Self-Sufficient: Security as a stand-alone solution 

Critical infrastructure protected by perimeter security and video surveillance

Photo: AEGIS Protect GmbH & Co. KG

KRITIS: Physical Protection in Practice

Germany's KRITIS Umbrella Act places greater emphasis on protecting critical sites and facilities – from perimeter security and detection to access control and defined incident response procedures.

What physical resilience means for operators of critical infrastructure

The KRITIS Umbrella Act broadens the approach to security

Cyber and information security have dominated much of the discussion surrounding critical infrastructure in recent years. Germany's KRITIS Umbrella Act now explicitly addresses the physical protection of critical facilities as a separate element of resilience.

The Act entered into force on 17 March 2026. It applies to critical facilities in sectors including energy, transport, healthcare, water, food and information technology and telecommunications.

The legislation does not simply prescribe the same fences, cameras or security systems for every facility. Instead, it follows a risk-based approach. Operators are expected to assess the threats relevant to their facilities and derive proportionate technical, security-related and organisational measures.

Physical security therefore increasingly becomes a structured and documented process.

Not every operator obligation applies immediately

Although the KRITIS Umbrella Act is already in force, its implementation is taking place in several stages.

A separate ordinance will define, among other things, which categories of facilities and which thresholds determine whether a facility qualifies as critical. According to the current information provided by the Federal Office of Civil Protection and Disaster Assistance, this ordinance is still being prepared.

As a result, registration under the KRITIS Umbrella Act is not yet required. The risk assessments and resilience obligations linked to registration will become applicable according to the statutory timetable once facilities have been identified and registered.

Nevertheless, the Federal Office recommends that operators begin addressing resilience at an early stage.

This is practical advice: a robust physical security structure is rarely something that can be implemented at short notice.

What does the Act require for physical protection?

Section 13 of the KRITIS Umbrella Act sets out four key objectives.

Operators of critical facilities are required to take measures designed to:

  1. prevent incidents,

  2. provide appropriate physical protection for premises and critical facilities,

  3. respond to and defend against incidents while limiting their consequences,

  4. restore the critical service quickly following an incident.

The Act also lists examples of measures that may contribute to physical protection.

These include:

  • structural and technical security,

  • organisational site protection,

  • perimeter boundaries,

  • resistant façade elements,

  • procedures for monitoring the surrounding area,

  • detection equipment,

  • access controls,

  • risk and crisis management procedures,

  • predefined procedures for alarm situations.

Physical security is therefore treated as a continuous process extending from the perimeter of a site through to the response to a confirmed incident.

1. Perimeter security: protection starts before the building entrance

At remote technical facilities, energy infrastructure, utilities and extensive industrial sites, unauthorised access should ideally be detected as early as possible.

A security concept therefore often starts at the outer perimeter.

Depending on the risk, property boundaries, vehicle entrances, gates, fences and particularly sensitive areas can be divided into different security zones.

The objective is not necessarily to make access physically impossible under every circumstance. Early detection of an approach or perimeter breach can be equally important.

The sooner a security-relevant event is detected, the more time is available for verification and response.

2. Detection: identifying incidents at an early stage

The KRITIS Umbrella Act expressly identifies detection equipment as a potential physical protection measure.

In practice, detection systems can monitor defined open areas, boundaries, entrances or technical installations.

Such systems can be particularly useful at extensive or remote facilities. Detection, however, should not be considered in isolation.

The key question is not simply:

“Has movement been detected?”

It is:

“What happens after the detection?”

A robust security concept therefore connects detection with alarm verification and a predefined response procedure.

3. Video verification: turning an alert into an assessed situation

Technical systems can generate alerts. To respond appropriately, the actual cause of an event should be established as quickly as possible.

Is the person authorised?

Was the event caused by an animal?

Is it a technical false alarm?

Or has an unauthorised person actually entered a protected area?

Camera-based alarm verification can help operators and monitoring personnel assess events and reduce unnecessary interventions.

If a security incident is confirmed, the predefined procedures for the particular facility can then be initiated.

For critical infrastructure, this connection between detection, assessment and response is ultimately more important than the number of cameras installed.

4. Access control: who is allowed where?

Access controls are also expressly identified by the KRITIS Umbrella Act.

Critical facilities should therefore clearly define which individuals are permitted to enter specific areas.

Different security zones can be appropriate. Employees, external maintenance contractors and delivery personnel may each require different levels of access.

Technical access control can be combined with organisational procedures including:

  • defined access permissions,

  • time-limited permissions,

  • identification of external contractors,

  • documented access,

  • separate authorisation for particularly sensitive areas.

Physical protection is therefore not limited to preventing intrusion from outside. Controlling the movement of authorised individuals within the site can be equally important.

5. The alarm procedure must be defined before an alarm occurs

A particularly important aspect of the KRITIS Umbrella Act is its explicit reference to predefined procedures in the event of an alarm.

Detection technology alone does not create resilience.

For relevant scenarios, operators should determine in advance:

  • Who receives the alarm?

  • Who verifies the event?

  • How is the incident prioritised?

  • Which internal contacts are informed?

  • When is a security or intervention service deployed?

  • When are the police, fire brigade or other authorities involved?

  • How is the incident documented?

  • Which escalation levels apply?

These procedures can be defined for individual sites and reviewed regularly.

This is how individual security components become part of an operational security organisation.

6. Monitoring and intervention complete the security chain

Particularly outside normal operating hours, it must be clear who responds to a security event.

Connection to a monitoring centre can provide the link between technical detection and an operational response.

Following alarm verification, the agreed site-specific response plan may involve informing responsible contacts, dispatching an intervention service or notifying the appropriate authorities.

Physical security can therefore be considered as a chain:

Detect → Verify → Assess → Respond → Document

If one part of this chain fails, the effectiveness of the remaining security technology is reduced.

7. Autonomous systems for remote and temporary areas

Not every area requiring protection is located within a fully developed and permanently connected facility.

Energy and infrastructure projects frequently involve temporary construction areas, remote technical installations or expansion sites without permanent power or communications infrastructure.

Autonomous detection and video surveillance systems can provide an additional option in these situations.

They can operate independently of existing building infrastructure and can be repositioned as a site changes.

Potential applications include:

  • remote technical installations,

  • electrical substations and energy infrastructure,

  • temporary critical infrastructure construction areas,

  • material and equipment storage,

  • expansion areas,

  • facilities that are not yet fully developed.

Physical protection should remain adaptable during construction, conversion and modernisation projects.

8. The risk assessment must lead to a comprehensible concept

The KRITIS Umbrella Act does not require maximum security equipment at every facility.

Instead, it calls for proportionate measures based on risk analysis and assessment, while taking the state of the art into account.

Different facilities will therefore require different solutions.

An urban utility site faces different risks from a remote energy installation. A hospital requires different security zones from a water treatment facility or telecommunications infrastructure.

A physical security concept should therefore answer several basic questions:

What is the threat?

What would be the consequences of a successful incident?

Which areas are particularly critical?

How early must an incident be detected?

What response is required?

Suitable security measures can then be derived from these requirements.

The resilience plan makes security decisions traceable

Section 13 of the KRITIS Umbrella Act also requires operators to describe and implement their measures within a resilience plan.

The considerations behind the selected measures must be documented and linked to the operator's risk assessment.

For physical security, this means avoiding a collection of historically accumulated standalone systems whose original purpose is no longer clear.

Instead, operators should be able to demonstrate which risk each measure is intended to reduce.

This approach also supports regular reviews.

Has the facility changed?

Have new areas been added?

Has the threat environment changed?

Are alarm procedures still current?

Do escalation and intervention procedures operate as intended?

Physical KRITIS security is more than video surveillance

The KRITIS Umbrella Act demonstrates that physical protection cannot be reduced to a single technical product.

Fencing, detection, video surveillance, access control, monitoring centres, site security and intervention are individual components of a wider resilience concept.

The appropriate combination must be derived from the actual risks affecting each facility.

AEGIS Protect supports the practical implementation of physical security measures – from autonomous perimeter and open-area detection and camera-based alarm verification to monitoring centre connections and site-specific intervention and security services.

We regard security technology not as an isolated installation but as a process: detect an event early, assess it reliably and respond according to a predefined procedure.

Teilen

Security that builds trust.

Welcome to AEGIS Protect, your reliable partner for comprehensive protection and security. Our goal is to give you a safe environment where you can feel relaxed and protected. With years of experience, modern technology and a team of professional security specialists, we meet your security needs reliably and efficiently. Count on us for round-the-clock protection wherever you need it.

Get in touch Call