By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: KOBILPublished February 13, 2026

TL;DR: Berlin’s January 2026 blackout left about 45,000 households and more than 2,200 businesses without power after an arson attack on cable infrastructure, according to KOBIL, underscoring how physical sabotage can cascade into transport, healthcare, and communications outages. The governance gap is not just infrastructure hardening but access control, data protection, and nationwide resilience standards that can actually be enforced.


At a glance

What this is: This is a governance analysis of Germany’s KRITIS debate after the Berlin blackout, showing that resilience fails when physical sabotage, data exposure, and uneven security standards intersect.

Why it matters: It matters to IAM and security teams because KRITIS resilience depends on who can access sensitive operational data, how privileged access is constrained, and whether controls are consistent across operators and jurisdictions.

By the numbers:

👉 Read KOBIL’s analysis of Berlin blackout resilience and KRITIS security


Context

Critical infrastructure resilience fails when physical sabotage, access asymmetry, and uneven security requirements are treated as separate problems. The Berlin blackout shows how a single attack on cable infrastructure can interrupt electricity, internet, heating, transport, and care delivery at once, which is why KRITIS policy cannot stop at sector labels or paper compliance.

In identity terms, the article’s strongest point is that sensitive infrastructure data and operational access are themselves high-value targets. Clear permissions, encryption, and zero trust controls matter because detailed network and pipeline information can materially help an attacker plan disruption. That is a familiar failure mode in critical environments, and the need for consistent access governance is typical rather than exceptional.


Key questions

Q: How should critical infrastructure operators protect sensitive operational data?

A: Operators should classify operational blueprints, network diagrams, and supply-point data as sensitive assets, then enforce least privilege, encryption, and full access logging. The objective is to reduce what an attacker can learn from a compromise and to prevent casual internal exposure from becoming targeting intelligence.

Q: Why do KRITIS programmes need both physical and identity controls?

A: Physical resilience limits direct disruption, but identity controls determine who can see, change, or recover the systems that keep critical services running. Without strong authentication and privileged access governance, a physical incident can become a broader operational failure because recovery paths are exposed or misused.

Q: What do organisations get wrong about Zero Trust and resilience?

A: Many organisations treat Zero Trust as a login problem and resilience as a separate recovery problem. In practice, both must work together because post-authentication access can still be abused. A useful programme verifies continuously, constrains lateral movement, and protects critical services during active compromise.

Q: Who is accountable when a third-party identity can reach critical infrastructure?

A: Accountability sits with the organisation that allows the trust path to exist and remain active. Security teams should require documented access ownership, test revocation, and verify that supplier access is auditable across the full lifecycle, not just at onboarding.


Technical breakdown

Why KRITIS resilience depends on access governance

KRITIS resilience is not just about physical redundancy. It also depends on controlling who can see network layouts, supply points, maintenance data, and emergency procedures. Once attackers or untrusted parties can map critical dependencies, they can target the weakest link with far more precision. In practice, this makes identity and access management part of infrastructure resilience, not a back-office control. Zero Trust Architecture helps because it assumes access cannot be trusted by default and forces verification before sensitive data or systems are exposed.

Practical implication: classify operational data by sensitivity and enforce least privilege on engineering, contractor, and emergency-access paths.

How inconsistent state and federal rules create security variance

A resilience framework weakens when different operators are held to different minimums. The article points to a common governance problem in critical infrastructure: one part of the estate is tightly regulated while another remains under a looser regime, creating uneven assurance across interdependent systems. That variance matters because outages rarely respect organisational boundaries. From an identity perspective, inconsistent policy enforcement also creates audit gaps, especially when privileged users or service accounts span multiple entities and tools.

Practical implication: standardise access policy, logging, and offboarding requirements across all operators that share critical services.

Why zero trust and multi-factor authentication are now baseline controls

The article treats zero trust, multi-factor authentication, and continuous risk assessment as prerequisites rather than advanced options. That framing is important because critical systems increasingly fail through trust leakage, not only through direct compromise. If a user, administrator, or remote service can reach sensitive operational environments without strong verification, the blast radius of a single compromise grows quickly. For KRITIS operators, identity assurance has to extend from human administrators to service accounts and machine-to-machine access paths.

Practical implication: require strong authentication and continuous verification for both human and non-human access to operational systems.


Threat narrative

Attacker objective: The objective is to disrupt essential services at scale and force operational, social, and economic instability.

  1. Entry occurs through sabotage of physical cable infrastructure, which disables power delivery and creates immediate operational disruption across connected services.
  2. Escalation follows because the outage affects transport, healthcare, and communications, increasing dependency on emergency power and constrained recovery processes.
  3. Impact is broad service interruption for tens of thousands of households and thousands of businesses, showing how one infrastructure attack can cascade through the regional economy.

NHI Mgmt Group analysis

Nationwide KRITIS standards are only useful if they reduce variance in real control enforcement. The article correctly identifies the danger of state-by-state exceptions and uneven thresholds. Critical services depend on common operating assumptions, especially when operators, authorities, and emergency responders need to coordinate under pressure. Without consistent minimums, resilience becomes a patchwork of local interpretations rather than a national control model.

Operational data is an infrastructure asset and must be governed like one. Maps of pipelines, network structures, and supply points are not neutral documentation. They are targeting intelligence when exposed, so access control, encryption, and permission scoping belong in the same conversation as physical hardening. For practitioners, this means treating sensitive infrastructure data as a protected resource with lifecycle controls, not a shared convenience artifact.

Zero Trust in KRITIS is not a branding choice, it is a control boundary. The article uses the right language by linking resilience to multi-factor authentication and continuous risk assessment. In critical environments, the identity layer determines whether remote administration, contractor access, and emergency override paths remain bounded. The practical lesson is that resilience programmes should measure how much implicit trust still exists in privileged access paths.

KRITIS governance is converging with identity governance because service continuity now depends on access assurance. This is where infrastructure security and IAM meet most clearly. If access to sensitive operational systems, telemetry, and recovery tooling is not tightly governed, attackers gain more than visibility. They gain the ability to shape response. Practitioners should align critical-infrastructure controls with identity lifecycle, privileged access, and monitored access review discipline.

What this signals

Critical infrastructure programmes are moving into the same governance territory as identity security: access scope, verification strength, and offboarding discipline now shape resilience outcomes. Where operational systems depend on contractors, managed service providers, and machine-to-machine workflows, the identity layer becomes part of continuity planning, not just cyber hygiene.

Operational trust gap: this is the gap between what a resilience policy assumes is protected and what an attacker can actually learn or reach through exposed infrastructure data. Teams should review whether shared diagrams, maintenance runbooks, and privileged recovery paths are governed with the same rigor as production access.

Practitioners should align KRITIS controls with external guidance such as MITRE ATT&CK Enterprise Matrix for threat mapping and NIST SP 800-53 Rev 5 Security and Privacy Controls for access control and logging discipline.


For practitioners

  • Tighten access to operational blueprints Restrict who can view pipeline maps, supply nodes, maintenance plans, and recovery documentation. Apply separate permissions for design, operations, contractor, and emergency-response roles, and log every access to those assets.
  • Standardise controls across all operators Use one baseline for authentication, logging, and offboarding across private operators, public bodies, and subcontractors that share critical infrastructure responsibilities. Inconsistency creates the weakest path across the whole system.
  • Extend Zero Trust to privileged access paths Require multi-factor authentication, device trust checks, and just-in-time elevation for administrators and remote support users. Do not allow standing administrative access to critical systems without periodic review.
  • Classify infrastructure data as sensitive Apply encryption and explicit retention rules to network diagrams, asset inventories, and operational telemetry. These artefacts often reveal enough context for attackers to plan sabotage or accelerate lateral movement.

Key takeaways

  • The Berlin blackout shows that resilience failures cascade across power, transport, healthcare, and communications when one critical dependency is attacked.
  • The governance issue is not only hardening infrastructure but protecting operational data, access paths, and emergency recovery controls from misuse.
  • KRITIS programmes need consistent identity assurance, least privilege, and zero trust enforcement if they want minimum standards to mean anything in practice.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Access control is central because the article ties resilience to permissions and verification.
NIST SP 800-53 Rev 5AC-6Least privilege directly applies to sensitive operational data and privileged access.
NIST Zero Trust (SP 800-207)The article explicitly recommends zero trust as a baseline resilience control.
ISO/IEC 27001:2022A.5.15Access control policy is relevant to protected infrastructure data and operational permissions.
MITRE ATT&CKTA0001 , Initial Access; TA0040 , ImpactThe article centers on sabotage-driven disruption and cascading operational impact.

Map sabotage scenarios to Initial Access and Impact tactics when planning detection and resilience exercises.


Key terms

  • Critical Infrastructure Data: Information that describes how essential services are built, connected, and recovered. In KRITIS environments this includes network maps, supply points, maintenance plans, and operational dependencies. If exposed, it can help attackers target disruption more efficiently.
  • Zero Trust: A security model that assumes no identity — human or non-human — should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
  • Privileged Access: Privileged access is any elevated entitlement that can change systems, data, or security settings. When privilege is excessive or poorly scoped, a single compromised identity can create outsized blast radius across environments.

What's in the full article

KOBIL's full article covers the operational and policy detail this post intentionally leaves for the source:

  • The draft KRITIS law’s structural tensions between federal, state, and private operators.
  • The article’s full discussion of Zero Trust, multi-factor authentication, and continuous risk assessment in critical infrastructure.
  • KOBIL’s framing of how security, identity, and compliance tooling fit into KRITIS implementation.
  • The broader policy argument around nationwide minimum standards for sensitive infrastructure protection.

👉 KOBIL’s full article adds the policy context, control requirements, and implementation framing behind the KRITIS debate.

Deepen your knowledge

NHI Mgmt Group’s NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, and secrets management. It helps practitioners connect identity controls to resilience, access assurance, and operational risk.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org