OT and energy

BESS cybersecurity and Czech NIS2 implementation

A BESS is both a power asset and a digitally controlled system. Security requirements belong in architecture, procurement and acceptance — not only in an IT policy after commissioning.

Legal context

Czech Act No. 264/2025 became effective on 1 November 2025. Applicability must be assessed for the organisation and regulated service; battery ownership alone is not the test.

Architecture and suppliers

Map accounts, data flows, remote access, firmware, APIs, cloud services and safe behaviour after lost communications.

Contractual and testable requirements

Specify logging, role control, vulnerability handling, incident notice, configuration export, support termination and controlled acceptance scenarios.

First step

Data first. Technology second.

Describe the facility, the operating problem and the required outcome. We will suggest an appropriate scope and agree how to transfer technical data.