SABINE FRÖMLING CONSULTING · OT-SECURITY · NIS2 · ISO 27001SABINE FRÖMLING CONSULTING · OT SECURITY · NIS2 · ISO 27001

SPRINGER VIEWEG — 1. AUFLAGE — JETZT ERHÄLTLICHSPRINGER VIEWEG — GERMAN EDITION — AVAILABLE NOW

ISMS für die Industrie

Der Praxisratgeber

Der Praxisratgeber für ein Informationssicherheits-Managementsystem, das den Kontakt mit dem Shopfloor übersteht — von ISO 27001 und NIS2 bis zur gelebten OT-Security. Jedes Kernkapitel verbindet die Norm mit einer Dokumentenvorgabe und einem OT-Praxis-Transfer.The German-language practitioner's guide to building an information security management system that survives contact with the shop floor — from ISO 27001 and NIS2 to hands-on OT security. Every core chapter pairs the standard with a document blueprint and an OT practice transfer.

Buchcover: ISMS für die Industrie – Der Praxisratgeber von Sabine Frömling, Springer Vieweg
Springer Vieweg · 1. Auflage · jetzt erhältlichSpringer Vieweg · 1st edition · available now

Jetzt bestellen:Order now: Springer · Amazon · Thalia · Orell Füssli · bücher.de · Hugendubel · Lehmanns · Dussmann · Beck-Shop

NORMEN & FRAMEWORKSFRAMEWORKS ISO/IEC 27001:2022 IEC 62443 NIS2 / KRITIS BSI IT-Grundschutz NIST CSF 2.0

Das BuchThe book

Methode statt Papierwerk.Method, not paperwork.

Industrieunternehmen scheitern an der Informationssicherheit nicht am Mangel an Normen — sie scheitern an der Lücke zwischen Norm und Anlage. Dieser Ratgeber schließt sie mit einem konsistenten Drei-Säulen-Muster in jedem Kernkapitel:Industrial companies don't fail at information security for lack of standards — they fail in the gap between the standard and the plant. This guide closes that gap with a consistent three-pillar pattern in every core chapter:

I.

NormStandard

Was ISO/IEC 27001, IEC 62443 und NIS2 tatsächlich fordern — gelesen durch die industrielle Brille, nicht die des Rechenzentrums.What ISO/IEC 27001, IEC 62443 and NIS2 actually require — read through an industrial lens, not a data-centre one.

II.

DokumentenvorgabeDocument blueprint

Eine konkrete Struktur für das Nachweisdokument: Scope, Richtlinien, SoA, Risikoregister und mehr — bereit zur Anpassung.A concrete structure for the deliverable that proves it: scope, policies, SoA, risk register and more — ready to adapt.

III.

OT-Praxis-TransferOT practice transfer

Wo IT-Logik in der Fertigung bricht — und was stattdessen funktioniert, von Patch-Fenstern bis Safety-Verriegelungen.Where IT logic breaks on the shop floor — and what works instead, from patch windows to safety interlocks.

Geschrieben fürWritten for CISOs und Informationssicherheitsbeauftragte, ISMS- und Compliance-Manager, OT- und Automatisierungsingenieure, Auditoren und Berater.CISOs and information security officers, ISMS and compliance managers, OT and automation engineers, auditors and consultants.

Verwandte, aber nicht identische Schutzziele: IT fokussiert Vertraulichkeit, Integrität und Verfügbarkeit; OT zusätzlich die Sicherheit von Mensch, Anlage und physischem Prozess.Related, but not identical security objectives: IT focuses on confidentiality, integrity and availability; OT also protects people, plant operations and the physical process.
ISO 27001
Systematisch steuern und belastbar nachweisen.
ISO 27001
Govern systematically and build reliable evidence.
NIS2
Verantwortung, Risiko und Umsetzung zusammenbringen.
NIS2
Connect accountability, risk and implementation.

InhaltsverzeichnisTable of contents

Alle 28 Kapitel sind einzeln bei Springer Nature indexiert und über einen persistenten DOI referenzierbar. Klicken Sie auf einen Kapiteltitel für Abstract, bibliografische Angaben und Zugriffsmöglichkeiten.All 28 chapters are individually indexed by Springer Nature and can be referenced via persistent DOI. Select a chapter title for its abstract, bibliographic details and access options.

Teil I — Methodik und GrundlagenPart I — Method and foundations

Teil II — Praxis-ToolboxPart II — Practice toolbox

Inhaltsverzeichnis der veröffentlichten 1. Auflage.The published book is written in German. Chapter titles are shown here in English translation.


Companion-Tools

Sechs kostenlose Tools. Ohne Anmeldung.Six free tools. English mode, no sign-up.

Jedes Tool vertieft ein Kapitel des Ratgebers: browserbasiert, herstellerneutral und workshoptauglich. Kapitelnummern verweisen auf die zugehörigen Abschnitte des Buches; alle Tools sind zweisprachig (DE/EN).Each tool deepens one chapter of the guide: browser-based, vendor-neutral and ready to use in workshops. Chapter numbers reference the corresponding sections of the book; all links below open the English versions.

Von der Governance in die Werkhalle: Sicherheitskontrollen, Anlagenübersicht und praktische Umsetzung im Betrieb.From governance into the plant: security controls, asset visibility and practical implementation in operations.

Kap. 3.5ch. 3.5

Crown-Jewels-CompanionCrown Jewels Companion

Die kritischsten OT-Assets methodisch identifizieren und priorisieren — Begleiter zur Kronjuwelen-Analyse.Methodically identify and prioritise the most critical OT assets — companion to the crown-jewels analysis.

Tool öffnen →Open tool →

Kap. 8.4ch. 8.4

OT-Tabletop-GeneratorOT Tabletop Generator

Realistische Tabletop-Übungsszenarien für das OT-Vorfallmanagement erzeugen — den Ernstfall trainieren, bevor er eintritt.Generate realistic tabletop exercise scenarios for OT incident management — train for the emergency before it happens.

Tool öffnen →Open tool →

Kap. 9ch. 9

No-Touch-RegisterNo-Touch Register

Containment-Governance für OT-Vorfälle: dokumentieren, welche Systeme niemals automatisch isoliert oder abgeschaltet werden dürfen.Containment governance for OT incidents: record which systems must never be automatically isolated or shut down.

Tool öffnen →Open tool →

Kap. 22ch. 22

OT-Fernzugriffs-KriterienkompassOT Remote Access Compass

Anforderungen an sicheren Fernzugriff definieren und Lösungskandidaten strukturiert bewerten — entlang IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 und NIS2.Define requirements for secure remote access and assess candidate solutions in a structured way — along IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 and NIS2.

Tool öffnen →Open tool →

Kap. 22.2ch. 22.2

JIT-Fernwartungs-FahrplanJIT Remote Maintenance Roadmap

Just-in-Time-Fernwartung entlang des Vier-Stufen-Modells planen: Zugriff nur bei Bedarf — nachvollziehbar und zeitlich begrenzt.Plan just-in-time remote maintenance along the four-stage model: access only when needed — traceable and time-boxed.

Tool öffnen →Open tool →

Resilienzresilience

Island-Mode-72h-StresstestIsland Mode 72h Stress TestNEUNEW

Ein Testprogramm für die Frage, ob kritische Prozesse 72 Stunden autark laufen können — von Credential-Caches bis Offline-Backups.A test programme for whether critical processes can run autonomously for 72 hours — from credential caches to offline backups.

Tool öffnen →Open tool →

Alle Tools sind offen auf GitHub veröffentlicht und laufen vollständig im Browser — es verlassen keine Daten Ihren Rechner.All tools are published openly on GitHub and run entirely in the browser — no data leaves your machine.


FachbeiträgeArticles

Publiziert auf drei Kontinenten.Published across three continents.

Regelmäßige Beiträge zu Cybersecurity, OT-Governance und Compliance für führende Fachmedien: die Foundry-Titel CSO Online (englisch und deutsch), Computerwoche, CIO.de und Computerworld España, syndiziert an ITWorld Korea, sowie it-daily, die <kes>, die Fachzeitschrift für Informationssicherheit, und iX. Die Sprache jedes Beitrags ist gekennzeichnet.Regular contributions on cybersecurity, OT governance and compliance for leading specialist publications: Foundry titles including CSO Online (English and German), Computerwoche, CIO.de and Computerworld España, syndicated to ITWorld Korea, as well as it-daily, <kes>, the German information security journal, and iX. The language of each piece is tagged.

2026

[DE] Wenn der eigene Security-Stack zur Angriffsfläche wird Computerwoche, 10. September 2026 · 8 Min.Computerwoche, September 10, 2026 · 8 min.Warum EDR, Schwachstellenscanner, SIEM und automatische Updates selbst zur Angriffsfläche werden können. Der Beitrag zeigt, weshalb Privilegien, Vertrauensbeziehungen, Update-Ketten und die Autonomie von Sicherheitswerkzeugen eigene Kontrollen brauchen.Why EDR, vulnerability scanners, SIEM and automatic updates can themselves become an attack surface. The article explains why the privileges, trust relationships, update chains and autonomy of security tools require their own controls.NEUNEW

[EN] CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production CSO Online, 8. September 2026 · 8 Min.CSO Online, September 8, 2026 · 8 min.Wie Betreiber Siemens-S7-Steuerungen härten, ohne HMI-, Engineering-, Remote-I/O- oder andere Produktionsabhängigkeiten unbeabsichtigt zu unterbrechen. Der Beitrag zeigt, wie sich die Empfehlungen mit einer Prüfung der Abhängigkeiten, einem geplanten OT-Change und einem überprüfbaren Rollback umsetzen lassen.How operators can harden Siemens S7 PLCs without unintentionally breaking HMI, engineering, remote-I/O or other production dependencies. The article explains how dependency checks, a planned OT change and a verifiable rollback path turn hardening guidance into operational practice.

[EN] When the patch tsunami meets the maintenance window. CSO Online, 2. September 2026 · 8 Min.CSO Online, September 2, 2026 · 8 min.KI beschleunigt die Schwachstellenfindung auf Maschinengeschwindigkeit, während OT-Patching an Wartungsfenstern, OEM-Freigaben und Betriebsrisiken gebunden bleibt. Der Beitrag zeigt, wie Betreiber die wachsende Lücke mit risikobasierter Priorisierung, kompensierenden Kontrollen und belastbarem Change Management beherrschen.AI can find flaws in hours, but factories cannot patch that fast. The article shows how OT teams can manage the widening gap with risk-based prioritisation, compensating controls and disciplined change management.

[DE] Wenn die Bundesnetzagentur den Strom drosselt. Computerwoche, 28. August 2026.Computerwoche, August 28, 2026.

[DE] DDoS für 5 Dollar: Wie Miet-Hacker ganze Unternehmen lahmlegen CIO.de, 28. August 2026 · 12 Min.CIO.de, August 28, 2026 · 12 min.Wie gemietete DDoS-Angriffe und IoT-Botnetze die Verfügbarkeit von Unternehmen bedrohen. Der Beitrag erläutert Angriffsarten, technische Zusammenhänge und Maßnahmen zum Schutz von Netzwerken und Online-Diensten.How rented DDoS attacks and IoT botnets threaten business availability. The article explains attack types, the underlying technology and measures to protect networks and online services.

[DE] Die Schwachstelle wird billig, der Stillstand bleibt teuer. it-daily, 20. August 2026.it-daily, August 20, 2026.

[DE] Die 5 gefährlichsten Sätze in Industrieunternehmen. Computerwoche, 19. August 2026.Computerwoche, August 19, 2026.

[EN] The Minnesota attackers may hold a better backup of your plant than you do. CSO Online, 4. August 2026.CSO Online, August 4, 2026.

[EN] The containment paradox: Why your ransomware playbook has the wrong people in charge. CSO Online, 27. Juli 2026.CSO Online, July 27, 2026.

[ES] La paradoja de la contención: por qué su plan contra el ‘ransomware’ pone a las personas equivocadas al mando. Computerworld España, 27. Juli 2026.Computerworld España, July 27, 2026.Spanische Ausgabe von „The containment paradox“.Spanish edition of “The containment paradox”.

[DE] OT-Sicherheit: Der Fernwartungszugang, den niemand mehr kennt. Computerwoche, 20. Juli 2026.Computerwoche, July 20, 2026.OT security: the forgotten remote maintenance access that may still provide a hidden path into production.

[DE] Dotcom-Blase und KI-Boom im Vergleich. CIO.de, 10. Juli 2026.CIO.de, July 10, 2026.The dotcom bubble vs. the AI boom: parallels, differences — and three tests for your AI portfolio.

[EN] Agentic AI identity: A 6-stage maturity model for non-human identities. CSO Online, 9. Juli 2026.CSO Online, July 9, 2026.

[DE] „Läuft seit 15 Jahren ohne Zwischenfall“. <kes> Informationssicherheit, 7. Juli 2026.<kes> Informationssicherheit, July 7, 2026.Running for 15 years without incident: why external service providers are the biggest risk to production networks.

[DE] Wo die souveräne Cloud Sinn macht – und wo nicht. Computerwoche, 30. Juni 2026.Computerwoche, June 30, 2026.Sovereign cloud, private cloud or hyperscaler: a workload-level decision guide.

[DE] Der blinde Fleck der europäischen Industrie. Computerwoche, 26. Juni 2026.Computerwoche, June 26, 2026.Opinion: compliant, certified — and vulnerable nonetheless. The reality in many European industrial companies.

[EN] Sovereign cloud won't fix your AI risk — identity governance will. CSO Online, 15. Juni 2026.CSO Online, June 15, 2026.

[EN] Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines. CSO Online, 22. Mai 2026.CSO Online, May 22, 2026.

[EN] The OT security time bomb: Why legacy industrial systems are the biggest cyber risk nobody wants to fix. CSO Online, 10. März 2026.CSO Online, March 10, 2026.

2025

[KO] CISO의 소프트 스킬, 이제는 없으면 안 되는 '파워 스킬'로. ITWorld Korea, 16. Dezember 2025.ITWorld Korea, December 16, 2025.Korean edition: CISO soft skills are now indispensable "power skills".Koreanische Ausgabe: CISO-Soft-Skills sind heute unverzichtbare „Power Skills“.

[EN] The 5 power skills every CISO needs to master in the AI era. CSO Online, 15. Dezember 2025.CSO Online, December 15, 2025.

[EN] What keeps CISOs awake at night — and why Zurich might hold the cure. CSO Online, 24. November 2025.CSO Online, November 24, 2025.

[EN] OT security: Why it pays to look at open source. CSO Online, 11. September 2025.CSO Online, September 11, 2025.

[KO] 컴플라이언스 위기를 막는 가장 확실한 전략, 서드파티 리스크 관리. ITWorld Korea, 4. Juli 2025.ITWorld Korea, July 4, 2025.Korean edition: The most reliable strategy against compliance crises — third-party risk management.Koreanische Ausgabe: Die sicherste Strategie gegen die Compliance-Krise — Third-Party-Risk-Management.

[EN] Third-party risk management: How to avoid compliance disaster. CSO Online, 3. Juli 2025.CSO Online, July 3, 2025.

[DE] OT-Security: Warum der Blick auf Open Source lohnt. CSO Online (deutsch), 15. April 2025.CSO Online (German), April 15, 2025.

2024

[DE] Third Party Risk Management: So vermeiden Sie Compliance-Unheil. CSO Online (deutsch), 6. August 2024.CSO Online (German), August 6, 2024.

In der PresseIn the press

OpenAI „hackt“ Hugging Face – eine Analyse — Computerwoche zitiert Sabine Frömling in der News-Analyse vom 23. Juli 2026 als Experten-Autorin und Cybersecurity-Beraterin, neben Analysten und Security-Verantwortlichen von Forrester, KuppingerCole, Acronis, Bitdefender und TrendAI. Ihre Einordnung: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“ — Computerwoche quotes Sabine Frömling in its July 23, 2026 news analysis as an expert author and cybersecurity consultant, alongside analysts and security leaders from Forrester, KuppingerCole, Acronis, Bitdefender and TrendAI. Her assessment: “The real security incident was not the AI, but the sandbox that accidentally had a door to the internet. They released a predator and blamed the fence.”

The Ghost in Your Warehouse — für die Q4-Ausgabe 2026 des MHI Solutions Magazine als OT-Security-Expertin zu Legacy-OT in der Intralogistik interviewt: unsichtbare Altsysteme — Industrie-PCs, Operator-Panels, einzelne alte Windows-Rechner —, die den Materialfluss moderner Läger steuern, aber auf keinem Netzwerkdiagramm auftauchen. Neben Stimmen von Gartner, Beckhoff und Designed Conveyor Systems ordnet Frömling ein, warum das Problem primär organisatorisch statt technisch ist — und warum am Anfang ein belastbares Asset-Inventory steht. (erscheint Q4 2026) — interviewed as an OT security expert on legacy OT in intralogistics for the Q4 2026 issue of MHI Solutions Magazine: the invisible legacy systems — industrial PCs, operator panels, the odd ageing Windows box — that run the material flow of modern warehouses yet appear on no network diagram. Alongside voices from Gartner, Beckhoff and Designed Conveyor Systems, Frömling explains why the problem is primarily organisational rather than technical — and why every hardening effort starts with a reliable asset inventory. (appears Q4 2026)

Doppelbelastung: Projektmitarbeiter unter Druck — Karriere-Porträt der Computerwoche (August 2012) über Frömlings MBA-Forschung zur Doppelbelastung von Mitarbeitern, die Projekte neben der Linientätigkeit stemmen. — a Computerwoche careers feature (August 2012) on Frömling's MBA research into the double burden carried by staff who work projects on top of their line duties.

In KürzeComing soon

EINGEREICHTSUBMITTEDMFA auf dem Shop Floor: Wenn Passkeys auf RADIUS treffen — bei iX eingereicht. Der Beitrag untersucht, wie moderne MFA-Verfahren mit industriellen Altprotokollen, gewachsenen Authentifizierungswegen und den Verfügbarkeitsanforderungen der Produktion zusammengebracht werden können. — submitted to iX. The article examines how modern MFA methods can be reconciled with industrial legacy protocols, established authentication paths and the availability requirements of production environments.
AUSGABE 5ISSUE 5Die unterschätzte Achillesferse der OT: das Dienstleister-Vertrauen — IT-SICHERHEIT, Print-Ausgabe 5 — IT-SICHERHEIT, print issue no. 5
AUSGABE 5ISSUE 5Machen heißt nicht Dürfen – warum Compliance in der Realität scheitert — <kes>, Print-Ausgabe 5 — <kes>, print issue no. 5
IN VORBEREITUNGIN PREPARATIONVom Feuerwehrmann zum Vertrauensarchitekten – wie sich die CISO-Rolle neu erfindet — IT-SICHERHEIT, Print — IT-SICHERHEIT, print edition
IN VORBEREITUNGIN PREPARATIONDas ISMS schützt Daten – aber wer schützt Menschen vor KI-Entscheidungen? — <kes> online — <kes> online

Medien & PresseMedia & Press

Wenn Cybersecurity physisch wird.When cybersecurity becomes physical.

Kurzfristig ansprechbar für aktuelle Stellungnahmen, Interviews und Hintergrundgespräche zu industrieller Cybersicherheit und KRITIS-Resilienz.Available at short notice for expert comment, interviews and background briefings on industrial cybersecurity and critical-infrastructure resilience.

Expertin für industrielle Cybersicherheit und KRITIS-ResilienzIndependent expert on industrial cybersecurity and critical-infrastructure resilience

Insbesondere dort, wo Cybervorfälle zu realen Produktions- und Versorgungsausfällen werden. Ich verbinde technische OT-Security mit der organisatorischen Betriebsrealität kritischer Infrastrukturen — unabhängig, herstellerneutral und verständlich für ein nichttechnisches Publikum.Specialising in the point where cyber incidents become physical outages. I connect technical OT security with the operational reality of critical infrastructure — independently, vendor-neutrally and in language that works for non-technical audiences.

Redaktionelle ReferenzenEditorial credentials Springer Vieweg· CSO Online· Computerwoche· CIO.de· <kes>· it-daily· iX

Was passiert technisch und organisatorisch in einem Kraftwerk, einer Fabrik, einem Wasserwerk oder Netzbetrieb, wenn Cybersecurity auf physische Betriebsrealität trifft?What happens technically and organisationally inside a power plant, factory, water utility or grid operation when cybersecurity collides with physical operations?

Wozu ich kurzfristig einordnen kannTopics I can explain at short notice

  • Cyberangriffe auf Kraftwerke, Produktion, Wasser- und EnergieversorgungCyberattacks affecting power plants, manufacturing, water and energy operations
  • Ransomware in OT: Abschalten, isolieren, weiterfahren oder manuell betreiben?Ransomware in OT: shut down, isolate, keep running or switch to manual operation?
  • Incident Response, Wiederanlauf und betriebliche Resilienz in industriellen UmgebungenIncident response, recovery and operational resilience in industrial environments
  • Fernzugriffe, Altanlagen, Lieferanten und andere typische industrielle AngriffswegeRemote access, legacy systems, suppliers and other common industrial attack paths
  • NIS2, KRITIS und Security-Governance — mit Blick auf die tatsächliche WerkhallenrealitätNIS2, critical-infrastructure regulation and security governance — viewed through real shop-floor operations
  • KI, Security-Tools und neue Cyberrisiken an der IT/OT-GrenzeAI, security tooling and emerging cyber risks at the IT/OT boundary

Interview- und StatementformateInterview and comment formats

Vom schnellen schriftlichen O-Ton bis zur Live-Schalte. Die Einordnung kann technisch tief gehen oder in wenigen Sätzen für Nachrichtenpublikum heruntergebrochen werden.From a rapid written quote to a live broadcast. The explanation can go deep technically or be distilled into a few clear sentences for a general news audience.

Schriftliches StatementWritten comment ZeitungsinterviewPress interview Radio / PodcastRadio / podcast TV aufgezeichnetRecorded TV Live-SchalteLive broadcast
Praxis & PublikationenPractice & publicationsLangjährige IT-/OT-Beratung, industrielle Projekterfahrung, Springer-Vieweg-Autorin und regelmäßige Fachautorin.Long-standing IT/OT consulting experience, industrial project work, Springer Vieweg author and regular specialist contributor.
Thematisch passendNews-relevant expertiseFokus auf die Schnittstelle zwischen Cybervorfall, Anlage, Betrieb und physischer Auswirkung.Focused on the point where cyber incidents meet plant operations and physical consequences.
Verständlich & erreichbarClear & reachableKurzfristige Einordnung für Redaktionen; komplexe OT-Sachverhalte in zitierfähiger, verständlicher Sprache.Short-notice media comment; complex OT issues explained in clear, quotable language.

Für die redaktionelle NennungSuggested attribution

Kurz und direkt verwendbar:Short, ready-to-use wording:

Sabine Frömling, Expertin für industrielle Cybersicherheit und KRITIS-ResilienzSabine Frömling, industrial cybersecurity and critical-infrastructure resilience expert

Alternativ ausführlicher: Sabine Frömling, unabhängige IT/OT-Security-Beraterin und Autorin des Springer-Vieweg-Fachbuchs ISMS für die Industrie.Longer alternative: Sabine Frömling, independent IT/OT security consultant and author of the Springer Vieweg book ISMS für die Industrie.

Kurzvita · ca. 40 WörterShort bio · approx. 40 words

Sabine Frömling ist unabhängige Beraterin und Fachautorin für industrielle Cybersicherheit, OT-Security und KRITIS-Resilienz. Sie berät seit vielen Jahren an der Schnittstelle von Informationssicherheit und physischer Betriebsrealität und ist Autorin des Springer-Vieweg-Fachbuchs ISMS für die Industrie.Sabine Frömling is an independent consultant and specialist author on industrial cybersecurity, OT security and critical-infrastructure resilience. Her work focuses on the point where information security meets physical operations. She is the author of the Springer Vieweg book ISMS für die Industrie.

Redaktionsbio · ca. 100 WörterEditorial bio · approx. 100 words

Sabine Frömling ist unabhängige IT/OT-Security-Beraterin und Fachautorin mit Schwerpunkt auf industrieller Cybersicherheit und KRITIS-Resilienz. Sie arbeitet an der Schnittstelle zwischen Cybervorfällen, Anlagenbetrieb und physischen Auswirkungen — insbesondere in Energie, Fertigung und anderen industriellen Umgebungen. Ihre Beiträge erscheinen regelmäßig bei CSO Online, Computerwoche, CIO.de, <kes>, it-daily und iX. Sie ist Autorin des bei Springer Vieweg erschienenen Fachbuchs ISMS für die Industrie – Der Praxisratgeber.Sabine Frömling is an independent IT/OT security consultant and specialist author focused on industrial cybersecurity and critical-infrastructure resilience. Her work examines the point where cyber incidents meet plant operations and physical consequences, particularly in energy, manufacturing and other industrial environments. Her articles appear regularly in CSO Online, Computerwoche, CIO.de, <kes>, it-daily and iX. She is the author of the Springer Vieweg book ISMS für die Industrie – Der Praxisratgeber.

Media-KitMedia kit

Kurzprofil, Kernthemen, zitierfähige Thesen, Interviewfragen, Publikationen und Kontaktdaten kompakt auf zwei Seiten.A compact two-page overview with profile, core topics, quotable positions, interview questions, publications and contact details. The PDF is currently available in German.

PressefotoPress photo

Das aktuelle Portrait kann für redaktionelle Berichterstattung verwendet werden. Bitte den Bildnachweis „Sabine Frömling“ verwenden, sofern kein abweichender Fotografen-Credit vereinbart wurde.The current portrait may be used for editorial coverage. Please credit “Sabine Frömling” unless a different photographer credit has been agreed.

Hinweis: Für Print oder großformatige Nutzung kann auf Anfrage eine höher aufgelöste Datei bereitgestellt werden.Note: A higher-resolution file can be provided on request for print or large-format use.

Zuletzt als Expertin gefragtRecent expert appearances

Computerwoche · OpenAI / Hugging Face Als Cybersecurity-Expertin in einer News-Analyse zum Sicherheitsvorfall zitiert.Quoted as a cybersecurity expert in a news analysis of the security incident.
MHI Solutions Magazine · The Ghost in Your Warehouse Für Q4 2026 als OT-Security-Expertin zu Legacy-OT und unsichtbaren Altsystemen in der Intralogistik interviewt.Interviewed for Q4 2026 as an OT security expert on legacy OT and hidden ageing systems in intralogistics.

Presseanfragen & kurzfristige InterviewsMedia enquiries & short-notice interviews

Für aktuelle Cyberlagen, Expertenstatements und Hintergrundgespräche bitte direkt per E-Mail oder Telefon kontaktieren.For breaking cyber incidents, expert comment or background briefings, contact me directly by email or phone.

Sabine Frömling

Über die AutorinAbout the author

Sabine Frömling

Unabhängige Beraterin für IT/OT-Security und Compliance in Berlin. IT-Beratung seit 2008, seit 2020 mit dediziertem Fokus auf OT- und Industrie-Cybersecurity: mehr als 60 Projekte in 11 Ländern und über 25 Cybersecurity-Programme in Energie, Fertigung, Pharma und Finanzwesen.Independent IT/OT security and compliance consultant based in Berlin. Consulting since 2008, with a dedicated OT and industrial cybersecurity focus since 2020: more than 60 projects in 11 countries and over 25 cybersecurity programmes across energy, manufacturing, pharmaceuticals and financial services.

Sie hält einen MBA; ihre Beiträge erscheinen regelmäßig in Foundry-Titeln wie CSO Online, Computerwoche, CIO.de und ITWorld Korea sowie bei it-daily, in der <kes>, der Fachzeitschrift für Informationssicherheit, und bei iX.She holds an MBA, and her work is published regularly across Foundry titles including CSO Online, Computerwoche, CIO.de and ITWorld Korea, as well as in it-daily, <kes>, the German information security journal, and iX.

SCHWERPUNKTEFOCUS — ISO/IEC 27001 · IEC 62443 · NIS2 / KRITIS · OT-SECURITY-GOVERNANCE · ISMS-AUDITS