Details
Initial situation and challenge
The municipal waste management company’s waste-to-energy plant provides thermal recycling of combustible waste for approximately 1.2 million people in the region. The incineration lines, with a throughput of over 32 metric tons per hour, convert residual waste into process steam for energy generation. As a German critical infrastructure facility, the waste-to-energy plant is subject to a wide range of regulatory requirements:
- Continuous monitoring of complex process engineering components, such as multistage exhaust gas treatment,
- Strict regulatory inspections in accordance with the Federal Immission Control Act (BImSchG).
- Failure-free operation in accordance with ISO 14001.
- Operation of an intrusion detection system in critical industrial facilities in accordance with the NIS2 transition law (NIS2UmsuCG).
The biggest challenge within the framework of the Information Security Management System (ISMS) was to ensure comprehensive transparency of the increasingly networked process control technology and to continuously monitor it for cyberattacks and error conditions in accordance with cybersecurity regulations.
The waste management company identified three objectives to be achieved with a solution

1. Detection of anomalies and error states
Continuously monitor OT communication of the incineration lines to detect cyber risks and unwanted changes early-on.
2. Enhanced legal compliance
Strengthen the continuous optimization process by assessing the ISMS security levels and by implementing cybersecurity requirements for critical entities.
3. Fast, informed root-cause analysis
Document all details of cyber incidents to precisely locate network error states and deterioration to accelerate mitigation measures.
Solution

Rhebo Industrial Security & Stability Assessment
- Analyze OT assets and communication structure for existing vulnerabilities and security risks.
- Assess risks to the stability and security of the waste-to-energy plant and define mitigation measures.

Rhebo Industrial Protector
- Ensure continuous 24/7 security monitoring of the entire OT.
- Identify malware, cyberattacks, security risks and technical error states in real time.

Rhebo Managed Protection
- Ensure correct assessment of anomalies with experts of the Rhebo service team.
- Bridge the skills gap with expert support and knowledge transfer.
Implementation and findings
In the first step, as part of a Rhebo Industrial Security & Stability Assessment, the current OT communication and infrastructure were thoroughly examined. This process identified both cybersecurity risks and digital risks to the availability of the systems resulting in the definition of adequate mitigation measures. Furthermore, it established transparency in the OT network by visualizing its assets, identifying outdated firmware versions, and evaluating the quality of OT communication.
This analysis also formed the basis for baselining – the definition of the authorized communication pattern in OT – for the network-based intrusion detection system (NIDS) Rhebo Industrial Protector. The NIDS was thus able to go live immediately afterward with a very short training period. Since then, it has enabled the team to quickly resolve errors in OT communication as well as cybersecurity threats, thereby ensuring the long-term security of the waste-to-energy processes.
With the Rhebo Managed Protection (Gold) service, the waste management company is strengthening its IT/OT security team through weekly analysis of identified anomalies in collaboration with Rhebo’s service team. This helps bridge the existing shortage of skilled personnel and build internal OT security expertise through direct collaboration and knowledge transfer.
















