WIK Whitepaper: Strengthening Cybersecurity for Transmission System Operators © Photo Credit: bird_saranyoo - stock.adobe.com

WIK Whitepaper: Strengthening Cybersecurity for Transmission System Operators

Lessons from EU and German frameworks

This white paper, commissioned by Deutsche Energie-Agentur (dena), analyses the evolving European and German legal framework for cybersecurity, with a particular focus on its implications for transmission system operators (TSOs). The paper provides a structured and easily comprehensible overview of the legal and regulatory framework, including a comprehensive overview of relevant laws, directives and technical standards for TSOs in Germany. It also highlights key insights and approaches that could be adopted in other countries.

This whitepaper, commissioned by Deutsche Energie-Agentur (dena), provides an accessible overview of the evolving European and German cybersecurity framework for Transmission System Operators (TSOs). It examines how regulation can strengthen cybersecurity in the energy sector and how TSOs can ensure compliance, resilience, and secure grid operation amid increasing digitalisation and interconnectivity.

The EU and Germany have developed a multi-level framework combining cross-sector and sector-specific regulation. What was once a reactive compliance task is now moving towards a preventive, risk-based, and governance-driven approach. Key elements include risk management, incident reporting, audits, clear responsibilities, supply chain security, certified products, and the growing legal integration of international standards. Collectively, these measures are designed to enhance harmonisation, operational resilience, and trust across interconnected energy systems.

In Germany, responsibilities are shared primarily between the Federal Network Agency (BNetzA), which is responsible for sector-specific regulation and supports the ongoing transition to decentralised, digitally connected renewable energy systems, and the Federal Office for Information Security (BSI), which focuses on cybersecurity, certification, and national incident response. It is therefore vital to ensure close coordination, especially as TSOs may need to interact with multiple authorities.

A key lesson is that effective cybersecurity requires more than regulation alone. Mutual trust, rapid information sharing, joint incident exercises, and the application of international standards are necessary to address evolving technologies and threats.