Skip to main content Skip to search Skip to main navigation
Menu
Important Industry & market Score: 8/10

Security Technology in IT Networks: 5 Rules for Critical Infrastructure Operators

How security systems must be integrated into critical infrastructure networks without compromising protection levels – five key rules at a glance.

What happened?

In a guest article for Protector Magazin, Uwe Greunke, Business Segment Leader Critical Infrastructure at Rohde & Schwarz Networks and Cybersecurity, outlines five rules for the secure integration of security technology into IT networks. The article is aimed in particular at operators of critical infrastructure, where security systems such as surveillance cameras, access control, locking mechanisms, or alarm and notification technology are increasingly becoming part of the IT network architecture.

Core message: When security systems are integrated into IT networks, they must work together efficiently – without reducing or eliminating the actual level of protection.

The Details

According to the article, security systems in critical infrastructure and OT environments are subject to the regulations of the German Critical Infrastructure Umbrella Act (KRITIS-Dachgesetz), the BSI Act (BSI-Gesetz), as well as other relevant standards such as the BSI IT-Grundschutz and the IEC 62443 standard. From this, Greunke derives the need to design the networking of these systems according to a clearly defined and binding security and zone concept. Particular attention must be paid to the communication paths between security systems, control centers, management systems, and neighboring IT networks – these must be strictly regulated.

The article names five specific rules:

  • Create clearly defined zones: Camera systems, sensors, and access components should be operated in logically or physically separated areas. Camera systems, for example, should only interact with associated systems such as NVR (Network Video Recorder) or VMS (Video Management System). Firewalls or segment gateways monitor and secure the transitions between zones.
  • Separate office IT and external networks: Security systems should generally run outside the conventional corporate IT environment. Transitions occur via designated points such as DMZ or NAT zones, which allow controlled use of services such as Active Directory, DNS, or PKI without compromising the security segments.
  • Ensure resilient and self-sufficient operation: An OT security network must remain functional independently even in the event of disruptions to the surrounding IT, WAN failures, or external threats. Mechanisms such as network probes, camera watchdogs, or PoE-based restarts can automatically resolve typical disruptions.
  • Encrypt and monitor communication paths: Video, alarm, and control data must be transmitted in encrypted form. Mentioned are VPNs (client-to-site or site-to-site) for maintenance access and site connections, as well as reverse proxies with end-to-end TLS encryption to guard against man-in-the-middle attacks.
  • Ensure modularity and expandability: New IP cameras or access points should be able to be integrated without significant adjustments to the existing architecture. Zone-based architectures allow new sites to be incorporated as separate segments without altering existing areas.

Assessment

The article makes clear that security technology in critical infrastructure environments can no longer be considered in isolation but must be regarded as an integral part of the IT network structure. This means that those responsible for security technology and IT need to collaborate more closely than before. According to Greunke, historically grown or uncontrolled connections between security systems and other networks conflict with regulatory requirements and are also problematic in terms of traceability and auditability.

For operators of critical infrastructure – for example in the areas of access control, video surveillance, or alarm technology – this creates clear regulatory pressure to act: anyone integrating cameras, access systems, or alarm technology into existing IT landscapes must do so according to a documented zone and security concept that complies with the aforementioned standards and laws.

Practical Tips

  • Operate security systems (cameras, access control, alarm technology) in their own clearly delineated network zones rather than mixing them indiscriminately with office IT.
  • Route transitions between security zones and corporate IT exclusively through defined points such as DMZ or NAT zones and monitor them technically.
  • Plan for automated monitoring mechanisms such as camera watchdogs or PoE-based restarts to ensure availability even without manual intervention.
  • Consistently encrypt communication paths – for example via VPN connections and end-to-end TLS encryption – to prevent manipulation and eavesdropping attempts.
  • When planning new system components, rely on modular, zone-based architectures from the outset so that later expansions are possible without affecting existing segments.

Outlook

Given the regulatory framework mentioned in the article – the Critical Infrastructure Umbrella Act, the BSI Act, BSI IT-Grundschutz, and IEC 62443 – pressure on critical infrastructure operators to design their security technology networks in a standards-compliant and auditable manner is likely to continue growing. Greunke's conclusion sums it up: only a sovereign, standards-compliant, and auditable network provides the foundation for operating security systems in a compliant and structured manner. For planners, installers, and operators of security technology, this means that IT network architecture must henceforth be considered a fixed component of every security concept – from zone planning to the encryption of communication paths.