NAD Water Control partners with DEFION to ensure NIS2 compliance for OT
"New requirements from NIS2 for OT systems are increasing the focus on security. With DEFION, we know we have the right expertise in-house to keep our systems secure. The collaboration was easy and pleasant; the specialists truly sat next to us rather than across from us. Thanks to their openness and expertise, we are working together toward the same goal: optimal security. This gives us the confidence to face the future."
Challenge
NAD Gemalenbeheer, a collaboration between the municipalities of Delft, Leidschendam-Voorburg, and Pijnacker-Nootdorp, manages various pumping stations, peripheral equipment, and pressure pipelines. These are connected to complex systems that are controlled and monitored via the internet.
With the introduction of the NIS2 directive, NAD Gemalenbeheer had to comply with strict security requirements — not only for its own systems but also for the suppliers it works with. In addition, under the IEC 62443 standard for industrial automation and control systems, it was essential to strengthen the focus on security.
Solution
Leveraging its expertise in OT security, DEFION mapped out the risks of the systems in detail by investigating several attack scenarios. During this process, vulnerabilities were identified that, in the worst-case scenario, could have resulted in the loss of control over more than 1,500 pumping stations and peripheral equipment — potentially allowing malicious actors to shut down systems entirely.
DEFION also thoroughly tested the supplier chain, external connections, and cloud environments, after which the appropriate security measures were implemented.
Results
In addition to these assessments and improvements, DEFION began monitoring NAD Gemalenbeheer's OT security. Thanks to additional sensors in the network, the organization now has real-time insight into the security of its systems, reducing dependency on external parties.
With this approach, NAD Gemalenbeheer is well prepared to meet NIS2 requirements while structurally strengthening the security of critical infrastructure.
®