Skip to main content

Public administration

Public sector IT is heterogeneous, and so is responsibility for it: a system is run by a service provider, owned by an authority and supervised under state law. So the first question is not how NIS2 gets implemented, but which unit falls under what.

Cybersicherheit fuer die oeffentliche Verwaltung Portal, Fachverfahren und Verzeichnisdienst im Verwaltungsnetz, der Verbund zum Dienstleister und die Gebaeudetechnik am selben Netz. Darunter, was dafuer angeboten wird. ADMINISTRATIVE NETWORK PORTAL · APPLICATIONS LINE-OF-BUSINESS APPS DIRECTORY SERVICE PROVIDER BOTH DIRECTIONS? BUILDING SYSTEMS PENTESTPORTALS SOCRESPONSE NIS-2IN SCOPE? PHISHINGREPORTING RATE PUBLIC ADMINISTRATION · IT-GRUNDSCHUTZ AS THE FRAMEWORK
Threat picture

Two cases that shaped German public sector IT

In July 2021 a rural district in Saxony-Anhalt declared a state of disaster after a ransomware attack. It was the first state of disaster in Germany caused by a cyber attack. Social benefits could not be paid out normally for weeks, and recovery took months.

In October 2023 it hit a municipal IT service provider in Südwestfalen. Around seventy administrations were affected at once: citizen portals offline, specialist systems unreachable, vehicle registration and citizen service offices on emergency operation. The way in led through a remote access path.

The second case is the more instructive one. In a shared structure your own security position is not yours alone. Anyone working in such a structure has to know what is reachable from the provider network and what is reachable in the other direction.

What follows

Classify, test, detect

In that order, because until the classification is settled it is not clear which evidence is required at all.

Establish what applies

Which of your units falls under what. For municipal utilities and publicly owned enterprises the answer is often different from the core administration, and different evidence duties follow from it.

Test portals and systems

Citizen and application portals with their authentication, permissions and data leaving through interfaces, specialist systems and their connection to central directory services, and the shared structure itself.

Involve people

Phishing resilience and reporting behaviour among staff, agreed with the works council and without putting anyone on the spot. What is measured is the reporting rate, not the click rate alone.

Testing

Where a test in public administration starts

Cybersicherheit fuer die oeffentliche Verwaltung Portal, Fachverfahren und Verzeichnisdienst im Verwaltungsnetz, der Verbund zum Dienstleister und die Gebaeudetechnik am selben Netz. Darunter, was dafuer angeboten wird. ADMINISTRATIVE NETWORK PORTAL · APPLICATIONS LINE-OF-BUSINESS APPS DIRECTORY SERVICE PROVIDER BOTH DIRECTIONS? BUILDING SYSTEMS PENTESTPORTALS SOCRESPONSE NIS-2IN SCOPE? PHISHINGREPORTING RATE PUBLIC ADMINISTRATION · IT-GRUNDSCHUTZ AS THE FRAMEWORK

At the portal, because it is publicly reachable and because authentication, permission checks and interfaces all come together there. Then at the specialist system and its connection to the directory service, because a service account taken over works across system boundaries.

One point regularly overlooked is the building and facility technology. Access control, heating and ventilation often hang on the same network as the administrative systems, but are neither inventoried nor monitored.

And finally the shared-structure question: what is reachable from the provider network, and what is reachable there from you. That direction is rarely tested, although on the day it decides how far an incident reaches.

Detection

Monitoring in a shared structure

Aufbau eines SOC Quellen laufen in eine Sammlung, die alles auf ein Schema bringt. Darauf Detection-Regeln mit ihrer Abdeckung, daneben Alarme und Playbooks. Der Rueckweg schaerft die Regeln nach. SOURCES COLLECTION DETECTION RESPONSE NETWORK ENDPOINTS IDENTITY CLOUD ONE SCHEME RULES AS CODE PLAYBOOKS SOC BUILD · COLLECT, DETECT, RESPOND, TUNE

In a shared structure, operation and responsibility lie apart. That is precisely why it has to be settled in advance who sees which events, who assesses them, and who acts on the day.

We bring the data sources together, develop use cases for the routes used in both incidents, and fix the reporting chains. Alongside them, playbooks for the case where it is not your organisation that is hit but your service provider.

Practice

Phishing simulation without shaming anyone

Phishing-Simulation und ihre Auswertung Eine Kampagne an fuenfhundert Postfaecher, aufgeteilt in gemeldet, ignoriert und geklickt. Ausgewertet wird ohne Namen. CAMPAIGN 500 MAILS REPORTED 46 % IGNORED 36 % CLICKED 18 % EVALUATION STAYS ANONYMOUS PHISHING SIMULATION · ANONYMISED

A campaign that is realistic but not humiliating. The evaluation is anonymised and at group level, agreed with the works council.

More interesting than the click rate is the reporting rate. An organisation where suspicious messages get reported quickly gains time, and in a ransomware attack time is the only resource that counts.

Regulation

What applies to you, and what expressly does not

This point is frequently overstated, so precisely: Germany has not made use of the option to extend the scope of the NIS2 directive to public administration bodies at local level. The federal states govern implementation for their own area, and what applies to a state authority follows from the respective state law.

In practice that means the first question is not how NIS2 gets implemented, but which of your units falls under what. For municipal utilities and publicly owned enterprises the answer is regularly different from the core administration.

IT-Grundschutz, the German federal baseline protection framework, is untouched by that and remains the established frame: structure analysis, protection requirement assessment, modelling, baseline security check. A security test supplies the evidence of effectiveness for what was modelled.

Common questions

What authorities, enterprises and providers ask

For the municipal level, Germany did not extend the scope. For state authorities it is decided by state law; for municipal utilities and publicly owned enterprises, often by their commercial activity. We make that classification at the beginning, not at the end.

Grundschutz describes what should be in place. A test shows whether it works. Together they make the evidence; neither does on its own.

That can be settled, and we settle it before starting. What matters is that the test scope covers the interface in both directions, otherwise exactly the route that was used in practice goes untested.

Yes, if it is anonymised and evaluated at group level from the outset. We agree the approach beforehand. The aim is a higher reporting rate, not a list of names.

Next step

Discuss your sector.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139