Jump to content
  • Newsroom
  • Veröffentlicht am:

NIS2 and the KRITIS Umbrella Act: How the Threat Landscape for Critical Infrastructure Is Evolving

Interview with Kevin Kohlhoff and Norman Weferling

The KRITIS Umbrella Act and NIS2 significantly raise the bar for the protection of critical infrastructure. While NIS2 primarily addresses cybersecurity and the security of network and information systems, the KRITIS Umbrella Act places a stronger emphasis on physical and organizational resilience. For organizations, this means that cybersecurity, physical security, business continuity, and crisis management must be addressed in a far more integrated manner.

In conversation with Mirko Geyer, Spokesperson at MHP, Kevin Kohlhoff, Associated Partner and Cyber Security Lead Public & Defense at MHP, and Norman Weferling, Senior Manager Cyber Security, assess the implications of the KRITIS Umbrella Act and NIS2. They discuss how well prepared German organizations are for the new requirements, which risks continue to be underestimated, and which measures are now critical to strengthening resilience over the long term.

Mirko Geyer: The KRITIS Umbrella Act and NIS2 are now in force. What changes are affected organizations already seeing in practice?

Norman Weferling: Honestly, the impact varies considerably depending on which law we are talking about. Organizations are clearly feeling the effects of NIS2 because the amended German Federal Office for Information Security Act, or BSIG, has applied without a transitional period since December 6, 2025. The reporting portal is operational and registration is mandatory. The situation is almost the reverse for the KRITIS Umbrella Act. Although it formally entered into force in March, the ordinance that will determine which facilities qualify as critical infrastructure remains in draft form. As a result, what I currently see in KRITIS-related projects is less implementation and more preparation for a regulatory framework whose details have yet to be finalized.

Many organizations are already actively implementing NIS2 requirements. However, their level of maturity varies significantly. Some have been addressing the issue for years and started preparations early, not least because implementation often requires extensive internal change. Others, by contrast, are already struggling with the registration process.

Kevin Kohlhoff: From my perspective, the most significant change is that resilience has moved beyond the remit of individual specialist functions and become a core corporate governance responsibility. Under NIS2, it is no longer sufficient to delegate cybersecurity to the IT function or the CISO. Executive management must understand the risks, ensure that the necessary measures are implemented, and oversee their effectiveness.

In practice, we therefore see organizations redefining responsibilities and, in many cases for the first time, bringing IT, OT, legal, compliance, procurement, business continuity, and physical security together in a coordinated program. While the lack of regulatory detail under the KRITIS Umbrella Act continues to create some hesitation, the key questions can already be answered today: Which services are genuinely critical? What is the maximum tolerable period of disruption? And which internal and external dependencies underpin their delivery Organizations that wait for a final checklist before taking action are losing valuable time.

Mirko Geyer: How do the KRITIS Umbrella Act and NIS2 interact, and where do they differ?

Norman Weferling: The first point to clarify is that the KRITIS Umbrella Act does not implement NIS2. This is a common misconception.NIS2 is implemented in Germany through the BSIG and governs cybersecurity and the security of network and information systems. The KRITIS Umbrella Act, by contrast, implements the EU Critical Entities Resilience Directive, or CER Directive, and addresses physical and organizational resilience. This includes areas such as physical security, personnel security, and emergency preparedness.

The two frameworks have been deliberately aligned where appropriate. Examples include the joint platform operated by the Federal Office for Information Security, or BSI, and the Federal Office of Civil Protection and Disaster Assistance, or BBK, the once-only principle for registration, and executive management obligations under both regulatory regimes.The most significant practical difference, however, lies in the number of affected organizations in Germany. NIS2 applies to approximately 29,500 entities, whereas the KRITIS Umbrella Act covers just over 2,000 operators of critical infrastructure facilities.

Kevin Kohlhoff: Both regulatory frameworks pursue the same fundamental objective from different risk perspectives: ensuring the reliable delivery of critical services. NIS2 and the BSIG focus on the security of the network and information systems used to provide those services. The KRITIS Umbrella Act addresses the physical and organizational resilience of critical infrastructure facilities.

In an operational environment, however, this distinction is difficult to maintain. A power outage can take IT systems offline, a cyberattack can halt a production facility, and a compromised access control system can enable unauthorized physical access to sensitive areas.

In addition, operators of critical infrastructure facilities are automatically classified as particularly important entities under the BSIG. For their critical facilities, they must also meet requirements that go beyond the general NIS2 baseline.The two regulatory frameworks are therefore not alternatives. Their requirements are cumulative. Organizations should address them from the outset through an integrated governance and risk management framework.

Mirko Geyer: In your view, are German organizations sufficiently prepared? What are the biggest challenges at present?

Norman Weferling: In my view, the answer is no, although the situation requires a nuanced assessment. Traditional critical infrastructure operators are comparatively well prepared. They have been addressing these issues since Germany’s first IT Security Act was introduced in 2015 and generally have established structures in place. The figure that concerns me most is a different one. By the statutory deadline of March 6, only around 11,500 of approximately 29,500 entities subject to NIS2 had registered. 

The BSI therefore had to extend the deadline until the end of July. An organization that is already struggling with registration is highly unlikely to have fully assessed or implemented the ten categories of risk management measures required under Section 30 of the BSIG.

Kevin Kohlhoff: Organizations are not yet adequately prepared across the board. Many companies have individual capabilities that are already well developed, such as an information security management system within IT, a physical security risk assessment, business continuity management capabilities, or a dedicated crisis management structure. However, these disciplines often operate with different scopes, risk criteria, and priorities. A number of well-functioning individual capabilities do not automatically add up to an effective resilience management framework. 

The biggest challenge is establishing end-to-end visibility across legal entities, sites, IT and OT environments, critical suppliers, and third-party service providers. On that basis, risks must be prioritized, accountability must be clearly assigned, and the necessary measures must receive adequate funding. Regulatory implementation rarely fails because another security technology is missing. It usually fails because accountability is unclear and priorities have not been properly defined. A certificate or an approved policy is not proof that an organization can withstand and recover from a real-world disruption.

Mirko Geyer: In addition to cyberattacks, the KRITIS Umbrella Act focuses particularly on physical threats. Which risks, including sabotage or drones, are still being underestimated?

Norman Weferling: Drones represent a relevant threat vector, but in my view they often receive more attention than other, far more likely disruption scenarios. Consider what happened in Berlin-Lichterfelde a few months ago. An arson attack on a cable bridge caused five high-voltage cables to fail. Around 45,000 households were left without power and heating for four and a half days in the middle of winter. It was the longest outage of its kind since 1945. This was not a sophisticated, high-tech attack. It was a classic single point of failure.

In my view, three issues in particular are consistently underestimated. The first is cascading effects, which are often what turn a localized incident into a major crisis. In Berlin, the power outage also disrupted both mobile and fixed-line communications. The second is the risk posed by malicious insiders or contractors with authorized access credentials. The third is that many operators do not have complete visibility of their own critical assets, dependencies, and potential points of failure.

Returning to the issue of drones, unauthorized drone overflights will become reportable incidents. However, very few organizations have yet established an appropriate incident reporting and response process.

Kevin Kohlhoff: What organizations most frequently underestimate is not a particular threat, but critical dependencies and shared vulnerabilities. Two data centers, for example, do not provide genuine redundancy if both depend on the same power corridor, telecommunications provider, or third-party service provider. Similarly, a production environment may be technically hardened and still become unavailable if building management systems, cooling infrastructure, spare-parts logistics, or specialized maintenance personnel are disrupted or unavailable.

Combined scenarios are particularly critical. A limited physical incident may coincide with a cyber disruption or a failure of communications infrastructure. What initially appears to be a manageable event can then escalate into a cross-sector crisis.

Organizations must therefore assess their critical services end to end, covering personnel and facilities, IT and OT environments, power supply, communications, and supply chain dependencies.

Mirko Geyer: What role will the integration of cybersecurity, physical security, and crisis management play in protecting critical infrastructure effectively?

Norman Weferling: It will be decisive, particularly because regulation itself does not provide organizations with the operational integration they need. The interaction between the two frameworks is well designed when it comes to registration and incident reporting. Both are handled through a joint platform operated by the BBK and the BSI. In addition, the competent resilience authorities may use parts of the BSIG documentation when reviewing evidence of compliance. However, this integration ends at the supervisory level. The BSI is responsible for digital and cybersecurity obligations. Depending on the sector, responsibility for physical resilience lies with the BBK, sector-specific authorities, or the federal states. The two frameworks also have separate enforcement and sanctions regimes. Organizations that treat these requirements as two separate internal projects create duplicate effort without necessarily becoming more resilient.

In my view, the Business Impact Analysis, or BIA, is the key integrating element. It creates a shared understanding of which process or service may be unavailable, and for how long. Based on that analysis, organizations can develop scenarios that account for both cyber and physical causes and establish one integrated crisis management structure rather than three separate ones.

Kevin Kohlhoff: Integration is not an optional organizational improvement. It is a prerequisite for effective operational resilience. In many organizations, cybersecurity, physical security, business continuity, and crisis management are each handled professionally, but largely in isolation. The respective functions use different risk taxonomies, report to different governance bodies, and prioritize according to their own criteria. Integration does not mean consolidating all these functions into a new department. What is required is a common governance and operating model based on the same critical services, an aligned risk methodology, consistent escalation paths, and integrated remediation planning.

Executive management should receive one coherent view of the organization’s resilience posture, rather than three conflicting status reports. Subject matter accountability should remain with the respective specialists. However, governance, prioritization, validation, and exercising must be coordinated across functions. Only then can compliance with individual regulatory requirements translate into a genuinely resilient organization.

Mirko Geyer: How is artificial intelligence changing the threat landscape? What impact does it have on attackers and defenders?

Norman Weferling: I take a more measured view than many others. So far, AI has primarily provided attackers with greater scale and higher-quality outputs, rather than fundamentally new capabilities. Typical examples include more convincing phishing emails without obvious linguistic errors, deepfake calls used for CEO fraud, and faster reconnaissance and target profiling.

The main impact is economic. A highly targeted attack can suddenly be executed at a cost approaching that of a broad, indiscriminate campaign. Defenders have access to the same underlying technologies, but they are structurally slower to adopt them. Procurement processes, governance requirements, and approval procedures often delay the deployment of new security capabilities. For critical infrastructure operators, there is an additional concern. As soon as AI is integrated into control rooms, security operations, or monitoring systems, the AI system itself becomes part of the attack surface.

Kevin Kohlhoff: As Norman has outlined, AI currently acts primarily as a force multiplier, increasing scale and efficiency. It changes the speed, scalability, and economics of cyberattacks. Threat actors can analyze information more quickly, create highly convincing social engineering scenarios, and identify potential vulnerabilities more efficiently. This significantly lowers the barrier to conducting targeted attacks.

On the defensive side, AI can support the analysis of large volumes of data, assist with alert triage, and save valuable time during security incident investigation and response. However, AI only delivers meaningful value if data quality, processes, and accountability are properly established. Particularly in critical infrastructure environments, AI systems must not become a new single point of failure. 

Security-relevant use cases therefore require human oversight, explainable and traceable decision-making, and robust fallback and recovery procedures. The decisive advantage will not come from having access to a more capable model alone. It will come from an organization’s ability to translate AI-generated insights into timely and effective risk-informed decisions.

Mirko Geyer: If you could give organizations three specific recommendations today to strengthen their resilience over the long term, what would they be?

Norman Weferling: First, organizations should determine immediately whether they fall within the scope of the legislation, using the current draft ordinance as the basis for their assessment. Anyone who waits until the KRITIS ordinance is published in the Federal Law Gazette will begin implementation with the clock already running. 

Second, physical and cyber risk assessments should be integrated into a single process rather than conducted separately. The KRITIS Umbrella Act requires an all-hazards approach, which is fundamentally incompatible with siloed risk management. 

Third, and perhaps most importantly, organizations must exercise and test their plans. A resilience plan that has never been tested under realistic time pressure is ultimately just a document, not an effective control.

My practical test is simple: Tomorrow morning, the power fails and the mobile network goes down at the same time. Who informs whom, and through which communication channel?

Kevin Kohlhoff: First, organizations should not begin with the wording of the legislation or a technical controls checklist. They should begin with their critical services.
Which services must continue to operate during a crisis? What is the maximum tolerable period of disruption? And which people, facilities, systems, suppliers, and service providers does their delivery depend on?

Second, clear accountability must be established at executive management level. NIS2 and the KRITIS Umbrella Act should be implemented through a coordinated program with clear decision rights, sufficient funding, and a prioritized implementation roadmap. Existing capabilities such as information security management systems, business continuity management, and crisis management should be developed in a targeted manner rather than supplemented with new and duplicative structures.

Third, implementation must focus on operational effectiveness rather than document production.Every measure requires an accountable owner, a target date, and reliable evidence that it has been implemented and is operating effectively. Compliance should be the outcome of an effective resilience management framework, not its sole objective.

MHP Newsroom

Sie benötigen Informationen zu MHP oder zu unseren Leistungen und Kompetenzen? Gerne unterstützen wir Sie mit aktuellen Informationen, Hintergrundberichten und Bildern.

Alle News im Überblick