Details
Initial situation and challenge
Stadtwerke Bochum Holding has been a reliable supply partner for all Bochum residents since 1855. Today, Stadtwerke Bochum provides around 3,600 GWh of electricity and around 2,900 GWh of gas every year. It also provides water, district heating, telecommunications products, and solutions for the expansion of e-mobility. As a modern, customer-oriented company, Stadtwerke Bochum actively addresses the requirements and challenges of the times. With the digitization of its critical infrastructure, this also included securing its substations and renewable energy plants against cyberattacks. In 2017, the local supplier therefore implemented an information and security management system (ISMS) in accordance with ISO 27001. Stadtwerke Bochum Netz, as part of Stadtwerke Bochum Holding, had already been addressing the need for an OT intrusion detection system for their critical infrastructure for four years before it was made mandatory by German authorities. This solution had to provide two key capabilities:
- Early detection of even successful attacks within the operational technology to prevent them from reaching the control center. In addition to the detection of malware that might have bypassed the firewall via service provider laptops (supply chain compromise), this also includes the identification of systems and communication behavior that endanger the cyber security of the OT.
- Support by the company providing the network intrusion detection system with forensic analysis of anomalies to compensate for the continued shortage of specialists in the field of OT cyber security and to build in-house know-how.
Solution

OT risk analysis and vulnerability assessment
Rhebo Industrial Security Assessment
- analyze assets and communication structures,
- identify vulnerabilities and security gaps,
- define measures for system hardening.

OT network intrusion detection system
Rhebo Industrial Protector
- continuously monitor the OT network communication,
- identify and analyze cyberattacks, security vulnerabilities, malware, and error states in real time.

On-demand OT security support
Rhebo Managed Protection
- conduct periodic vulnerability assessments,
- regularly evaluate identified anomalies with Rhebo experts,
- get emergency support.
Implementation and findings
At the end of 2019, Rhebo conducted a Rhebo Industrial Security Assessment for Stadtwerke Bochum Netz. The OT networks of the energy supply infrastructure were analyzed for existing vulnerabilities and security risks, their criticality was assessed, and recommendations for remediation were made. All detected anomalies were subsequently resolved in a targeted manner. Once the security risks had been eliminated, the OT monitoring with anomaly detection Rhebo Industrial Protector used during the assessment started continuous operation. Since then, the dedicated network intrusion detection system has been monitoring the OT networks for electricity, gas, and water as well as the interface to the company's IT. With the introduction of OT monitoring in 2019, the company also needed to acquire expertise on the still new topic of OT security. Faced with the ongoing shortage of skilled workers, Stadtwerke Bochum Netz decided to train the existing team on the job. Stadtwerke Bochum Netz operates the Rhebo intrusion detection system independently, but regularly accesses the expertise of the Rhebo team. As part of the OT security service Rhebo Managed Protection, the security team discusses conspicuous or unclear anomalies identified by Rhebo Industrial Protector with the Rhebo support team on a weekly basis and coordinates the next steps. This has not only enabled the localization and elimination of frequent network and communication errors or nonsecure OT components. Security risks from service providers, such as the use of SNMPv1 and NTLMv1, which would otherwise have remained invisible, have also been quickly identified and addressed with the subcontractor.