Partner Login Anruf an byon Anruf an byon +49 69 710 486 400 Mail an byon Mail an byon
byon communicate louis duennebier kontakt

Get in touch with byon
Louis Dünnebier
Sales Professional – SD-WAN – Security
Tel.: +49 69 710 486 746
kontakt@byon.de

Your 5-minute consultation

Book an appointment now →

Go to the contact form

byon communicate produkte it secruity kritis byon KRITIS byon KRITIS byon KRITIS

KRITIS

As your expert in IT security and KRITIS, byon offers solutions to protect businesses from cyber-attacks in accordance with the definition of critical infrastructure (KRITIS) set out by the Federal Office for Information Security (BSI).

byon communicate produkte it secruity kritis umspannwerk

What is KRITIS?

KRITIS is a term used by the BSI to refer to critical infrastructure in Germany. This includes the supply of essential goods and services such as electricity, water, gas, local transport, medical care and IT.


Organisations classified as KRITIS must demonstrate that they have put in place appropriate measures to protect against cyber-attacks. New legislative changes, such as the NIS2 Directive and the KRITIS Framework Act on Resilience, entail specific audit cycles. The DORA Regulation also affects KRITIS operators, financial institutions and third-party ICT service providers.
The importance of critical infrastructure only becomes apparent when disruptions occur. It is therefore essential to safeguard this infrastructure against cybercrime in advance. We audit the IT infrastructure of your company or organisation and bring it up to date in accordance with the applicable legal requirements.

 

Who is covered by KRITIS?

If your company operates in one of the sectors listed in Section 2(10) of the BSI Act (BSIG), then it is covered by KRITIS. You can determine whether your company is included by checking the following key details:

Check the BSI-KritisV – Regulation on the Determination of Critical Infrastructures under the BSI Act – to see whether your company is included in one of the sectors listed there.


There are also certain thresholds to be taken into account. The calculation formulas for determining these can be found in Part 2 of the BSI KritisV under point 8: BSI-KritisV – Regulation on the Determination of Critical Infrastructures under the BSI Act.

You can find out more on the BSI website:

to BSI Website

byon communicate produkte it secruity kritis sektoren brancheneinteilung
byon communicate produkte it secruity kritis tabelle

What requirements apply to KRITIS organisations?

A whole range of security measures and protective mechanisms have been defined to safeguard KRITIS organisations. These range from protection against attacks and malware to the prevention and management of security incidents.

How can we support your organisation with regard to KRITIS?

The following technical solutions can help with the implementation of the KRITIS requirements:

byon communicate produkte itsecruity laptop man

SIEM – Security Information and Event Management

SIEM is one of the key pillars of the byon security fabric and offers features such as real-time security analytics, threat intelligence, and self-learning asset discovery. All of this is brought together in a clear, intuitive graphical user interface.
  • Active and passive detection methods for creating an inventory
  • AI-powered detection of behavioural anomalies – protection against known and unknown threats
  • Detection of unusual and suspicious behavioural patterns
  • Graphical visualisation of relationships between users and devices for even faster response times to threats
EDR / XDR – Endpoint Detection and Response
Endpoint Detection and Response (EDR) combines continuous monitoring, advanced analytics of endpoints, networks and the cloud, and advanced real-time correlation to detect and respond to suspicious activity on hosts and endpoint connections.
Advanced attacks are difficult to detect using standalone security products. By analysing security feeds from across your entire security fabric, correlating related events to incidents and conducting further investigation, EDR/XDR can immediately initiate cross-platform actions to block the attack and prevent further activity.
byon communicate produkte itsecruity smartphone
Are you interested in our byon security solutions to implement your KRITIS requirements?
Please feel free to contact us, and together we will develop a suitable solution for your company.

.

FAQ

Which sectors and industries in Germany are classified as critical infrastructures and why are they important? byon Which sectors and industries in Germany are classified as critical infrastructures and why are they important? byon Which sectors and industries in Germany are classified as critical infrastructures and why are they important?
In Germany, there are 9 KRITIS sectors for which sector-specific security standards are crucial in order to ensure a functioning state and society. These include the sectors of energy, food, finance and insurance, healthcare, information technology and telecommunications, municipal waste disposal, media and culture, state and administration, as well as transport and traffic. These sectors are important because they provide essential services whose failure could lead to significant supply shortages and risks to society and public safety. Operators of these KRITIS infrastructures must therefore ensure their secure and reliable operation.
What dangers and threats exist for critical infrastructures (KRITIS) in Germany and how are they addressed? byon What dangers and threats exist for critical infrastructures (KRITIS) in Germany and how are they addressed? byon What dangers and threats exist for critical infrastructures (KRITIS) in Germany and how are they addressed?
Critical infrastructures and critical services in Germany are exposed to a wide range of dangers, including natural disasters (e.g. storms, flooding), technical failures, cyber attacks, power outages, epidemics and pandemics, and terrorism. An all-hazards approach is applied to take all potential risks into account and promote resilience. Particular attention is given to dependencies between sectors, which can lead to domino and cascading effects. As a result, failures and significant disruptions in one area of critical services and infrastructures can affect other sectors and have dramatic consequences for society and public safety.
What legal and regulatory frameworks exist in Germany and the EU for the protection of critical infrastructures (KRITIS)? byon What legal and regulatory frameworks exist in Germany and the EU for the protection of critical infrastructures (KRITIS)? byon What legal and regulatory frameworks exist in Germany and the EU for the protection of critical infrastructures (KRITIS)?
In Germany, there is no single KRITIS regulation, but rather various sector-specific laws such as the Spatial Planning Act and the Civil Protection and Disaster Assistance Act. A new overarching KRITIS Act is intended to harmonise these regulations. At EU level, there are directives such as the CER Directive and the NIS2 Directive, which promote the protection and resilience of critical infrastructures. In addition, national laws such as the IT Security Act and the BSI Act exist to strengthen cybersecurity and the protection of critical infrastructures.
  • The EPCIP Directive of 2008:
 
    The EPCIP Directive (Directive 2008/114/EC) was adopted in 2008 to identify critical infrastructures in the energy and transport sectors whose disruption would have significant impacts on at least two EU Member States. The aim is to protect these infrastructures through appropriate measures.


  • Directive on the Resilience of Critical Entities (CER Directive):
 The CER Directive, adopted on 14 December 2022, replaces the EPCIP Directive. It covers more sectors (including healthcare, banking and digital infrastructure) and provides for the identification and protection of nationally and Europe-wide significant critical infrastructures. In addition, Member States are required to implement measures to improve resilience..

  • The NIS Directives:
 The first NIS Directive (2016) aims to ensure a high level of security for network and information systems in the EU. It requires minimum security requirements and incident reporting obligations for KRITIS operators and operators of digital services. The NIS2 Directive (2022) expands these requirements and must be transposed into national law by October 2024 (NIS2 Implementation Act).

  • The IT Security Act:
  The IT Security Act (IT-SiG) of 2015 and the IT Security Act 2.0 of 2021 establish the legal framework for cyber and IT security for KRITIS in Germany. They expand the powers of the Federal Office for Information Security (BSI) and introduce the BSI KRITIS Regulation, which legally identifies critical infrastructures and defines security requirements.

Contact & Enquiries

Would you like to find out more about the benefits
of our byon products and services?

Why not get in touch with us today –
we’d be happy to help.

Louis Dünnebier
Sales Professional – SD-WAN – Security
Tel.: +49 69 710 486 746

Your 5-minute consultation

Book an appointment now →

Go to the contact form

byon communicate louis duennebier kontakt
byon #6

Louis Dünnebier
Sales Professional – SD-WAN – Security