
IT security for utilities and critical infrastructure
The duties of a critical infrastructure operator, the resources of an SME, and regulated costs. Where we start at Swiss utilities.
The situation
Around 600 utilities supply Switzerland with electricity. The median distribution grid operator serves just under 1,500 end customers. So the typical Swiss utility carries the duties of a critical infrastructure operator with an IT team of a handful of people.
That is the core tension in this industry. The requirements are written for operators with dedicated staff functions, and they have to be met by a team that also runs the control room, office IT and the customer portal. Setting up a group-scale programme here produces paperwork nobody maintains.
Then there is the cost side. Grid costs are regulated. Security cannot simply be financed through the tariff, it has to be justified to the regulator and the owners and correctly sized. Buying a tool is easier than explaining why it was needed.
And operations themselves are changing. Telecontrol, smart meters and vendor remote-maintenance access now sit on the same infrastructure as mail and ERP. The attack surface grows faster than the team.
What we find in this industry
- Critical infrastructure duties, SME resourcesThe requirements were written for operators with dedicated staff functions. They have to be met by a team that also runs the control room, office IT and the customer portal. Scope therefore has to match size, otherwise the system is never lived.
- Control technology and office IT are convergingTelecontrol, smart meters and vendor remote-maintenance access now sit on the same network as mail and ERP. What used to be two separate worlds is now one shared attack surface.
- Remote access nobody fully knows aboutSuppliers have been given access over the years, for commissioning, for faults, for maintenance contracts. Who can reach what today is rarely documented properly. It is usually the first finding of a stocktake.
- Regulated costs, unregulated expectationsEvery franc spent on security has to stand up to the regulator and the owners. Without a recognised framework there is no language for that, and the discussion stays a matter of belief.
- Assets and protection requirements are not recorded systematicallyWithout an inventory you can neither prioritise nor evidence. That is where most of the work sits in our mandates, and it is unspectacular but the precondition for everything else.
- Mandatory reporting assumes a rehearsed processSince April 2025 critical infrastructure operators must report cyber attacks. In many places the process behind that exists only on paper, and in a real incident there is no time to invent it.
Typical trigger
The board or the owning municipality asks about the state of cyber security and there is no defensible answer. Or an audit finds that assets and protection requirements are recorded nowhere.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
Structure sized to the organisation you actually are
We build the ISMS along ISO 27001 and the Swiss ICT minimum standard, with asset inventory, protection requirements and a supplier overview. The control catalogue is harmonised across ISO 27001 Annex A, the ICT minimum standard and NIST CSF, so three lists do not have to be maintained side by side.
The scope matches 1,500 end customers, not 150,000. A system your team can actually run is worth more than one that impresses an auditor and then nobody.
Remote access and suppliers back under control
We bring order to access, permissions and vendor maintenance, and establish supplier and measure tracking that works during normal operations.
Your people stay on the grid. We work off the backlog without the supply suffering for it.
A named responsibility that can also report
For the board, the municipality and the regulator what counts most is that someone can explain the security position in business language and justify the spend.
We take that on as a mandate, with experience from regulated environments and without you having to create a position.
Know where you stand before the programme is designed
A fixed-price assessment shows where you sit against recognised frameworks and which gaps actually matter.
The result is an order of work you can defend to owners and the regulator, rather than a list from a product brochure.
Who it is for
- Distribution grid operators and utilities with a small IT team
- Critical infrastructure operators with an ISMS requirement and no structure for it
- Municipally or cantonally owned utilities with a duty to report upwards
- Utilities where control technology and office IT are converging
Related engagements
- ISMS and supplier management for a critical-infrastructure energy provider
- Cybersecurity strategy and governance from a maturity assessment
- Privileged Identity and Access Management with Entra ID
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
We are a small utility. Does the ICT minimum standard even apply to us?
The Swiss ICT minimum standard is a recommendation, not an obligation. In practice it still becomes the benchmark, because regulators, owners and insurers use it as a reference. We therefore apply it as a framework and scale the scope to your actual size.
Do we really have to report an attack?
Since 1 April 2025 critical infrastructure operators have a duty to report cyber attacks. What matters less is the duty itself and more the process behind it: who detects, who decides, who reports. We build and rehearse that with you.
Can we build the ISMS without certifying it?
Yes, and for many utilities that is the right path. The value sits in the inventory, the protection requirements and the way measures are steered. Certification is a separate, later decision.
How do we keep an ISMS alive with only two IT people?
By scoping it for two people from the start. Fewer documents, clear ownership, fixed dates. A small system that runs beats a large one that goes to sleep.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

