Details
Initial situation and challenge
As a distribution network operator of Entega AG, e-netz Südhessen AG reliably supplies electricty and gas to one million people in 63 municipalities in the German Rhein-Main-Neckar region. As a sustainable, future-oriented energy and infrastructure service provider, e-netz Südhessen stands for reliable operation and the innovative advancement of its networks towards energy transition. Since 2010, the company has been implementing quality, energy, occupational health and safety as well as environmental management systems according to ISO 9001, ISO 50001, ISO 45001 and ISO 14001, respectively. In 2012 e-netz Südhessen implemented a certified Information Security Management Systems (ISMS). In order to continuously improve the growing infrastructure, the IACS is to be periodically audited for vulnerabilities and optimisation. In addition, the company wanted an intelligent embedded system that would comprehensively secure the IACS against cyberattacks, misconfigurations and technical error states.
Detection of attacks and error states
Continuously monitor IACS communication (IEC104) on value level to detect and mitigate any anomaly in real-time.
Fast, sound analysis of events
Document all event details to enable root cause analysis and traceability of affected devices.
Support of ISMS re-certification
Establish continuous improvement process as well as evaluation of security levels and implemented measures.
Solution

Risk analysis
Rhebo Industry 4.0 Stability and Security Audit
- Analysis of assets and communication structures;
- Risk assessment for cybersecurity and stability;
- Definition of mitigation measures.

IACS monitoring
Rhebo Industrial Protector
- Continuous IACS monitoring;
- Real-time identification and evaluation of cyberattacks, vulnerabilities, malware and technical error states;
- Compliance with industry standards and regulatory requirements.

Continuous improvement
Rhebo Managed Protection
- Periodic Industry 4.0 Stability and Security Audits
- Forensic analysis of security and stability events;
- Emergency support.
Implementation and findings
Rhebo performed a Rhebo Industry 4.0 Stability and Security Audit of the e-netz Südhessen’s IACS. Using three passive sensors, all communication via Ethernet, mobile and the corporate network was recorded and analysed by Rhebo. The results proved a very well managed and secured infrastructure. Further use cases (e.g. connection of a substation) were simulated to evaluate the functionality of the IACS monitoring solution Rhebo Industrial Protector. The detailed monitoring data, extremely good traceability of events as well as the customisation of the dashboard convinced e-netz Südhessen to integrate Rhebo Industrial Protector with a total of seven data tapping points. Rhebo will also support e-netz Südhessen with periodic audits and forensic analysis as part of the Rhebo Managed Protection Level Agreement. This service helps e-netz Südhessen to continuously improve its security infrastructure and get immediate assistance whenever events occur.
- The network map visualises all assets in the ICS with their properties and connections.
- For each host, details such as protocols, connections, and anomalies are displayed in real-time.
- Rhebo Industrial Protector reports insecure operations such as scans and unencrypted passwords.