Ensuring system availability

at a
manufacturer and operator of smart grid edge devices
The international vendor of critical smart grid devices also operates an installed fleet of tens of thousands of edge devices worldwide – making it directly responsible for their availability and functionality in daily operations.

Detection of OT security risks

in
multiple food production lines
The food manufacturing company with over 20,000 employees in more than two dozen countries sought visibility and clarity on existing cybersecurity risks in its production lines.

Global 24/7 Cybersecurity For Renewable Energy Resources

at
BayWa r.e. Data Services GmbH
The BayWa r.e. AG designs, builds and operates wind farms and photovoltaic (PV) parks worldwide. 99 % of technical operations management, servicing and maintenance are carried out via remote access.

Network Intrusion Detection with Rhebo support

at
Stadtwerke Bochum Netz
Stadtwerke Bochum Holding has been a reliable supply partner for all Bochum residents since 1855. Today, Stadtwerke Bochum provides around 3,600 GWh of electricity and around 2,900 GWh of gas every year. It also provides water, district heating, telecommunications products, and solutions for the expansion of e-mobility. As a modern, customer-oriented company, Stadtwerke Bochum actively addresses the requirements and challenges of the times.

Verification of Network Segmentation at German Water Company

at
Waterworks Leipzig
The German water company Leipziger Wasserwerke (LWW) is a subsidiary of the Leipziger Gruppe. With 5 water plants, the company supplies 545,000 people in the Leipzig region with fresh and high-quality drinking water. It also treats 95,000 m³ of waste water per day in 25 sewage treatment plants.

Sabotage Investigation in Logistics Companies

at
Digital Forensics GmbH
Digital Forensics GmbH is a german company specializing in forensic analysis of large-volume network traffic in industry and insurance. The company evaluates cases of damage and analyses cyber attacks. Knowledge of industry-specific protocols such as Profinet, OPC, S7 or IEC61850 as well as their evaluation form a focal point of the work.

Secure Energy Supply For Over 1 Million People

at
Thüringer Energienetze GmbH & Co. KG
TEN Thüringer Energienetze is the largest distribution network operator in the German federal state of Thuringia. Its networks reliably supply more than 1.1 million people, the domestic economy and downstream distributors with energy. TEN provides all infrastructure services for the supply of electricity and natural gas, the connection of decentralized energy resources and, as part of its services, network operation for third parties.

Real-Time Security and Continuous Improvement Of Energy Supply

at
e-netz Südhessen AG
Anchored in Darmstadt, e-netz Südhessen AG, as a subsidiary of ENTEGA AG, takes care of the secure energy supply and the functioning infrastructure for around one million people in the region - from private households to municipal facilities, operators of solar systems and wind farms to industrial companies, scientific and research institutions.

Defense-in-Depth in the OT networks

at
MEGA, der Monheimer Elektrizitäts- und Gasversorgung GmbH
As a municipal energy supplier and innovative service provider, MEGA is as much a part of Monheim as the Rhine. Personally and locally, we create a warm, bright home for the people of Monheim with a fast digital window to the world. For over 100 years, we have been helping to make Monheim am Rhein a livable and attractive city - for families and companies.

Ensuring ICS Cybersecurity of Energy Providers

at
EWR Netz GmbH
In addition to its core business as a public network operator for electricity, gas and water, EWR Netz GmbH offers many different services with its qualified employees and extensive technical equipment. Regional network operators such as EWR Netz GmbH play an important role in the energy transition, as renewable energies and decentralized generation plants are feeding more and more electricity into the networks.

Intrusion Detection & Mitigation

at
sonnen GmbH
In 2018, sonnen GmbH has been the first provider in Germany to network residential and commercial energy storage systems into a virtual power plant. sonnen GmbH is building an energy system that provides clean electricity at exactly the right time and where it is needed. A system that enables cost benefits for everyone while relieving the strain on the power grid. In addition, the sonnen Virtual Power Plant (VPP) plays an important role in the energy transition: Through its storage system, the company is globally ensuring that more and more renewable energies can be connected to the grid. This stabilises the energy grids and accelerates the transition to sustainable energy supply.

Details

Initial situation and challenge

The edge devices for the smart grid are distributed worldwide and controlled centrally by the vendor. Due to the evolving risk landscape for IIoT devices, the vendor integrated the security monitoring solution Rhebo IIoT Security with anomaly detection as agents on the edge devices. These agents monitor communication and processes on the edge devices locally and report anomalies in real time.  

The agent also detects processes that indicate malfunctions or technical errors on the edge devices. During the monitoring, the Rhebo team noticed unusual behavior patterns in a regionally limited cluster of the tens of thousands of monitored smart grid edge devices. The security monitoring agent was repeatedly restarted at an unusually high frequency.

Solution

Rhebo IIoT Security

Endpoint Detection & Response

  • continuously monitors the edge devices’ behaviors,
  • identifies, analyzes and reports cyber attacks and error states in real time,
  • provides optional fleet protection against critical events via automated security policies.

Containerized IIoT security monitoring

  • allows for fast and low-footprint integration on controls of globally distributed edge devices,
  • enables cost-efficient maintenance of security solution,
  • enables security monitoring on edge devices with limited resources.

Implementation and findings

The operation of the security monitoring of Rhebo IIoT Security is provided as a managed service by the Rhebo support team. During the evaluation of various metrics, Rhebo noticed that the security monitoring agents on several dozen edge devices in the fleet were repeatedly restarting.  

Together with the vendor, the specific devices were examined via the control platform of the edge devices. As it turned out, the trigger for the monitoring agent restarts was that the edge devices themselves were repeatedly restarted. As a result, the devices were not optimally available and usable for customers of the smart grid. These restarts weren't detected before on the control platform itself due to specific metric settings and a fleet of several tens of thousands of devices. They were lost in the noise.  

Thanks to the security monitoring, the malfunctioning devices were detected and localized quickly. The vendor was able to examine the devices in a targeted manner and eliminate the error.

Results

REAL-TIME ALERT OF TECHNICAL MALFUNCTIONING

through continuous monitoring of the device communication.

PINPOINT LOCALIZATION OF MALFUNCTIONING DEVICES

through agent-based deployment directly on the edge devices.

BRIDGING THE PREVAILING SKILLS GAP

with security monitoring as managed services by Rhebo.

Also interesting

Anne Grätz

Get in touch with us

Write or call us to discuss your requirements for OT cybersecurity and intrusion detection.
Contact us