Security of supply starts with infrastructure
In Everyday Operations
Where an outage isn’t just a ticket, but a disruption to service
When it comes to critical infrastructure, an IT incident has immediate consequences beyond IT. Three scenarios illustrate how a resilient cloud architecture makes all the difference.
Intrusion detection systems must run continuously and be able to report incidents within the NIS2 timeframes. The underlying infrastructure itself must not be a target for attacks due to vulnerabilities.

Control and management systems for public utilities must continue to operate even in the event of disruptions. A failure affects not just one system, but an entire region.
Passenger information and guidance systems must operate with particular reliability during disruptions—precisely when the load is at its highest. Scalability must not be an issue in an emergency.

Regulatory Context
Requirements Applicable to Operators of Critical Infrastructure
The BSI-KritisV defines who qualifies as a KRITIS operator based on sector-specific thresholds, ranging from energy and water to food and transportation. Section 8a of the BSIG requires proof of adequate protective measures and attack detection systems every two years. NIS2 tightens these obligations and sets strict reporting deadlines: an early warning within 24 hours, a report within 72 hours. The planned KRITIS umbrella law adds physical resilience as a separate requirement. Additional industry-specific requirements apply, such as § 11 EnWG for the energy sector. BSI C5 remains the assessment checklist for the cloud infrastructure itself.
Sovereignty
Resilience does not end at the boundaries of one’s own system
Those responsible for service delivery must also view their own cloud dependency as a risk. A single provider on which everything depends is itself a single point of failure.
A verifiable basis rather than a leap of faith
Kubernetes and OpenStack as an open foundation. Attack detection and audits can be implemented on an architecture that is truly transparent.
Portability as a Technical Foundation
Workloads are not tied to a specific manufacturer. Switching providers is not just a theoretical contractual option; it is actually technically feasible.
No dependence on a single provider
Redundancy at the infrastructure level is not enough if, in the end, a single provider is still supporting the entire system. Open standards make true diversification possible.
On Site: When Connectivity Itself Becomes a Risk
The same cloud stack can also run directly in the company's own control room or operations center if reliability requires physical separation.
Operations in Germany
If secunet takes over operations, this is done exclusively in certified data centers located in Germany.
Projects & References

A company specializing in digital agricultural systems that contribute to food security.

Cloud infrastructure for a company in the air traffic control sector, with corresponding availability requirements.

Collaboration with one of Germany's most security-critical companies on sovereign IT infrastructures.
Zertifizierungen & Standards






Let's talk about your resilience requirements
Whether it’s § 8a BSIG compliance, attack detection, or control system operation: We’ll work with you to assess your needs.
Resources