The ML Gruppe logo
Security training for NIS2 at energy suppliers

Sabotage, cyberattacks, hybrid threats: Why NIS-2 will fail without training

The photo shows a portrait of Pascal Rieboldt from the ML Gruppe.

Pascal Rieboldt, COO of the ML Gruppe

9. June 2026

Energy providers, grid operators, and defense companies must now be NIS 2-compliant. But many underestimate the most critical factor: people. Why the right employee training is so important.

The threat situation is real: 321 registered cases of sabotage against critical infrastructure in Germany in 2025. A doubling of successful cyber attacks on Europe’s energy sector within a few years. Massive attacks on Ukraine’s energy supply.

The EU responded to this very development with the NIS 2 Directive. And companies have been required to implement it since December 2025.

This raises an urgent question for energy suppliers, grid operators and companies in the defence and critical infrastructure sectors: Is your organization really prepared – both technically and in terms of people?

In this post:

The energy sector is under attack

Energy infrastructure is one of the most important strategic targets of hybrid attacks worldwide today. The reason is obvious: anyone who disrupts the energy supply hits the economy, the state, industry and the population at the same time.

This is particularly evident in Russia’s war against Ukraine. There, power plants, substations and grid infrastructure were systematically attacked – physically and digitally.

Hybrid attacks on energy infrastructure are not a phenomenon limited to war zones, but rather part of a strategic destabilization tactic that has long affected NATO countries and their defense industries as well. Defense contractors and suppliers to the Bundeswehr are also in the crosshairs as part of critical infrastructure—and are subject to NIS 2 requirements.

The threat situation in figures

In Germany, authorities are registering an increasing number of incidents against critical infrastructure. This concerns:

  • Energy supplier
  • Network operator
  • Charging infrastructure
  • industrial control systems
  • Remote maintenance access
  • OT and SCADA systems (digital control of critical systems)

At the same time, cyber attacks on European energy companies are increasing massively. Studies show that successful attacks on the energy sector have doubled in just a few years.

Today, critical infrastructure is no longer a purely technical target – but a strategic area of attack.

Under fire: why the danger is real

Germany:

  • The BSI recorded 68 critical cyberattacks on the German energy system in the first half of 2025. (Source: BSI / RiffReporter, February 2026)
  • In 2024, the number of successful attacks on energy suppliers increased significantly compared to the previous year. (Source: connect-professional / BSI situation picture, August 2025)
  • According to the Microsoft Digital Defense Report 2025, Germany ranks fourth among the countries most affected by cyber attacks worldwide – with 3.3% of all global attacks in the first half of 2025. (Source: Microsoft Digital Defense Report 2025)
  • In 2025, a total of around 334,000 cybercrime cases were registered in Germany – with a considerable number of unreported cases. (Source: BKA Federal Situation Report Cybercrime 2025, May 2026)

Europe and globally:

  • The ENISA Threat Landscape Report 2024 confirms: The energy sector is one of the most affected industries in Europe. Solar and wind power operators in particular are being targeted. (Source: ENISA, 2024)
  • Between 2020 and 2022, the average number of cyberattacks on utility companies worldwide doubled – with a further sharp increase after the start of the Russian war of aggression. (Source: IEA / KnowBe4 study, April 2025)

Ukraine as an extreme scenario – and preview:

  • Between October 2025 and January 2026 alone, the Ukrainian security service documented at least 256 airstrikes on electricity and heat supply facilities. (Source: Amnesty International, April 2026)
  • The available capacity of fossil and nuclear power plants in Ukraine has fallen from around 40 to just ~10 gigawatts since the start of the war.(Source: t-online / Helmholtz-Zentrum Berlin, December 2025)
  • At times, emergency shutdowns affect up to 80% of the Ukrainian population at temperatures below -15 degrees. (Source: Amnesty International, April 2026)

NIS-2 is the response to this threat landscape

With the NIS 2 Directive, the EU is responding to the massive increase in threats to critical infrastructure. The following are particularly affected:

  • Energy supplier
  • Electricity and gas network operators
  • Operators of critical energy systems
  • Companies in the defense and armaments sector
  • Suppliers and KRITIS-related service providers

Energy companies in particular are considered “essential facilities”. Particularly high requirements apply to them.

Companies must:

  • Systematically assess risks
  • Report security incidents within tight deadlines
  • Securing supply chains
  • Establish crisis processes

NIS-2 requires significantly more than traditional IT security. Technical safeguards—firewalls, segmentation, monitoring—are necessary but not sufficient.

Above all, however, the directive places the human factor at the center. Article 21 expressly requires organizations to take measures to NIS-2-Employee Training and must implement measures to promote cybersecurity competencies at all levels—including executives and governing bodies.

Successful attacks today often occur where uncertainty, a lack of routines or a lack of awareness meet complex systems.
This point in particular is often underestimated in implementation practice. People remain the most critical weak point.

Anyone who therefore views training as merely a compliance or “checkbox” exercise underestimates both the threat landscape and the actual objective of NIS-2.

In an emergency, it’s not just technology that provides protection – it’s the ability of employees to recognize attacks and act correctly.

The human factor: the biggest security gap

Companies are investing in firewalls, monitoring and zero-trust architectures. At the same time, employees remain the least prepared line of defense.

Many successful attacks start right there:

  • Phishing mails
  • Stolen access data
  • Social engineering
  • Manipulated remote maintenance
  • unsafe mobile devices
  • Misconduct under stress or in a crisis

Phishing remains the most common entry vector for cyber attacks – even in the energy sector. Studies show that the susceptibility of employees in energy companies to phishing attacks can be drastically reduced from 47.8% to less than 4% through targeted training programs. That is a risk reduction of more than 90 % – through skills development.

It is important to note that training in the energy sector must be specific. General IT security awareness training is not enough.

If you want to protect critical infrastructure, you need to prepare employees for real-life attack scenarios.

System control, energy and defense grow together

Digitalization is increasingly blurring the boundaries between IT, OT and physical infrastructure.

Companies from the defense and armaments sector in particular are coming under increased scrutiny as a result. This is because energy supply, industrial production and security-critical infrastructure are closely linked today.

Attacks on energy companies are therefore no longer only economically motivated. They can be part of geopolitical, hybrid or strategic operations.

This makes it all the more important to have a security culture that not only affects IT departments, but the entire company.

“NIS 2 compliance doesn’t start with technology—it starts with people’s ability to identify risks and take the right action.”
— ML Gruppe

NIS 2-Compliant Competency Development for Critical Infrastructure: How the ML Gruppe Can Support You

From needs analysis to audit documentation—the ML Gruppe supports energy companies, grid operators, defense contractors, and organizations related to critical infrastructure in implementing NIS-2 and embedding security expertise within their organizations on a sustainable basis. To this end, we rely on practical, NIS-2-compliant learning and training concepts specifically designed for critical infrastructure, energy utilities, and defense-related companies.

NIS-2 Readiness Check

Assessment with a clear action plan: Where does your organization stand today – and what is missing to achieve demonstrable compliance?

Role-specific training concepts

Tailor-made programs for control centers, field service, IT and plant control teams, armaments production as well as management and executive level – not a one-size-fits-all format, but context-appropriate skills development.

Blended learning formats

Classroom training, e-learning and realistic simulations – for example on phishing, social engineering or emergency exercises – combined for maximum effectiveness.

Documentation & verification

Audit-proof records for proof of compliance, internal audits and official inspections – complete and immediately usable.

Ongoing update

The threat situation is changing. So does our training content – continuously and without additional effort for your organization.

Conclusion: Protecting critical infrastructure by building up expertise

Attacks on energy supply, grid infrastructure and critical systems will continue to increase. At the same time, digitalization, remote maintenance, networked systems and geopolitical tensions are increasing the attack surfaces for companies in the energy and defence environment.

The question is no longer whether something will happen. It’s whether employees know what to do if it does.

This is precisely why many companies will fail: not because of a lack of technology, but because of uncertainty, a lack of routines and a lack of preparation in the event of an emergency. After all, cyber resilience is not created by firewalls and monitoring alone – but by people who recognize threats, react correctly and remain capable of acting even under pressure.

This is exactly where ML Gruppe comes in. Because in the end, the most resilient infrastructure is the one whose people are prepared.

How to Become NIS-2 Compliant

We help energy suppliers, grid operators, and organizations associated with critical infrastructure systematically build security capabilities—in a practical, transparent, and NIS 2-compliant manner.

FAQs on the Pay Transparency Directive

What is the NIS 2 Directive?2026-07-09T18:39:35+02:00

NIS-2 (Network and Information Security Directive 2) is the revised EU directive on cybersecurity for critical infrastructure.

It replaces the original NIS Directive from 2016 and sets out binding minimum requirements for cyber resilience, risk management, reporting obligations, supply chain security, and, quite explicitly, employee training.

The directive took effect throughout the EU on January 16, 2023, and member states were required to transpose it into national law by October 17, 2024.

The NIS 2 Implementation Act (NIS2UmsuCG) took effect on December 6, 2025—without a transition period. Affected companies have been required to comply with the obligations immediately since then. The competent authority is the BSI, with which registration is required.

For affected companies, this means they can no longer view cybersecurity as merely an IT issue, but rather as an ongoing organizational responsibility, and they must implement it in a verifiable manner rather than simply documenting it from a technical standpoint.

Welche Unternehmen sind von NIS-2 betroffen?2026-07-09T18:39:34+02:00

The classification follows three steps: sector → size → category. Eighteen sectors are regulated, divided into two groups in accordance with two annexes to the BSIG:

Appendix 1 — Sectors of critical and important infrastructure (high criticality): Energy, transportation and traffic, banking, financial market infrastructures, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space.

Appendix 2 – Sectors of Critical Infrastructure: Postal and courier services, waste management, chemicals, food production, manufacturing (including mechanical engineering, medical devices, electronics, and automotive manufacturing), digital service providers, and research.

Within these sectors, the company’s size (“size-cap rule”) determines the category:

  • Major organization with 50 or more employees OR €10 million in revenue or total assets, as well as
  • An organization of particular importance with 250 or more employees OR €50 million in revenue or €43 million in total assets.

KRITIS operators, trust service providers, and TLD/DNS providers are also affected, regardless of their size. Suppliers are also often indirectly subject to these requirements through supply chain mandates.

The BSI offers a service for conducting an impact analysis. The impact analysis is based on the BSI’s decision tree.

Why is training so important under NIS-2?2026-07-09T18:39:24+02:00

NIS-2 requires organizational and technical cybersecurity measures. These explicitly include training, awareness initiatives, and cyber hygiene for employees.

Why does NIS-2 also affect defense and defense contracting companies?2026-07-09T18:39:24+02:00

Defense companies are often part of critical supply chains or operate security-critical infrastructure. As a result, regulatory requirements and threat levels increase significantly.

Which energy companies are specifically covered by NIS-2?2026-07-09T18:39:24+02:00

This applies to electricity, gas, district heating, and oil suppliers, as well as all grid operators (transmission and distribution system operators) and operators of critical generation facilities—in effect, the entire relevant energy sector. Municipal utilities and local providers also fall under NIS-2, provided they meet the thresholds, which is the case for most companies with their own grid. Particular attention must be paid here to supply chain security: Many municipal utilities share service providers, IT systems, and remote maintenance infrastructures, which must also be secured under NIS-2.

What penalties apply for NIS-2 violations?2026-07-09T18:39:24+02:00

For significant entities, fines of up to 10 million euros or 2% of global annual revenue may be imposed—whichever amount is higher. For important entities, the upper limit is 7 million euros or 1.4% of annual revenue. In addition, regulatory authorities may order temporary operational restrictions.

Of particular note: Managing directors and governing bodies are personally liable for ensuring compliance with safety obligations.

Do executives also have to participate in NIS 2 training?2026-07-09T18:39:17+02:00

Yes—and that is one of the most important changes compared to the old NIS 1 Directive. Article 20 of NIS 2 explicitly requires the management bodies of essential and important facilities to participate in cybersecurity training and to demonstrate the knowledge they have acquired. Training must therefore not be limited to the IT department.

How does NIS-2 differ from the previous KRITIS regulation?2026-07-09T18:39:17+02:00

NIS-2 and the German KRITIS regulation (Section 8a BSIG) overlap in some areas but have different focuses. NIS-2 has a broader scope—both in terms of sector coverage and organizational requirements. The KRITIS umbrella law, which is currently being drafted in Germany, is intended to regulate the physical resilience of critical infrastructure and adds another dimension of compliance to NIS-2. Energy providers must keep both sets of regulations in mind.

How long does a NIS 2-compliant training program take for a medium-sized energy utility?2026-07-09T18:39:14+02:00

That depends on the starting point and the size of the organization. Based on practical experience: A full rollout—from needs analysis through design to the first documented training session—typically takes three to six months for medium-sized energy utilities (200–1,000 employees). Ongoing updates and refresher training should then be viewed as a continuous process, not as a one-time project.

What requirements must NIS 2 training courses for KRITIS companies meet?2026-07-09T18:38:44+02:00

Effective NIS-2 training programs for KRITIS companies must:

  • Take into account OT/IT convergence and specific KRITIS scenarios
  • be structured according to specific roles (control center, field staff, management, IT)
  • Ensure traceability for regulatory authorities (documentation, certification)
  • Include regular review cycles and status updates
  • Explicitly involve executives and governing bodies (NIS 2 requirement)
Managers are listening to a security training session on NIS-2.

We’ll get your team ready for NIS-2

We provide role-based training for executive management, departments, and employees—ensuring that regulatory requirements are reliably implemented and competencies are embedded within the company.

Go to Top