For energy and heat network operators.
Cybersecurity compliance for heat networks and decentralised energy.
Who this is for.
Heat networks. District heating and cooling. Thermal storage. Energy service companies. Solar and wind. Charge point operators. NIS2 treats energy as one of its most critical sectors, and names district heating and cooling in its own right.
Most operators in this sector look the same inside. A small IT function. An operations team on the process side. No security role. The regulator now wants both halves evidenced together.
What applies to you.
Every EU country transposes NIS2 into national law during 2024 to 2026. The national text is the one that binds you.
Risk measures
Measures proportionate to your exposure, across all hazards. They cover the plant and the office, not only the servers. A shared control-room login counts, and so does an unpatchable HMI.
Incident reporting
A significant incident starts a clock: early warning in 24 hours, full notification in 72. We track the clock, gather the detail and draft the notification with a significance classification for you to confirm. You submit it to your national authority.
Management accountability
Your management body approves the measures and oversees them. It can be held liable when they are not in place. We produce the proof: dated approvals, the decisions behind them, training records.
All your assets, one record.
We cover the whole estate: laptops, servers, identity, cloud, and the operational technology that runs your plants. One asset inventory, one risk register, one evidence pack. OT joins through a read-only feed from the monitoring you already run.
We understand what makes OT different. Availability comes first, patch windows are scarce, and some assets can never be touched. The platform supports workflows built around those constraints, so an unpatchable asset is managed risk, not a permanent red line.
Every operation is different. We listen first, then shape the work around how you actually run it.
What working with us looks like.
Four steps. Add a site, a supplier or a new asset, and the record still describes what you actually run.
Your operation, as it really is
Sites, networks, the IT and OT split, the monitoring platform in place. Built from what you run, not a sector template.
What is missing, ranked
One ranked list, worst first, with the OT findings in it. Each item says what closes it, so nobody has to relitigate the running order.
Do the work
Start with the compliance side: write the policy, run the training, name the owner. Where a gap turns out to be technical, our Security Operations pillar closes it, switched on when the list calls for it.
Hold the evidence
Evidence builds as the work happens: control state with dates, risk decisions with owners, board approvals. When the authority or a municipal client asks, the pack is current.