Utilities & critical infrastructure — NIS2, NIST, UK CAF
Continuous offensive validation, traffic-side intrusion detection and regulator-ready evidence for energy, water and telecom operators — mapped to NIS2, the UK CAF, NIST CSF and the Gulf national frameworks, on one on-premise appliance.
NIS2 came into force across EU member states in 2024, and the Italian decreto legislativo 138/2024, in force since 16 October 2024, made every essential energy, water and telecommunications operator personally accountable for "appropriate, proportionate, effective" cybersecurity measures. The ACN Q1 2026 bulletin reports a 41% YoY rise in destructive (not merely extortive) attacks on critical infrastructure operators across the EU. The combination of state-aligned offensive activity, AI-augmented ransomware affiliates targeting OT environments, and a regulator that now expects continuous evidence — not annual reports — has turned the security posture of a utility from a budget line into a fiduciary obligation for the board.
What is on the CISO's desk right now
NIS2 Article 23 incident reporting
24h early warning, 72h notification, 1-month final report. Every minute of detection latency translates into regulatory exposure: the clock runs from awareness, and supervisors will compare the date you claim with your own alerts.
Continuous controls evidence
ACN guidance is explicit that measures must remain effective over time, not at one point in time. A clean pentest report from last year does not satisfy the obligation.
OT/IT convergence
Energy and water operators run mixed Modbus / DNP3 / IEC 60870 estates next to IT systems. The 2026 attack pattern is to land via IT and pivot to OT — exactly the path most security stacks are blind to.
Supply-chain attack on security vendors
CERT-EU 2025-2026 advisories on third-party SOC providers made every CISO question SaaS security tooling. Procurement is increasingly forbidding vendor-cloud touch points on production telemetry.
How Zero Hunt maps to the utility operating model
Continuous generative pentest covering IT + OT segments
The 10-agent swarm runs on schedule and on change-detection, exercising both IT and OT segments. The AI Gym backtest corpus includes Vulhub OT/ICS modules. Findings are generated, not cataloged — keeping pace with the AI-augmented offensive activity actually observed against utilities.
Deep-packet AI traffic analysis on the OT boundary
Wire-speed 4-head ML model running on the appliance GPU at 2.7+ Gbit/s baseline. Detects ransomware staging traffic on IT, anomalous Modbus / DNP3 patterns on OT, and the lateral pivot between the two — the canonical 2026 utility attack chain.
Auto-mapped NIS2 Article 23 evidence + 72h notification timeline
Every finding, every detected event, every remediation is signed at write time and mapped to NIS2 controls. The 24h / 72h / 1-month timeline becomes a query, not a fire drill. Trust Center exports the auditor bundle in one click.
Capability emphasis for utilities
- ▸Sensor placement across multi-subnet IT, DMZ and OT segments
- ▸OT/ICS protocol coverage in the AI Traffic model (Modbus, DNP3, IEC 60870, BACnet)
- ▸Air-gap deployment for classified or generation-asset segments
- ▸Signed, hash-chained chain of custody on every artifact (NIS2 audit defensibility)
- ▸Full integration with existing SIEM/SOAR via REST + WebSocket + webhook
Who buys this in a utility
CISO sponsoring; SOC manager validating; OT security lead co-signing; procurement vetting against ACN essential-operator requirements; CFO authorizing on the basis that the appliance replaces 1-2 FTE-equivalent of pentest contractor cost plus the NIS2 reporting infrastructure.
Frameworks mapped for this sector, worldwide
The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:
- Global / cross-industry
- NIST Cybersecurity Framework
- ISO/IEC 27001:2022
- CIS Critical Security Controls v8
- European Union
- NIS2 Directive
- United States
- NIST SP 800-53
- United Kingdom
- NCSC Cyber Assessment Framework
- Asia-Pacific
- Singapore Cybersecurity Act / PDPA
- Middle East
- Saudi NCA ECC / SAMA CSF
- UAE Information Assurance (NESA)
- Qatar NCSA framework
Why this sector runs its AI red team on-premise, on private AI →
Go deeper on the regulations
- Playbook · 12 minNIS2 penetration testing and vulnerability assessment requirements — what is mandatory and what is risk-based
A clause-by-clause guide to what NIS2, Implementing Regulation (EU) 2024/2690 and, for Italy, D.Lgs. 138/2024 and the ACN baseline measures require on vulnerability assessment and penetration testing, and the evidence that proves it.
- Playbook · 11 minUK penetration testing requirements — CBEST for financial firms and the NCSC Cyber Assessment Framework
How the Bank of England's CBEST intelligence-led testing and the NCSC Cyber Assessment Framework v4.0 treat penetration testing and vulnerability management: who they apply to, who may test, and what evidence counts.
- Playbook · 8 minNIS2 Article 23 incident timeline — the practical playbook
A step-by-step operational reference for the NIS2 Article 23 incident reporting cadence: what to do in the first hour, by hour 24, by hour 72, and by month 1. Decision gates, evidence checklists, common failure modes.
- Definition · 7 minWhat is CTEM (Continuous Threat Exposure Management)?
CTEM is a five-stage, continuously running program — scoping, discovery, prioritization, validation, mobilization — that keeps an organization's exposure surface measured, ranked by exploitability, and provably reduced over time. It is the framework Gartner codified to replace point-in-time pentesting and standalone vulnerability scanning as the basis of cyber-risk management.
- Definition · 7 minDecreto Legislativo 138/2024 — the Italian NIS2 transposition
Decreto Legislativo 138 of 4 September 2024 is the Italian transposition of NIS2 (Directive (EU) 2022/2555). It identifies essential and important entities, defines technical and organizational measures, attaches personal liability to top management, and operationalizes ACN as the competent national authority and CSIRT Italia as the national CSIRT.
Want to see this against your environment?
A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.