For technical directors and heads of IT: the problem in one sentence
A utility or port runs dozens to hundreds of remote sites, each with its own controller, its own vendor remote access and a connection that was once set up "temporarily". The head of IT is expected to secure it, the technical director needs access at any time, and since 2025 the regulator demands evidence. We know this situation from ship and offshore networks, where conditions are harsher still, and apply the same principles on land.
- Every remote site reachable, even when one cellular network fails
- Control systems, office and guests in separate zones
- Vendor maintenance only time-limited, logged and approved
- One monitoring view for sites, links and security events
Assets we connect
Distributed assets have one thing in common: no staff on site and no second chance when the connection is gone.
NIS2 and KRITIS: what applies to utilities and ports in Germany
Drinking water and wastewater are separate NIS2 sectors; ports and port facilities belong to the transport sector. Since the German NIS2 implementation act entered into force on 6 December 2025, companies in these sectors with 50 or more employees, or more than EUR 10 million in turnover and balance sheet, generally count as "important entities"; from 250 employees, or EUR 50 million in turnover and EUR 43 million in balance sheet, as "essential entities". Registration with the BSI was due by 6 March 2026, with a grace period until 31 July 2026 (as of 22 Sept 2026).
You are additionally an operator of a critical facility if your plant reaches the thresholds of the BSI-KritisV: 22 million cubic metres per year for drinking water supply, 500,000 connected inhabitants for wastewater disposal. Many municipal utilities are below these but still fall under NIS2. KRITIS operators must add attack detection systems and provide evidence every three years under section 39 BSIG. Whether and how you are affected is a question for your legal team; the technical implementation is described under NIS2 and Compliance & Regulations.
What DRYNET delivers
Telecontrol over LTE/5G with failover
Peplink routers with SIM cards from several carriers, SpeedFusion tunnel to the control room, Starlink or VSAT where cellular is not enough. One standard for all sites.
OT/IT segmentation to IEC 62443
Zones and conduits for control systems, office and guests, implemented with Fortinet firewalls. Migration during operation, rule set documented.
Secure vendor remote maintenance
A central access platform instead of a vendor router in every station: multi-factor authentication, time-limited approval, session log. You stay in control.
Port Wi-Fi and terminal connectivity
Planning and installation of site Wi-Fi, point-to-point links and outdoor access points, separate networks for operations, contractors and guests.
24/7 monitoring
Availability of every site, link quality and security events in one view. Alarms to your on-call team or to us.
Managed service
We operate routers, firewalls and the access platform, keep firmware current and maintain the documentation for audits. You decide how much to hand over.
Four steps
Site and access inventory
Which sites exist, how they are connected, who has remote access. Often the first complete list the organisation has.
Target architecture
Zone model, link mix per site, central remote maintenance, monitoring. Agreed with control engineering, IT and data protection.
Pilot and series
One pumping station or substation as the pilot, then rollout with pre-configured equipment and installation by our technicians.
Operation and evidence
Monitoring, change management, documentation. As a managed service with 24/7 support if required.
Questions we ask in the first conversation
- How many remote sites are there, and how many depend on a single cellular contract?
- Which vendors currently have permanent remote access to controllers?
- Is there a separation between control systems and office IT, and is it documented?
- Who is alerted at night when a site goes offline?
- Are you registered with the BSI, and is there a schedule for the measures?
- Which sites are on the water or outside cellular coverage?
Frequently asked questions from utilities, water suppliers and ports
We are a small municipal utility. Does NIS2 apply to us?
If you operate in the energy, drinking water or wastewater sectors and have at least 50 employees or more than EUR 10 million in turnover and balance sheet, generally yes, as an "important entity". Your legal team should make the classification. Regardless of that, the technical measures, segmentation, controlled remote access and monitoring, make sense at any size.
Our pumping stations run on LTE routers from various manufacturers. Do we have to replace everything?
Not necessarily. We check which devices support current firmware, encrypted tunnels and central management. The goal is a standard you can operate long term, replaced site by site rather than all at once.
How does failover for telecontrol work when a carrier fails?
The router keeps connections to two carriers at the same time; the SpeedFusion tunnel to the control room switches without a session drop on failure (hot failover). At sites without a second network we use Starlink as the second path, hardware and plan through our partner Tototheo, integration by DRYNET. The control system does not notice the switch. IRIS², the EU constellation for secure connectivity with 348 satellites in LEO and MEO, is the coming European option; first launches are planned for 2029 (as of September 2026). We advise on it, see satellite communication.
The equipment vendor needs access for maintenance. How is that made secure?
Through a central access platform: the vendor signs in with multi-factor authentication, you approve the session, access is limited to the asset and the time window and is logged. Permanent vendor routers in stations are removed. Details under Secure Remote Access.
What does IEC 62443 mean for a water works?
The standard groups systems into zones with the same protection requirements and controls the transitions between them. In practice: process control system, telecontrol stations, laboratory and administration are separate zones, and every transition passes a firewall with documented rules. We deliver the zone model as a document you can also use in an audit.
Can you provide Wi-Fi across an entire port area?
Yes. We plan with a coverage survey, use outdoor access points and point-to-point links and separate networks for operations, contractors and guests. Cranes, gates and cameras get their own segments; salt water and wind drive the hardware selection.
We have no IT department of our own for operations. Do you take that on?
Yes, as a managed service: we operate routers, firewalls, access platform and monitoring, keep firmware current and maintain the documentation. Scope and response times are agreed by contract. More under Managed Services.
What documents do we receive for the BSI or an auditor?
Network diagrams with zones, firewall rule set, a list of all remote access paths with owners, monitoring reports and change history, kept up to date during operation so you do not start from zero for the evidence under section 39 BSIG.
Request a conversation
Prefer to talk? +49 431 55607040
Related services
Utilities, water & ports
Every site reachable, every access controlled
We bring order to distributed assets, with equipment built for the job and technicians who travel to you.
