Analysis · Sep 1, 2026
Signals, Systems, Societies. Why attacks are made of single signals.

On 25 September, Louis Wübben speaks at the KRITIS forum of Security Essen (hall 5, 11:30) on “Using Technology to Protect What Society Depends On”. This article explains what sits behind it.
Signals
Attacks on critical infrastructure often show up only as fragmented single signals.
That follows from how alarm technology is built. An alarm panel delivers a Contact ID message. A camera delivers a video stream. A sensor delivers a fault signal. Every source has its own protocol and its own channel, and in a conventional control center operators check each message on its own, thousands a day, most of them false alarms. Nobody sees a pattern that spans three sources and twenty minutes, because no system relates those signals to one another.
In its July 2026 guidelines on the CER Directive, the European Commission describes what it expects. Intrusion and perimeter detection systems should be monitored and tested regularly (paragraph 29). Video systems should cover the relevant areas in real time and in recordings, with regular review of the footage (paragraph 30). And operators should keep an incident database in which events are recorded systematically (paragraph 20). A pattern is only visible to someone who has a history and can read it.
Systems
What is usually missing is a place where those signals arrive together: staffed around the clock, able to decide and to intervene. The guidelines describe that place without naming it — a liaison officer as the interface to the authorities (paragraph 13), formalized cooperation with police, emergency services and defense (paragraph 61), crisis communication across several channels (paragraph 63), alerting systems with clear chains of command (paragraph 65). For a company with one critical site and no security department of its own, that place is a control center.
The alarm receiving center (Notruf- und Serviceleitstelle, NSL) has existed for decades, and its interfaces are standardized. What it lacked was the ability to bring signals from different sources into one picture instead of working through them in a queue. That takes software that relates signals to each other and adapts procedures to the operator. We answer those signals ourselves, on Trident, our own operating system for alarm receiving centers, recognized under VdS 3534 — built to close exactly that gap.
Societies
A substation is never only a substation. When an arson attack cut high-voltage cables in Berlin in January 2026, around 45,000 households were without power for days, hospitals and care homes among them, and with the power went heating, mobile networks and internet access. This is why the Commission’s guidelines recommend that operators record the dependencies between assets and sectors (paragraph 14). Protecting a substation means protecting the systems behind it.
As of 30 June 2026, the Federal Office for Information Security counted 1,231 operators with 2,180 assets registered as KRITIS under the German BSI Act (BSI-Gesetz). A large share of them will also fall under the KRITIS Framework Act and will have to organize physical protection that is monitored, tested and documented. Staffing alone will barely carry that: the German security industry association (BDSW) counted 5,478 open positions in February 2026. Technology that brings signals together and shows where someone is needed is the precondition for this protection happening at all.
The talk on 25 September goes into all three levels. We are in hall 8, stand 8C20 for the whole week — what we are showing at Security Essen has its own article. If you would like to talk before then, get in touch.


