SucheKontaktRessourcen

Network-based Intrusion Detection

in a waste-to-energy plant
A municipal waste management facility secures its waste-to-energy plant with Rhebo Industrial Protector against cyberattacks and technical anomalies.

Ensuring system availability

at a manufacturer and operator of smart grid edge devices
The international vendor of critical smart grid devices also operates an installed fleet of tens of thousands of edge devices worldwide – making it directly responsible for their availability and functionality in daily operations.

Detection of OT security risks

in multiple food production lines
The food manufacturing company with over 20,000 employees in more than two dozen countries sought visibility and clarity on existing cybersecurity risks in its production lines.

OT security monitoring and risk assessment

in the chemical industry

Network Intrusion Detection with Rhebo support

for multi-utility Stadtwerke Bochum Netz
Stadtwerke Bochum Holding has been a reliable supply partner for all Bochum residents since 1855. Today, Stadtwerke Bochum provides around 3,600 GWh of electricity and around 2,900 GWh of gas every year. It also provides water, district heating, telecommunications products, and solutions for the expansion of e-mobility. As a modern, customer-oriented company, Stadtwerke Bochum actively addresses the requirements and challenges of the times.

Verification of Network Segmentation at German Water Company

at water & waste water utility Leipziger Wasserwerke
The German water company Leipziger Wasserwerke (LWW) is a subsidiary of the Leipziger Gruppe. With 5 water plants, the company supplies 545,000 people in the Leipzig region with fresh and high-quality drinking water. It also treats 95,000 m³ of waste water per day in 25 sewage treatment plants.

Sabotage Investigation in Logistics Companies

with Rhebo and Digital Forensics GmbH
Digital Forensics GmbH is a german company specializing in forensic analysis of large-volume network traffic in industry and insurance. The company evaluates cases of damage and analyses cyber attacks. Knowledge of industry-specific protocols such as Profinet, OPC, S7 or IEC61850 as well as their evaluation form a focal point of the work.

Secure Energy Supply For Over 1 Million People

at energy provider TEN - Thüringer Energienetze GmbH & Co. KG
TEN Thüringer Energienetze is the largest distribution network operator in the German federal state of Thuringia. Its networks reliably supply more than 1.1 million people, the domestic economy and downstream distributors with energy. TEN provides all infrastructure services for the supply of electricity and natural gas, the connection of decentralized energy resources and, as part of its services, network operation for third parties.

Real-Time Security of Energy Supply

at multi-utility e-netz Südhessen AG
Anchored in Darmstadt, e-netz Südhessen AG, as a subsidiary of ENTEGA AG, takes care of the secure energy supply and the functioning infrastructure for around one million people in the region - from private households to municipal facilities, operators of solar systems and wind farms to industrial companies, scientific and research institutions.

Defense-in-Depth in the OT networks

of mulit-utility MEGA Monheim
As a municipal energy supplier and innovative service provider, MEGA is as much a part of Monheim as the Rhine. Personally and locally, we create a warm, bright home for the people of Monheim with a fast digital window to the world. For over 100 years, we have been helping to make Monheim am Rhein a livable and attractive city - for families and companies.

Ensuring ICS Cybersecurity of Energy Distribution

at multi-utility EWR Netz GmbH
In addition to its core business as a public network operator for electricity, gas and water, EWR Netz GmbH offers many different services with its qualified employees and extensive technical equipment. Regional network operators such as EWR Netz GmbH play an important role in the energy transition, as renewable energies and decentralized generation plants are feeding more and more electricity into the networks.

Intrusion Detection of IoT Edge Devices

at energy storage system vendor sonnen GmbH
In 2018, sonnen GmbH has been the first provider in Germany to network residential and commercial energy storage systems into a virtual power plant. sonnen GmbH is building an energy system that provides clean electricity at exactly the right time and where it is needed. A system that enables cost benefits for everyone while relieving the strain on the power grid. In addition, the sonnen Virtual Power Plant (VPP) plays an important role in the energy transition: Through its storage system, the company is globally ensuring that more and more renewable energies can be connected to the grid. This stabilises the energy grids and accelerates the transition to sustainable energy supply.

Details

Initial situation and challenge

The municipal waste management company’s waste-to-energy plant provides thermal recycling of combustible waste for approximately 1.2 million people in the region. The incineration lines, with a throughput of over 32 metric tons per hour, convert residual waste into process steam for energy generation. As a German critical infrastructure facility, the waste-to-energy plant is subject to a wide range of regulatory requirements:

  • Continuous monitoring of complex process engineering components, such as multistage exhaust gas treatment,  
  • Strict regulatory inspections in accordance with the Federal Immission Control Act (BImSchG).  
  • Failure-free operation in accordance with ISO 14001.
  • Operation of an intrusion detection system in critical industrial facilities in accordance with the NIS2 transition law (NIS2UmsuCG).

The biggest challenge within the framework of the Information Security Management System (ISMS) was to ensure comprehensive transparency of the increasingly networked process control technology and to continuously monitor it for cyberattacks and error conditions in accordance with cybersecurity regulations.

The waste management company identified three objectives to be achieved with a solution

Heating oven of energy from waste plant

1. Detection of anomalies and error states

Continuously monitor OT communication of the incineration lines to detect cyber risks and unwanted changes early-on.

2. Enhanced legal compliance

Strengthen the continuous optimization process by assessing the ISMS security levels and by implementing cybersecurity requirements for critical entities.

3. Fast, informed root-cause analysis

Document all details of cyber incidents to precisely locate network error states and deterioration to accelerate mitigation measures.

Solution

Arbeiter bedient Schaltkasten

Rhebo Industrial Security & Stability Assessment

  • Analyze OT assets and communication structure for existing vulnerabilities and security risks.  
  • Assess risks to the stability and security of the waste-to-energy plant and define mitigation measures.
Arbeiter bedient Schaltkasten

Rhebo Industrial Protector

  • Ensure continuous 24/7 security monitoring of the entire OT.
  • Identify malware, cyberattacks, security risks and technical error states in real time.
Arbeiter bedient Schaltkasten

Rhebo Managed Protection

  • Ensure correct assessment of anomalies with experts of the Rhebo service team.  
  • Bridge the skills gap with expert support and knowledge transfer.

Implementation and findings

In the first step, as part of a Rhebo Industrial Security & Stability Assessment, the current OT communication and infrastructure were thoroughly examined. This process identified both cybersecurity risks and digital risks to the availability of the systems resulting in the definition of adequate mitigation measures. Furthermore, it established transparency in the OT network by visualizing its assets, identifying outdated firmware versions, and evaluating the quality of OT communication.

This analysis also formed the basis for baselining – the definition of the authorized communication pattern in OT – for the network-based intrusion detection system (NIDS) Rhebo Industrial Protector. The NIDS was thus able to go live immediately afterward with a very short training period. Since then, it has enabled the team to quickly resolve errors in OT communication as well as cybersecurity threats, thereby ensuring the long-term security of the waste-to-energy processes.

With the Rhebo Managed Protection (Gold) service, the waste management company is strengthening its IT/OT security team through weekly analysis of identified anomalies in collaboration with Rhebo’s service team. This helps bridge the existing shortage of skilled personnel and build internal OT security expertise through direct collaboration and knowledge transfer.