IT-SIG 2.0: KRITIS protection made easy

IT-SIG 2.0: KRITIS protection made easy - Image by Pete Linforth from Pixabay

Share post

The IT Security Act 1 - IT-SiG 2023 - started on May 2.0, 2.0 and the transition periods have already expired. Legal requirements can be fully covered with WatchGuard EPDR after a short introductory period.

Since May 1, 2023, operators of critical infrastructures (KRITIS) have been obliged to introduce attack detection systems (SzA). According to Ralf Taegener, Managing Director of BOC IT-Security GmbH, there is still room for improvement in terms of the implementation rate - and not only for companies in the field of municipal waste disposal, which are affected for the first time: "Many companies - and especially in the energy sector - have not yet progressed beyond the first planning phase. Nevertheless, the implementation of the legal requirements should take place immediately, also in your own interest. Because the threat situation for companies – and thus also their customers – has increased significantly in recent years.”

maintenance of the common good

Jörg Peine-Paulsen from the Department of Economic Protection/Constitutional Protection in the Lower Saxony Ministry of the Interior and Sport also has a clear opinion on the implementation of the KRITIS requirements: "Maintaining our common good is a task that we as a society have to take particular care of, especially in uncertain times . Very important components in this focus are critical companies or institutions, KRITIS for short, whose production facilities or systems - called critical infrastructures - are of essential importance for the production of important or necessary goods or services. An extensive delivery failure of these products cannot usually be compensated for or compensated for by other actors. Possible consequences of this are that too many people are no longer able to purchase the relevant goods or services, and that hunger, thirst, and a lack of energy or health care can follow. Appropriate protection of KRITIS is therefore essential."

IT Security Act 2.0 – IT-SiG 2.0

The IT Security Act has existed in Germany since the summer of 2015. This was updated and expanded from May 2021. Since then, the second law to increase the security of information technology systems (IT-SiG 2.0) has applied. This includes the deadline for operators of critical infrastructures (KRITIS) to introduce systems for attack detection from May 1, 2023. The in § 8a (1a) BSIG formulated requirements for a SzA system are of the WatchGuard's EPDR solution, which ensures continuous endpoint monitoring and detection and classification of all activities. Unusual user, computer and process behavior is detected and blocked.

In this way, for example, ransomware can be tracked down. Corresponding malware infections have repeatedly led to failures of IT operations on the company side in recent years. This risk is massively reduced by using the WatchGuard EPDR solution, which includes all the necessary functions for Endpoint Protection (EPP) and Endpoint Detection & Response (EDR). A clear advantage in view of the deadline that has already passed: According to Taegener, the solution, including the required documentation, can be introduced at short notice. This means that companies are prepared for emergencies and can also look forward to the upcoming test date every two years with peace of mind.

Fast implementation facilitated

In accordance with the urgency, WatchGuard has also launched a discount campaign: Operator of critical infrastructures (whether in the fields of energy, health, information technology and communication, transport and traffic, water, finance and insurance, nutrition or waste disposal) can secure a 30 percent discount on the EPDR offer until the end of September this year.

More at WatchGuard.com

 


About WatchGuard

WatchGuard Technologies is one of the leading providers in the field of IT security. The extensive product portfolio ranges from highly developed UTM (Unified Threat Management) and next-generation firewall platforms to multifactor authentication and technologies for comprehensive WLAN protection and endpoint protection, as well as other specific products and intelligent services relating to IT security . More than 250.000 customers worldwide rely on the sophisticated protection mechanisms at enterprise level,


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

IT security: NIS-2 makes it a top priority

Only in a quarter of German companies do management take responsibility for IT security. Especially in smaller companies ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more