Skip to main content

Applied OT security research: field experience from KRITIS sectors in rail and energy

A look back at the Forschungstag Cybersicherheit NRW: which results from our work in rail and energy environments we showed there, and what holds up in practice.

Railway security

On 30 April 2026, the Forschungstag Cybersicherheit NRW brought together people from research, industry and politics to discuss current work in cybersecurity research. As a security consultancy with a large research and development share, we used the occasion to present results from several years of applied research. The talk was called "Applied OT security research: field experience from KRITIS sectors in rail and energy".

OT systems are increasingly the target of attacks. In 2025, more than 30 wind and PV installations and a heating plant in Poland were attacked in a coordinated operation, with wiper malware and firmware manipulation on remote terminal units (CERT.PL). Industroyer and Industroyer2 showed in Ukraine in 2016 and 2022 how OT protocols such as IEC 60870-5-104 and IEC 61850 can be abused deliberately. Rail systems are affected too: in 2023 and 2024, Polish trains were stopped remotely because the radio protocol in use provided no authentication.

How do you defend against that? It is the question behind several of our research projects and behind our day-to-day consulting work.

Automotive and rail security

In the FINESSE research project we spent three years on threats to rail and road vehicles. On the basis of documented incidents we developed the VATT&EK framework, which provides 15 tactics and over 150 techniques for describing attacks on intelligent transport systems.

Two physical demonstrators came out of that: YekCar for automotive (with ECUs, CAN bus, UDS and a keyless system) and YekTrain for rail. We use both to run attacks, develop detection rules and test IDS and VSOC concepts.

On that basis we built the MVB-IDS, our own intrusion detection system for the Multifunction Vehicle Bus. Together with DB Systemtechnik we were able to test it in real operation on the Advanced TrainLab, a research train of Deutsche Bahn.

In parallel we classified the UDS diagnostic protocol, which is built into every modern vehicle, systematically (UDS Attack Taxonomy, IEEE CNS 2025) and developed monitoring strategies for a Vehicle Security Operations Center (From ECU to VSOC, arXiv 2510.25375). The multi-modal VSOC architecture underneath was published at CRITIS 2025 in Jönköping.

Energy sector

In the energy sector we run OT penetration tests in substations and power plants, covering the industrial protocols in use as well as control systems, engineering workstations and the IT/OT boundary. That work shows the same thing repeatedly: SOC teams and operating staff have almost no way to practise handling an OT attack without putting productive plant at risk.

Cyber ranges from the IT world fall short here. They neither represent industrial protocols such as IEC-104, IEC 61850 or Modbus realistically, nor make the physical effects of an attack on a controlled process visible. That link between digital anomalies in network traffic and concrete consequences in the plant is exactly what is needed to recognise an OT attack and judge it.

Out of our experience from OT pentests and SOC engineering came YekCity, a physical training environment with real industrial protocols (IEC 60870-5-104, IEC 61850 with GOOSE, MMS and SV, Modbus TCP, DNP3, PROFINET, S7, OPC UA), a network architecture segmented to the Purdue model, and a smart city model where switching states and power cuts become physically visible. Detection rules follow MITRE ATT&CK for ICS, and the platform works with the usual SIEM systems such as Splunk, Elastic and Microsoft Sentinel.

We use YekCity in emergency exercises and awareness training for operators of critical infrastructure. SOC teams practise detecting manipulated IEC-104 or MMS packets, red and blue team scenarios follow real APT campaigns such as Industroyer or Triton, and operating staff learn what a cyber attack does inside the plant.

Sources

The project: FINESSE, attack detection for road and rail

Questions about this?

Talk to our consultants.