the evidence for certification.

How do forecasting models get data from control and metering systems without endangering the control systems?

The data platform reads from the process network through a data diode or protocol gateway but never writes back. Readings from smart meter gateways reach the platform via gateway administration, pseudonymized under GDPR and the Metering Point Operation Act. The models run outside the control systems, and their forecasts flow into grid operations as a proposal, not as a control command.

When should energy suppliers start with post-quantum cryptography?

Now, with the inventory. Smart meter gateways, telecontrol devices and substation equipment stay in the field well beyond the expected arrival of capable quantum computers, and replacing devices in the grid takes years of lead time. The inventory shows which firmware signatures, certificates and connections migrate first, and the roadmap ties the migration to rollout and renewal cycles.

Getting started & delivery5 questions

Can we start with a single area of expertise?

Yes. We can scope a specific task first. We consider its interfaces with the rest of your infrastructure and agree which work is included before implementation.

What should we prepare for the first conversation?

A brief description of the challenge, the systems involved and your desired outcome is enough to start. Known deadlines and the relevant contacts are helpful. Please do not include credentials or confidential system documentation in an initial enquiry.

Who needs to participate in the project?

OT security architect: Zone model, hardening, intrusion detection for control systems. Cryptography specialist: Smart meter PKI, HSM integration, PQC roadmap. Integration developer: Interfaces to plants, remote access, data diodes. Data engineer: Data platform, forecasting models, model operations. Compliance consultant: KRITIS, NIS2, IT security catalog, audit documents. Project lead: Milestones, maintenance windows, acceptance, reports.

How do you determine the schedule and effort?

We consider the systems, interfaces, available documentation and operational constraints. An agreed scope and milestones provide the basis for estimating effort. A fixed duration without these details would not be reliable.

What does the first stage deliver?

Plants, networks, interfaces and obligations under KRITIS, NIS2 and the IT security catalog Asset inventory, crypto inventory, gap analysis, prioritized list of measures by impact on supply

Operations & development4 questions

How can we work together?

Project: Clearly scoped initiative such as a zone model under IEC 62443, the setup of a sub-CA or preparation for the KRITIS audit, with a defined result, milestones and acceptance. Team reinforcement: OT security architects, cryptography specialists or data engineers work in your teams, tools and approval processes, directly in the control center if needed. Managed service: OTOKO® operates intrusion detection, PKI and HSMs or the data platform with agreed service levels, regular reports and the evidence that KRITIS auditors and the Federal Network Agency require.

What happens at handover to operations?

Monitoring, certificates, audits, knowledge transfer Intrusion detection in daily operations, certificate renewal, audit support, stepwise handover

Can we expand to further sites or systems later?

We can account for future expansion in the initial concept. Documented interfaces and reusable rules provide a foundation. Each additional site or system still needs to be assessed for its particular requirements.

How do we keep the solution maintainable?

Agree responsibilities, recurring tasks and change procedures alongside the technical implementation. Documentation and knowledge transfer help your team operate the solution. The specific activities and any ongoing support are part of the agreed scope.

Energy

Let's discuss your next step.

Let us review together where your grids and plants are exposed today and which measures deliver the most benefit first.

Book a first consultation

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.