Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

KRITIS resilience after Berlin: are access and data controls enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Berlin’s January 2026 blackout left about 45,000 households and more than 2,200 businesses without power after an arson attack on cable infrastructure, according to KOBIL, underscoring how physical sabotage can cascade into transport, healthcare, and communications outages. The governance gap is not just infrastructure hardening but access control, data protection, and nationwide resilience standards that can actually be enforced.

NHIMG editorial — based on content published by KOBIL: Berlin blackout and KRITIS security governance

By the numbers:

Questions worth separating out

Q: How should critical infrastructure operators protect sensitive operational data?

A: Operators should classify operational blueprints, network diagrams, and supply-point data as sensitive assets, then enforce least privilege, encryption, and full access logging.

Q: Why do KRITIS programmes need both physical and identity controls?

A: Physical resilience limits direct disruption, but identity controls determine who can see, change, or recover the systems that keep critical services running.

Q: What do organisations get wrong about Zero Trust and resilience?

A: Many organisations treat Zero Trust as a login problem and resilience as a separate recovery problem.

Practitioner guidance

  • Tighten access to operational blueprints Restrict who can view pipeline maps, supply nodes, maintenance plans, and recovery documentation.
  • Standardise controls across all operators Use one baseline for authentication, logging, and offboarding across private operators, public bodies, and subcontractors that share critical infrastructure responsibilities.
  • Extend Zero Trust to privileged access paths Require multi-factor authentication, device trust checks, and just-in-time elevation for administrators and remote support users.

What's in the full article

KOBIL's full article covers the operational and policy detail this post intentionally leaves for the source:

  • The draft KRITIS law’s structural tensions between federal, state, and private operators.
  • The article’s full discussion of Zero Trust, multi-factor authentication, and continuous risk assessment in critical infrastructure.
  • KOBIL’s framing of how security, identity, and compliance tooling fit into KRITIS implementation.
  • The broader policy argument around nationwide minimum standards for sensitive infrastructure protection.

👉 Read KOBIL’s analysis of Berlin blackout resilience and KRITIS security →

KRITIS resilience after Berlin: are access and data controls enough?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Nationwide KRITIS standards are only useful if they reduce variance in real control enforcement. The article correctly identifies the danger of state-by-state exceptions and uneven thresholds. Critical services depend on common operating assumptions, especially when operators, authorities, and emergency responders need to coordinate under pressure. Without consistent minimums, resilience becomes a patchwork of local interpretations rather than a national control model.

A question worth separating out:

Q: Who is accountable when a third-party identity can reach critical infrastructure?

A: Accountability sits with the organisation that allows the trust path to exist and remain active. Security teams should require documented access ownership, test revocation, and verify that supplier access is auditable across the full lifecycle, not just at onboarding.

👉 Read our full editorial: Berlin blackout shows why KRITIS resilience still depends on access control



   
ReplyQuote
Share: