Sabotage, cyberattacks, hybrid threats: Why NIS-2 will fail without training

Pascal Rieboldt, COO of the ML Gruppe
9. June 2026
Energy providers, grid operators, and defense companies must now be NIS 2-compliant. But many underestimate the most critical factor: people. Why the right employee training is so important.
The threat situation is real: 321 registered cases of sabotage against critical infrastructure in Germany in 2025. A doubling of successful cyber attacks on Europe’s energy sector within a few years. Massive attacks on Ukraine’s energy supply.
The EU responded to this very development with the NIS 2 Directive. And companies have been required to implement it since December 2025.
This raises an urgent question for energy suppliers, grid operators and companies in the defence and critical infrastructure sectors: Is your organization really prepared – both technically and in terms of people?
In this post:
The energy sector is under attack
Energy infrastructure is one of the most important strategic targets of hybrid attacks worldwide today. The reason is obvious: anyone who disrupts the energy supply hits the economy, the state, industry and the population at the same time.
This is particularly evident in Russia’s war against Ukraine. There, power plants, substations and grid infrastructure were systematically attacked – physically and digitally.
Hybrid attacks on energy infrastructure are not a phenomenon limited to war zones, but rather part of a strategic destabilization tactic that has long affected NATO countries and their defense industries as well. Defense contractors and suppliers to the Bundeswehr are also in the crosshairs as part of critical infrastructure—and are subject to NIS 2 requirements.
The threat situation in figures
In Germany, authorities are registering an increasing number of incidents against critical infrastructure. This concerns:
- Energy supplier
- Network operator
- Charging infrastructure
- industrial control systems
- Remote maintenance access
- OT and SCADA systems (digital control of critical systems)
At the same time, cyber attacks on European energy companies are increasing massively. Studies show that successful attacks on the energy sector have doubled in just a few years.
Today, critical infrastructure is no longer a purely technical target – but a strategic area of attack.
NIS-2 is the response to this threat landscape
With the NIS 2 Directive, the EU is responding to the massive increase in threats to critical infrastructure. The following are particularly affected:
- Energy supplier
- Electricity and gas network operators
- Operators of critical energy systems
- Companies in the defense and armaments sector
- Suppliers and KRITIS-related service providers
Energy companies in particular are considered “essential facilities”. Particularly high requirements apply to them.
Companies must:
- Systematically assess risks
- Report security incidents within tight deadlines
- Securing supply chains
- Establish crisis processes
NIS-2 requires significantly more than traditional IT security. Technical safeguards—firewalls, segmentation, monitoring—are necessary but not sufficient.
Above all, however, the directive places the human factor at the center. Article 21 expressly requires organizations to take measures to NIS-2-Employee Training and must implement measures to promote cybersecurity competencies at all levels—including executives and governing bodies.
Successful attacks today often occur where uncertainty, a lack of routines or a lack of awareness meet complex systems.
This point in particular is often underestimated in implementation practice. People remain the most critical weak point.
Anyone who therefore views training as merely a compliance or “checkbox” exercise underestimates both the threat landscape and the actual objective of NIS-2.
In an emergency, it’s not just technology that provides protection – it’s the ability of employees to recognize attacks and act correctly.
The human factor: the biggest security gap
Companies are investing in firewalls, monitoring and zero-trust architectures. At the same time, employees remain the least prepared line of defense.
Many successful attacks start right there:
- Phishing mails
- Stolen access data
- Social engineering
- Manipulated remote maintenance
- unsafe mobile devices
- Misconduct under stress or in a crisis
Phishing remains the most common entry vector for cyber attacks – even in the energy sector. Studies show that the susceptibility of employees in energy companies to phishing attacks can be drastically reduced from 47.8% to less than 4% through targeted training programs. That is a risk reduction of more than 90 % – through skills development.
It is important to note that training in the energy sector must be specific. General IT security awareness training is not enough.
If you want to protect critical infrastructure, you need to prepare employees for real-life attack scenarios.
System control, energy and defense grow together
Digitalization is increasingly blurring the boundaries between IT, OT and physical infrastructure.
Companies from the defense and armaments sector in particular are coming under increased scrutiny as a result. This is because energy supply, industrial production and security-critical infrastructure are closely linked today.
Attacks on energy companies are therefore no longer only economically motivated. They can be part of geopolitical, hybrid or strategic operations.
This makes it all the more important to have a security culture that not only affects IT departments, but the entire company.
“NIS 2 compliance doesn’t start with technology—it starts with people’s ability to identify risks and take the right action.”
— ML Gruppe
Conclusion: Protecting critical infrastructure by building up expertise
Attacks on energy supply, grid infrastructure and critical systems will continue to increase. At the same time, digitalization, remote maintenance, networked systems and geopolitical tensions are increasing the attack surfaces for companies in the energy and defence environment.
The question is no longer whether something will happen. It’s whether employees know what to do if it does.
This is precisely why many companies will fail: not because of a lack of technology, but because of uncertainty, a lack of routines and a lack of preparation in the event of an emergency. After all, cyber resilience is not created by firewalls and monitoring alone – but by people who recognize threats, react correctly and remain capable of acting even under pressure.
This is exactly where ML Gruppe comes in. Because in the end, the most resilient infrastructure is the one whose people are prepared.
How to Become NIS-2 Compliant
We help energy suppliers, grid operators, and organizations associated with critical infrastructure systematically build security capabilities—in a practical, transparent, and NIS 2-compliant manner.
FAQs on the Pay Transparency Directive
NIS-2 (Network and Information Security Directive 2) is the revised EU directive on cybersecurity for critical infrastructure.
It replaces the original NIS Directive from 2016 and sets out binding minimum requirements for cyber resilience, risk management, reporting obligations, supply chain security, and, quite explicitly, employee training.
The directive took effect throughout the EU on January 16, 2023, and member states were required to transpose it into national law by October 17, 2024.
The NIS 2 Implementation Act (NIS2UmsuCG) took effect on December 6, 2025—without a transition period. Affected companies have been required to comply with the obligations immediately since then. The competent authority is the BSI, with which registration is required.
For affected companies, this means they can no longer view cybersecurity as merely an IT issue, but rather as an ongoing organizational responsibility, and they must implement it in a verifiable manner rather than simply documenting it from a technical standpoint.
The classification follows three steps: sector → size → category. Eighteen sectors are regulated, divided into two groups in accordance with two annexes to the BSIG:
Appendix 1 — Sectors of critical and important infrastructure (high criticality): Energy, transportation and traffic, banking, financial market infrastructures, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space.
Appendix 2 – Sectors of Critical Infrastructure: Postal and courier services, waste management, chemicals, food production, manufacturing (including mechanical engineering, medical devices, electronics, and automotive manufacturing), digital service providers, and research.
Within these sectors, the company’s size (“size-cap rule”) determines the category:
- Major organization with 50 or more employees OR €10 million in revenue or total assets, as well as
- An organization of particular importance with 250 or more employees OR €50 million in revenue or €43 million in total assets.
KRITIS operators, trust service providers, and TLD/DNS providers are also affected, regardless of their size. Suppliers are also often indirectly subject to these requirements through supply chain mandates.
The BSI offers a service for conducting an impact analysis. The impact analysis is based on the BSI’s decision tree.
NIS-2 requires organizational and technical cybersecurity measures. These explicitly include training, awareness initiatives, and cyber hygiene for employees.
Defense companies are often part of critical supply chains or operate security-critical infrastructure. As a result, regulatory requirements and threat levels increase significantly.
This applies to electricity, gas, district heating, and oil suppliers, as well as all grid operators (transmission and distribution system operators) and operators of critical generation facilities—in effect, the entire relevant energy sector. Municipal utilities and local providers also fall under NIS-2, provided they meet the thresholds, which is the case for most companies with their own grid. Particular attention must be paid here to supply chain security: Many municipal utilities share service providers, IT systems, and remote maintenance infrastructures, which must also be secured under NIS-2.
For significant entities, fines of up to 10 million euros or 2% of global annual revenue may be imposed—whichever amount is higher. For important entities, the upper limit is 7 million euros or 1.4% of annual revenue. In addition, regulatory authorities may order temporary operational restrictions.
Of particular note: Managing directors and governing bodies are personally liable for ensuring compliance with safety obligations.
Yes—and that is one of the most important changes compared to the old NIS 1 Directive. Article 20 of NIS 2 explicitly requires the management bodies of essential and important facilities to participate in cybersecurity training and to demonstrate the knowledge they have acquired. Training must therefore not be limited to the IT department.
NIS-2 and the German KRITIS regulation (Section 8a BSIG) overlap in some areas but have different focuses. NIS-2 has a broader scope—both in terms of sector coverage and organizational requirements. The KRITIS umbrella law, which is currently being drafted in Germany, is intended to regulate the physical resilience of critical infrastructure and adds another dimension of compliance to NIS-2. Energy providers must keep both sets of regulations in mind.
That depends on the starting point and the size of the organization. Based on practical experience: A full rollout—from needs analysis through design to the first documented training session—typically takes three to six months for medium-sized energy utilities (200–1,000 employees). Ongoing updates and refresher training should then be viewed as a continuous process, not as a one-time project.
Effective NIS-2 training programs for KRITIS companies must:
- Take into account OT/IT convergence and specific KRITIS scenarios
- be structured according to specific roles (control center, field staff, management, IT)
- Ensure traceability for regulatory authorities (documentation, certification)
- Include regular review cycles and status updates
- Explicitly involve executives and governing bodies (NIS 2 requirement)



