Your starting point
As an operator of critical infrastructure, you must take appropriate organizational and technical measures and regularly demonstrate their implementation to the BSI (Section 8a BSIG). With the NIS-2 implementation, especially important and important entities are added, along with registration and reporting obligations as well as personal duties of management (Section 38 BSIG).
The KRITIS sectors per the BSI-KritisV include: energy, water, food, information technology and telecommunications, health, finance and insurance, transport and traffic, and municipal waste disposal. NIS-2 broadens the circle to include, among others, the chemical industry, manufacturers of critical products and postal and courier services.
What we do for you
- IS penetration tests by a BSI-certified service provider. The test reports are structured so that they can feed into your evidence trail without rework.
- BSI maturity and implementation level assessment (BSI RUN) as a standardized procedure for determining your level of implementation, embedded in our ISMS consulting per BSI IT-Grundschutz or ISO 27001.
- Red teaming and attack simulations, when, beyond the mandatory evidence, you want to know how your detection and response perform in a real incident.
- Darknet monitoring for early detection of compromised access and data.
Why zentrust for KRITIS
- BSI-certified: as an IT security service provider in the scope of IS penetration testing, and with our own information network certified to ISO 27001 on the basis of IT-Grundschutz. You will find both forms of evidence about us.
- Member of the BSI’s Alliance for Cyber Security.
- Plannable dates: Section 8a test cycles have deadlines. We work to your evidence window, at short notice by arrangement.
- A shared language with your information security officer: our reports use the categories your evidence trail needs, from prioritizing measures to risk classification.
Do you operate a sea or inland port? Where operational technology (OT) is in use alongside IT, special requirements apply to the test approach. For that we have a dedicated page: Information security for port operators (IT & OT).
