Security
GRI industry information on disaster/emergency planning and disaster management measures
As an operator of critical infrastructure, 50Hertz is required under the IT-SiG and the EnWG to ensure information security on systems necessary for maintaining security of supply. Information must be processed, stored and communicated such that the availability, confidentiality and integrity of the information and the critical systems are ensured to a sufficient and appropriate extent.
The information security management system pursuant to ISO 27001 "IT security catalogue in accordance with Sec. 11 (1a) EnWG" was recertified in 2020. This established security process ensures that information security risks are systematically identified and addressed. In the reporting year, no targeted cyber-attacks on 50Hertz were registered and no damage from information security incidents was recorded. In an independent audit for the evaluation and certification of data centres’ operational safety (based on DIN EN 56000), the tier 3 data centres of 50Hertz were reported to be "highly available".
As part of the data security management system (DSMS), the existing e-learning programme was updated and both internal and external employees were provided with information and training.
For 50Hertz, security goes beyond its corporate boundaries. Therefore, both internal and external stakeholders receive training in crisis management and communication in the form of regular crisis team exercises, among other things. As a result of this, not only existing structures, processes and reporting channels are evaluated and continuously improved, but the crisis team members and employees also receive intensive training on how to deal with unexpected events level-headedly under special stresses and quickly make appropriate decisions to manage crises. These and further measures aim to continuously and holistically increase the resilience of 50Hertz. In addition to the training concept for all members of the crisis team, this includes the examination of the object protection approaches and the further development of the Company’s general security.
In the reporting year, the transmission system operators 50Hertz and Energinet from Denmark as well as the operators of the coal-fired power plant KNG Rostock successfully performed a simulation of a power grid restart. Live testing was carried out of the fictional situation following a power outage in continental Europe with voltage supplied from Denmark. This was the first time a land and sea cable connection between two countries as well as offshore wind power were used under real conditions to restart a power plant. These kind of start-up attempts, also known as black start tests, are part of the grid restoration plans of transmission system operators, as their capability has to be tested regularly in their corresponding grid areas to guarantee the swiftest possible restoration of the electricity grid after a power outage.