Critical Infrastructure — operationalised.
Sector-specific resilience for operators of essential services.
OT/ICS security baselines aligned to NIS2 Annex I — energy, finance, health, transport, water and digital infrastructure.
Critical infrastructure operators carry an asymmetric burden: a single outage can cascade across borders, sectors and citizens. ENISA's Critical Information Infrastructure Protection (CIIP) workstream produces sectoral guidance, threat landscapes and certification schemes that we operationalise inside client environments. Our practice combines IT/OT convergence expertise with deep regulatory fluency in NIS2 Annex I sectors.
Open CIIP topic on ENISA- Regulatory anchor
- NIS2 Annex I + sectoral acts (DORA, eIDAS2, etc.)
- Sectors covered
- Energy, transport, finance, health, water, digital, public admin, space
- OT standard
- IEC 62443 — industrial automation & control systems
- Sectoral ETLs
- Transport, Health, 5G, Space published by ENISA
What this framework covers
IT/OT convergence challenges
Operational technology environments were not designed for an internet-connected world. Common patterns we see across utilities, manufacturing and healthcare include long-lived assets, deterministic protocols, limited patch windows and shared engineering workstations.
- ›Asset visibility — passive discovery before any active scanning
- ›Network segmentation — Purdue model zones and conduits
- ›Secure remote access — jump hosts, MFA and session recording for vendors
- ›Vulnerability management — risk-based, not CVSS-based, given patch constraints
- ›Safety-aware incident response — IR plans that preserve human safety first
Cross-border dependencies
ENISA's work on cross-border dependencies highlights how a compromise in one Member State can cascade across the single market. We model these dependencies explicitly in client BCM and crisis exercises.
- ›Single points of failure in shared services (cloud, identity, DNS, time)
- ›Sectoral interconnects — energy/finance, transport/logistics, health/digital
- ›Cascading impact analysis built into NIS2 risk assessments
Sectoral CSIRTs & ISACs
We help clients plug into the right information-sharing communities so threat intelligence flows in and incident notifications flow out efficiently.
- ›National CSIRT and CSIRTs Network channels
- ›Sectoral ISACs (energy, finance, health, transport)
- ›EU-CyCLONe coordination for large-scale cross-border incidents
Critical infrastructure programme components
- IT/OT asset inventory using passive discovery and protocol-aware sensors
- Architecture review against IEC 62443 zones, conduits and security levels
- Secure remote access design for OEMs and third-party engineers
- OT-aware SOC use cases and 24/7 monitoring of ICS protocols
- Cross-border cascading impact modelling for NIS2 risk assessment
- Sectoral tabletop exercises validated against EU-CyCLONe scenarios