Energy
Electricity, gas, oil and heating rely on operational technology, so most of the risk sits in industrial systems and with suppliers.
What the Act requires of this sector
Energy is the first sector of Annex I of the Act. The competent authority for cyber security requirements is the central state authority for cyber security, that is the Security and Intelligence Agency (SOA), and the competent CSIRT is the national cyber security centre (NCSC-HR).
The category follows size: entities above the ceilings for medium-sized enterprises are essential, and medium-sized ones important. In addition, the authority may classify an entity regardless of size under the special criteria of Article 11, if it is the sole provider in an area for instance.
The sector’s particularity is operational technology. For measures 5 and 6, Annex II states expressly which sub-measures apply to it without restriction and which depend on a risk assessment, so that line has to be drawn in writing rather than verbally.
Where this sector usually gets stuck
What we do for you
Who from the sector falls in scope
The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.
Coordinated attack on 22 energy companies
The attacks came in two waves and eleven companies were directly compromised. The first wave exploited a then unknown firewall vulnerability. A risk assessment that covers only the office network cannot see this scenario; SCADA systems, controllers and telemetry have to be in scope.
SOURCE: SektorCERT, the Danish CSIRT for critical infrastructure, incident report, 2023.
Frequently asked questions
The questions energy companies ask first, mostly about operational technology and suppliers.
Does the law apply to smaller distributors and heating utilities?
It does. In energy, smaller entities are often above the ceiling for medium-sized enterprises, and the competent authority may classify them regardless of size under Article 11.Do industrial control systems have to be in scope?
They do. A risk assessment covering only the office network misses most of the risk. SCADA systems, controllers and telemetry go into the asset register like everything else.How do we handle remote access by equipment suppliers?
Named accounts instead of shared ones, access opened on request and closed after the job, and a record of every session. It is also one of the most common audit findings.What if a system cannot be patched without vendor approval?
Compensating measures apply, together with a written justification of why patching is not possible. A missing patch is not in itself a finding; a missing justification is.How often is the continuity plan tested?
At least once a year, and by exercise rather than by reading. The exercise minutes are the evidence for the business continuity measure.Do all measures apply to operational technology?
Not in full. For measure 5, Annex II states that sub-measure 5.4 applies to OT subject to a risk assessment, while the rest apply in full. For measure 6, sub-measures 6.1, 6.3 and 6.5 apply in full, while 6.2 and 6.4 depend on a further assessment.What if a system cannot be taken down for a change?
Then a change window is planned and, until it opens, a compensating measure applies. What matters is that the deferral has a deadline, a justification and an owner, because without those it looks like a failing in an audit.Do sectoral rules apply alongside the Act?
They do. Alongside the Cybersecurity Act, energy also has critical infrastructure legislation and sectoral requirements, so the first step is to separate what falls under which, so the same work is not done twice.Related pages
The pages that set out in full what energy has to show in measures and evidence.
Let us look at where your network boundary sits.
Half an hour, no obligation. We look at where your office network ends and the operational network begins.
