Based on your browser language, we recommend the following version of this page:

Basierend auf Ihrer Browsersprache empfehlen wir die folgende Version dieser Seite:

Based on your browser language, we recommend the following version of this page:

W oparciu o język przeglądarki zalecamy następującą wersję tej strony:

Based on your browser language, we recommend the following version of this page:

Based on your browser language, we recommend the following version of this page:

Baserat på ditt webbläsarspråk rekommenderar vi följande version av denna sida:

En fonction de la langue réglée dans votre navigateur, nous vous recommandons la version suivante de cette page :

我們根據此瀏覽器使用的語言偏好設定,協助導向此適當版本

CNI regulation: Deutsche Windtechnik takes far-reaching precautions to ensure information security

Protective measures far surpass BSI standards

The German National Strategy for Critical Infrastructure Protection (CNI strategy) is especially relevant and challenging for the wind industry. This is because we are part of the energy sector. It means that we are responsible for part of the energy supply and must ensure the security of the information systems involved. As a service provider, Deutsche Windtechnik has therefore introduced comprehensive protective measures for its critical infrastructure. These measures have now been confirmed for the first time as part of a CNI verification audit by the German Federal Office for Information Security (BSI). What is special about this is that most of our measures are based on the ISO 27001 requirement, which is the gold standard for information security management. This means they go far beyond the requirements of the audit.


BSI audit standards exceeded, aiming for ISO 27001 

Every company that is part of the CNI is legally obligated to submit to a BSI audit every two years. A certified auditor verifies whether the company fulfils the BSI's legal requirements. "We take the issue of information security very seriously and are aware of our responsibility. This is not only required by law. Our clients also rightly expect us to provide a comprehensive strategy to protect our shared information systems as part of our services – and they get it," said Nicolas Abel, Chief Information Security Officer at Deutsche Windtechnik. "For this reason, we only see the BSI audit as proof that we fulfil the minimum requirements. The real measure of our CNI strategy is whether we fulfil the requirements of ISO 27001."

This is because ISO 27001 is the internationally recognised standard for information security management systems (ISMS). It aims to protect the confidentiality, integrity and availability of information. Accordingly, it specifies the requirements for the implementation of an ISMS and defines its operation, monitoring, maintenance and improvement. The measures include risk management, security guidelines, access controls, emergency plans and continuous monitoring to identify, assess and minimise information security risks. 

Dedicated networks for critical infrastructures 

The security of the control centres is the focal point of Deutsche Windtechnik's protective measures. According to CNI regulations, these facilities are considered to be particularly critical and worth protecting. If they were affected by a cyber attack, this could have far-reaching consequences: for the operation of the turbines we manage, for our clients and even for the power supply to parts of the population.

"We make sure that nobody can access or change our data streams without authorisation," Nicolas Abel emphasised. "To this end, we have moved our critical infrastructure to a dedicated, independent power plant network. This measure goes well beyond the legal requirements. It's actually quite rare in the wind industry." 

Information security involves the workforce 

A key aspect of information security is making information secure regardless of the storage medium. This is because information security goes beyond IT security. We look at how information is classified, encrypted, transmitted and later destroyed, both digital and analogue. "We are aware and prepared for the fact that third parties might try to access sensitive data in order to cause damage," Nicolas Abel said. "Information security starts with ourselves – with the people. For example, we organise regular training courses to raise our employees' awareness. This puts them in a better position to identify and report phishing attempts."

Security creates trust 

We operate in a global market. This requires thinking beyond German borders, also when it comes to information security. By following the internationally recognised ISO 27001, we set the highest standards, which our global clients also trust. By consistently focusing on ISO 27001, we send a clear signal: We are aware of our social responsibility. For us, security is not just a legal obligation but a central pillar of our corporate strategy. 

This proactive approach to information security emphasises our commitment to the highest security standards and creates trust among all those who use our services. Our standards strengthen the shared digital infrastructure as well as our confidence in our own security strategy.

Deutsche Windtechnik Control Centre

Maximum security for control centres thanks to dedicated, independent networks.

Your contact person - we look forward to hearing from you!
Scroll to top