Public administration
Public sector IT is heterogeneous, and so is responsibility for it: a system is run by a service provider, owned by an authority and supervised under state law. So the first question is not how NIS2 gets implemented, but which unit falls under what.
Two cases that shaped German public sector IT
In July 2021 a rural district in Saxony-Anhalt declared a state of disaster after a ransomware attack. It was the first state of disaster in Germany caused by a cyber attack. Social benefits could not be paid out normally for weeks, and recovery took months.
In October 2023 it hit a municipal IT service provider in Südwestfalen. Around seventy administrations were affected at once: citizen portals offline, specialist systems unreachable, vehicle registration and citizen service offices on emergency operation. The way in led through a remote access path.
The second case is the more instructive one. In a shared structure your own security position is not yours alone. Anyone working in such a structure has to know what is reachable from the provider network and what is reachable in the other direction.
Classify, test, detect
In that order, because until the classification is settled it is not clear which evidence is required at all.
Establish what applies
Which of your units falls under what. For municipal utilities and publicly owned enterprises the answer is often different from the core administration, and different evidence duties follow from it.
Test portals and systems
Citizen and application portals with their authentication, permissions and data leaving through interfaces, specialist systems and their connection to central directory services, and the shared structure itself.
Involve people
Phishing resilience and reporting behaviour among staff, agreed with the works council and without putting anyone on the spot. What is measured is the reporting rate, not the click rate alone.
Where a test in public administration starts
At the portal, because it is publicly reachable and because authentication, permission checks and interfaces all come together there. Then at the specialist system and its connection to the directory service, because a service account taken over works across system boundaries.
One point regularly overlooked is the building and facility technology. Access control, heating and ventilation often hang on the same network as the administrative systems, but are neither inventoried nor monitored.
And finally the shared-structure question: what is reachable from the provider network, and what is reachable there from you. That direction is rarely tested, although on the day it decides how far an incident reaches.
Monitoring in a shared structure
In a shared structure, operation and responsibility lie apart. That is precisely why it has to be settled in advance who sees which events, who assesses them, and who acts on the day.
We bring the data sources together, develop use cases for the routes used in both incidents, and fix the reporting chains. Alongside them, playbooks for the case where it is not your organisation that is hit but your service provider.
Phishing simulation without shaming anyone
A campaign that is realistic but not humiliating. The evaluation is anonymised and at group level, agreed with the works council.
More interesting than the click rate is the reporting rate. An organisation where suspicious messages get reported quickly gains time, and in a ransomware attack time is the only resource that counts.
What applies to you, and what expressly does not
This point is frequently overstated, so precisely: Germany has not made use of the option to extend the scope of the NIS2 directive to public administration bodies at local level. The federal states govern implementation for their own area, and what applies to a state authority follows from the respective state law.
In practice that means the first question is not how NIS2 gets implemented, but which of your units falls under what. For municipal utilities and publicly owned enterprises the answer is regularly different from the core administration.
IT-Grundschutz, the German federal baseline protection framework, is untouched by that and remains the established frame: structure analysis, protection requirement assessment, modelling, baseline security check. A security test supplies the evidence of effectiveness for what was modelled.
What authorities, enterprises and providers ask
For the municipal level, Germany did not extend the scope. For state authorities it is decided by state law; for municipal utilities and publicly owned enterprises, often by their commercial activity. We make that classification at the beginning, not at the end.
Grundschutz describes what should be in place. A test shows whether it works. Together they make the evidence; neither does on its own.
That can be settled, and we settle it before starting. What matters is that the test scope covers the interface in both directions, otherwise exactly the route that was used in practice goes untested.
Yes, if it is anonymised and evaluated at group level from the outset. We agree the approach beforehand. The aim is a higher reporting rate, not a list of names.
Suited to this sector.
- Penetration testing and assessments Web, network, cloud, API, red teaming, OSINT.
- SOC, SIEM and monitoring Design, SIEM engineering, detection.
- NIS2 consulting NIS2: establishing what applies, the evidence, and the implementation.
- Phishing simulations Realistic campaigns, measurable awareness, without shaming anyone.