On 13 March 2025, the German Federal Office for Information Security (BSI) presented new recommendations for securing the OT of distribution network operators. The document, 'Monitoring in der Stationsautomatisierung', addresses protection against cyber attacks on power supply systems and thus underlines their outstanding importance for security of supply. The recommendations help operators of critical infrastructure successfully address the growing challenge of protecting their OT systems against cyber attacks.

 

Why Are Substations
an Attractive Target?

Power supply facilities, such as substations and power plants, are central components of electricity grids. They are important for ensuring the security of supply for other critical infrastructures. Their critical nature makes them attractive targets for cyberattacks, especially in an era of increasing connectivity and digitalization. Therefore, targeted protection of these facilities is essential.

 

Objectives of the Recommended Actions

The BSI's new recommended actions aim to accelerate the integration of power supply systems into existing intrusion detection systems or, alternatively, to initiate the monitoring of these systems if they are not yet equipped with one. Thus, it supplements the BSI guidance for intrusion detection systems, which was updated on November 18, 2024, by taking into account the specific requirements of station automation.

 

Key Aspects 
of the Recommended Actions

The recommended actions highlight several topics, including:

Documentation of the System

Complete and up-to-date documentation is the basis for effective monitoring. In addition to a list of devices (OT asset inventory), this also includes the network diagram, an overview circuit diagram, and complete information on the parameterization of the OT devices. In the case of IEC61850 systems, a complete and up-to-date SCD file should be available.

Logging

The use of OT intrusion detection systems to log security-relevant events is essential. Care should be taken to ensure that all relevant network areas are included in the monitoring. Intrusion detection systems with a (specification-based) allowlist approach can reduce the effort involved.

Detection and 
Reaction

Safety-relevant events must be recognized promptly, and appropriate response measures must be initiated.

Timely Evaluation

Safety-relevant events must be evaluated in real time. High-quality and comprehensible presentations of the information can facilitate this process and enable an initial assessment to be carried out at the network control center.

Functional 
Monitoring

Systems should be checked regularly for their planned functionality.

Advantages of Specialized
OT Intrusion Detection Systems

Due to the unique characteristics of OT networks, monitoring methods used in office IT are not always applicable. The use of specialized OT attack detection systems can significantly facilitate the detection of attacks and malfunctions and shorten response times to security incidents in energy systems. Targeted monitoring of these OT systems makes an essential contribution to the protection of critical services.

 

The BSI's new recommended actions provide operators of energy systems with important guidance on how to protect their infrastructure. Particularly in view of the increasing threat situation, the consistent implementation of these measures is an important step towards ensuring security of supply and minimizing the risk of cyberattacks.
 

Further information can be found here in the official documents.

 

StationGuard

✔️ OT intrusion detection ✔️ Vulnerability management ✔️ Asset inventory ✔️ Functional monitoring

Complete Detection 
for Your OT Network

Secure all your assets immediately with a solution designed specifically for critical infrastructure. StationGuard monitors all communications in real time, detects threats and malfunctions, and requires no learning curve – protection starts from day one.

Learn More

Resources