Global 24/7 Cybersecurity For Renewable Energy Resources

at
BayWa r.e. Data Services GmbH
The BayWa r.e. AG designs, builds and operates wind farms and photovoltaic (PV) parks worldwide. 99 % of technical operations management, servicing and maintenance are carried out via remote access.

Network Intrusion Detection with Rhebo support

at
Stadtwerke Bochum Netz
Stadtwerke Bochum Holding has been a reliable supply partner for all Bochum residents since 1855. Today, Stadtwerke Bochum provides around 3,600 GWh of electricity and around 2,900 GWh of gas every year. It also provides water, district heating, telecommunications products, and solutions for the expansion of e-mobility. As a modern, customer-oriented company, Stadtwerke Bochum actively addresses the requirements and challenges of the times.

Verification of Network Segmentation at German Water Company

at
Waterworks Leipzig
The German water company Leipziger Wasserwerke (LWW) is a subsidiary of the Leipziger Gruppe. With 5 water plants, the company supplies 545,000 people in the Leipzig region with fresh and high-quality drinking water. It also treats 95,000 m³ of waste water per day in 25 sewage treatment plants.

Sabotage Investigation in Logistics Companies

at
Digital Forensics GmbH
Digital Forensics GmbH is a german company specializing in forensic analysis of large-volume network traffic in industry and insurance. The company evaluates cases of damage and analyses cyber attacks. Knowledge of industry-specific protocols such as Profinet, OPC, S7 or IEC61850 as well as their evaluation form a focal point of the work.

Secure Energy Supply For Over 1 Million People

at
Thüringer Energienetze GmbH & Co. KG
TEN Thüringer Energienetze is the largest distribution network operator in the German federal state of Thuringia. Its networks reliably supply more than 1.1 million people, the domestic economy and downstream distributors with energy. TEN provides all infrastructure services for the supply of electricity and natural gas, the connection of decentralized energy resources and, as part of its services, network operation for third parties.

Real-Time Security and Continuous Improvement Of Energy Supply

at
e-netz Südhessen AG
Anchored in Darmstadt, e-netz Südhessen AG, as a subsidiary of ENTEGA AG, takes care of the secure energy supply and the functioning infrastructure for around one million people in the region - from private households to municipal facilities, operators of solar systems and wind farms to industrial companies, scientific and research institutions.

Defense-in-Depth in the OT networks

at
MEGA, der Monheimer Elektrizitäts- und Gasversorgung GmbH
As a municipal energy supplier and innovative service provider, MEGA is as much a part of Monheim as the Rhine. Personally and locally, we create a warm, bright home for the people of Monheim with a fast digital window to the world. For over 100 years, we have been helping to make Monheim am Rhein a livable and attractive city - for families and companies.

Ensuring ICS Cybersecurity of Energy Providers

at
EWR Netz GmbH
In addition to its core business as a public network operator for electricity, gas and water, EWR Netz GmbH offers many different services with its qualified employees and extensive technical equipment. Regional network operators such as EWR Netz GmbH play an important role in the energy transition, as renewable energies and decentralized generation plants are feeding more and more electricity into the networks.

Intrusion Detection & Mitigation

at
sonnen GmbH
Since 2018, Sonnen GmbH has been the first and so far only provider in Germany to connect private home storage systems to form a virtual power plant. Sonnen GmbH is building an energy system that provides clean electricity at exactly the right time and where it is needed. A system that enables cost benefits for everyone while relieving the strain on the power grid. In addition, the sonnenVPP plays an important role in the energy transition. By stabilizing the energy grids on three continents, the company is ensuring that more and more renewable energies can be connected to the grid, thus accelerating the transition to clean energy.

Dipl.-Ing (TU) Sven Hanemann

»With Rhebo we can actively make sure that our Industrial Automation & Control System (IACS) is stable and secure. Rhebo provides the detailed visibility into our IACS to rapidly identify and mitigate novel attacks and misconfigurations that have been invisible to us in the past.«
To story download

Details

Initial situation and challenge

As a distribution network operator of Entega AG, e-netz Südhessen AG reliably supplies electricty and gas to one million people in 63 municipalities in the German Rhein-Main-Neckar region. As a sustainable, future-oriented energy and infrastructure service provider, e-netz Südhessen stands for reliable operation and the innovative advancement of its networks towards energy transition. Since 2010, the company has been implementing quality, energy, occupational health and safety as well as environmental management systems according to ISO 9001, ISO 50001, ISO 45001 and ISO 14001, respectively. In 2012 e-netz Südhessen implemented a certified Information Security Management Systems (ISMS). In order to continuously improve the growing infrastructure, the IACS is to be periodically audited for vulnerabilities and optimisation. In addition, the company wanted an intelligent embedded system that would comprehensively secure the IACS against cyberattacks, misconfigurations and technical error states.

Detection of attacks and error states

Continuously monitor IACS communication (IEC104) on value level to detect and mitigate any anomaly in real-time.

Fast, sound analysis of events

Document all event details to enable root cause analysis and traceability of affected devices.

Support of ISMS re-certification

Establish continuous improvement process as well as evaluation of security levels and implemented measures.

Solution

RISK ANALYSIS

Rhebo Industry 4.0 Stability and Security Audit

  • Analysis of assets and communication structures;
  • Risk assessment for cybersecurity and stability;
  • Definition of mitigation measures.

IACS MONITORING

Rhebo Industrial Protector

  • Continuous IACS monitoring;
  • Real-time identification and evaluation of cyberattacks, vulnerabilities, malware and technical error states;
  • Compliance with industry standards and regulatory requirements.

CONTINUOUS IMPROVEMENT

Rhebo Managed Protection

  • Periodic Industry 4.0 Stability and Security Audits
  • Forensic analysis of security and stability events;
  • Emergency support.

Implementation and findings

Rhebo performed a Rhebo Industry 4.0 Stability and Security Audit of the e-netz Südhessen’s IACS. Using three passive sensors, all communication via Ethernet, mobile and the corporate network was recorded and analysed by Rhebo. The results proved a very well managed and secured infrastructure. Further use cases (e.g. connection of a substation) were simulated to evaluate the functionality of the IACS monitoring solution Rhebo Industrial Protector. The detailed monitoring data, extremely good traceability of events as well as the customisation of the dashboard convinced e-netz Südhessen to integrate Rhebo Industrial Protector with a total of seven data tapping points. Rhebo will also support e-netz Südhessen with periodic audits and forensic analysis as part of the Rhebo Managed Protection Level Agreement. This service helps e-netz Südhessen to continuously improve its security infrastructure and get immediate assistance whenever events occur.

  • The network map visualises all assets in the ICS with their properties and connections.
  • For each host, details such as protocols, connections, and anomalies are displayed in real-time.
  • Rhebo Industrial Protector reports insecure operations such as scans and unencrypted passwords.

Results

COMPLETE TRANSPARENCY

of the structure, assets and connections of the IACS.

REAL-TIME ALERTS

and documentation of anomalies ensured.

CONTINUOUS IMPROVEMENT

according to ISO 27001 and ISO 9001 supported with periodic risk analysis.

CONTINUOUS MONITORING

of communication within the IACS.

TRACEABILITY AND RISK ASSESSMENT

of incidents significantly improved.

STABLE OPERATION OF THE IACS

strengthened by identification and analysis of misconfigurations.

Also interesting