SABINE FRÖMLING CONSULTING · OT-SECURITY · NIS2 · ISO 27001SABINE FRÖMLING CONSULTING · OT SECURITY · NIS2 · ISO 27001
SPRINGER VIEWEG — 1. AUFLAGE — JETZT ERHÄLTLICHSPRINGER VIEWEG — GERMAN EDITION — AVAILABLE NOW
ISMS für die Industrie
Der Praxisratgeber
Der Praxisratgeber für ein Informationssicherheits-Managementsystem, das den Kontakt mit dem Shopfloor übersteht — von ISO 27001 und NIS2 bis zur gelebten OT-Security. Jedes Kernkapitel verbindet die Norm mit einer Dokumentenvorgabe und einem OT-Praxis-Transfer.The German-language practitioner's guide to building an information security management system that survives contact with the shop floor — from ISO 27001 and NIS2 to hands-on OT security. Every core chapter pairs the standard with a document blueprint and an OT practice transfer.

Jetzt bestellen:Order now: Springer · Amazon · Thalia · Orell Füssli · bücher.de · Hugendubel · Lehmanns · Dussmann · Beck-Shop
Das BuchThe book
Methode statt Papierwerk.Method, not paperwork.
Industrieunternehmen scheitern an der Informationssicherheit nicht am Mangel an Normen — sie scheitern an der Lücke zwischen Norm und Anlage. Dieser Ratgeber schließt sie mit einem konsistenten Drei-Säulen-Muster in jedem Kernkapitel:Industrial companies don't fail at information security for lack of standards — they fail in the gap between the standard and the plant. This guide closes that gap with a consistent three-pillar pattern in every core chapter:
I.
NormStandard
Was ISO/IEC 27001, IEC 62443 und NIS2 tatsächlich fordern — gelesen durch die industrielle Brille, nicht die des Rechenzentrums.What ISO/IEC 27001, IEC 62443 and NIS2 actually require — read through an industrial lens, not a data-centre one.
II.
DokumentenvorgabeDocument blueprint
Eine konkrete Struktur für das Nachweisdokument: Scope, Richtlinien, SoA, Risikoregister und mehr — bereit zur Anpassung.A concrete structure for the deliverable that proves it: scope, policies, SoA, risk register and more — ready to adapt.
III.
OT-Praxis-TransferOT practice transfer
Wo IT-Logik in der Fertigung bricht — und was stattdessen funktioniert, von Patch-Fenstern bis Safety-Verriegelungen.Where IT logic breaks on the shop floor — and what works instead, from patch windows to safety interlocks.
Geschrieben fürWritten for CISOs und Informationssicherheitsbeauftragte, ISMS- und Compliance-Manager, OT- und Automatisierungsingenieure, Auditoren und Berater.CISOs and information security officers, ISMS and compliance managers, OT and automation engineers, auditors and consultants.
Systematisch steuern und belastbar nachweisen.ISO 27001
Govern systematically and build reliable evidence.
Verantwortung, Risiko und Umsetzung zusammenbringen.NIS2
Connect accountability, risk and implementation.
InhaltsverzeichnisTable of contents
Alle 28 Kapitel sind einzeln bei Springer Nature indexiert und über einen persistenten DOI referenzierbar. Klicken Sie auf einen Kapiteltitel für Abstract, bibliografische Angaben und Zugriffsmöglichkeiten.All 28 chapters are individually indexed by Springer Nature and can be referenced via persistent DOI. Select a chapter title for its abstract, bibliographic details and access options.
Teil I — Methodik und GrundlagenPart I — Method and foundations
Teil II — Praxis-ToolboxPart II — Practice toolbox
Inhaltsverzeichnis der veröffentlichten 1. Auflage.The published book is written in German. Chapter titles are shown here in English translation.
Companion-Tools
Sechs kostenlose Tools. Ohne Anmeldung.Six free tools. English mode, no sign-up.
Jedes Tool vertieft ein Kapitel des Ratgebers: browserbasiert, herstellerneutral und workshoptauglich. Kapitelnummern verweisen auf die zugehörigen Abschnitte des Buches; alle Tools sind zweisprachig (DE/EN).Each tool deepens one chapter of the guide: browser-based, vendor-neutral and ready to use in workshops. Chapter numbers reference the corresponding sections of the book; all links below open the English versions.
Kap. 3.5ch. 3.5
Crown-Jewels-CompanionCrown Jewels Companion
Die kritischsten OT-Assets methodisch identifizieren und priorisieren — Begleiter zur Kronjuwelen-Analyse.Methodically identify and prioritise the most critical OT assets — companion to the crown-jewels analysis.
Kap. 8.4ch. 8.4
OT-Tabletop-GeneratorOT Tabletop Generator
Realistische Tabletop-Übungsszenarien für das OT-Vorfallmanagement erzeugen — den Ernstfall trainieren, bevor er eintritt.Generate realistic tabletop exercise scenarios for OT incident management — train for the emergency before it happens.
Kap. 9ch. 9
No-Touch-RegisterNo-Touch Register
Containment-Governance für OT-Vorfälle: dokumentieren, welche Systeme niemals automatisch isoliert oder abgeschaltet werden dürfen.Containment governance for OT incidents: record which systems must never be automatically isolated or shut down.
Kap. 22ch. 22
OT-Fernzugriffs-KriterienkompassOT Remote Access Compass
Anforderungen an sicheren Fernzugriff definieren und Lösungskandidaten strukturiert bewerten — entlang IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 und NIS2.Define requirements for secure remote access and assess candidate solutions in a structured way — along IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 and NIS2.
Kap. 22.2ch. 22.2
JIT-Fernwartungs-FahrplanJIT Remote Maintenance Roadmap
Just-in-Time-Fernwartung entlang des Vier-Stufen-Modells planen: Zugriff nur bei Bedarf — nachvollziehbar und zeitlich begrenzt.Plan just-in-time remote maintenance along the four-stage model: access only when needed — traceable and time-boxed.
Resilienzresilience
Island-Mode-72h-StresstestIsland Mode 72h Stress TestNEUNEW
Ein Testprogramm für die Frage, ob kritische Prozesse 72 Stunden autark laufen können — von Credential-Caches bis Offline-Backups.A test programme for whether critical processes can run autonomously for 72 hours — from credential caches to offline backups.
Alle Tools sind offen auf GitHub veröffentlicht und laufen vollständig im Browser — es verlassen keine Daten Ihren Rechner.All tools are published openly on GitHub and run entirely in the browser — no data leaves your machine.
FachbeiträgeArticles
Publiziert auf drei Kontinenten.Published across three continents.
Regelmäßige Beiträge zu Cybersecurity, OT-Governance und Compliance für führende Fachmedien: die Foundry-Titel CSO Online (englisch und deutsch), Computerwoche, CIO.de und Computerworld España, syndiziert an ITWorld Korea, sowie it-daily, die <kes>, die Fachzeitschrift für Informationssicherheit, und iX. Die Sprache jedes Beitrags ist gekennzeichnet.Regular contributions on cybersecurity, OT governance and compliance for leading specialist publications: Foundry titles including CSO Online (English and German), Computerwoche, CIO.de and Computerworld España, syndicated to ITWorld Korea, as well as it-daily, <kes>, the German information security journal, and iX. The language of each piece is tagged.
2026
[DE] Wenn der eigene Security-Stack zur Angriffsfläche wird Warum EDR, Schwachstellenscanner, SIEM und automatische Updates selbst zur Angriffsfläche werden können. Der Beitrag zeigt, weshalb Privilegien, Vertrauensbeziehungen, Update-Ketten und die Autonomie von Sicherheitswerkzeugen eigene Kontrollen brauchen.Why EDR, vulnerability scanners, SIEM and automatic updates can themselves become an attack surface. The article explains why the privileges, trust relationships, update chains and autonomy of security tools require their own controls.NEUNEW
[EN] CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production Wie Betreiber Siemens-S7-Steuerungen härten, ohne HMI-, Engineering-, Remote-I/O- oder andere Produktionsabhängigkeiten unbeabsichtigt zu unterbrechen. Der Beitrag zeigt, wie sich die Empfehlungen mit einer Prüfung der Abhängigkeiten, einem geplanten OT-Change und einem überprüfbaren Rollback umsetzen lassen.How operators can harden Siemens S7 PLCs without unintentionally breaking HMI, engineering, remote-I/O or other production dependencies. The article explains how dependency checks, a planned OT change and a verifiable rollback path turn hardening guidance into operational practice.
[EN] When the patch tsunami meets the maintenance window. KI beschleunigt die Schwachstellenfindung auf Maschinengeschwindigkeit, während OT-Patching an Wartungsfenstern, OEM-Freigaben und Betriebsrisiken gebunden bleibt. Der Beitrag zeigt, wie Betreiber die wachsende Lücke mit risikobasierter Priorisierung, kompensierenden Kontrollen und belastbarem Change Management beherrschen.AI can find flaws in hours, but factories cannot patch that fast. The article shows how OT teams can manage the widening gap with risk-based prioritisation, compensating controls and disciplined change management.
[DE] Wenn die Bundesnetzagentur den Strom drosselt.
[DE] DDoS für 5 Dollar: Wie Miet-Hacker ganze Unternehmen lahmlegen Wie gemietete DDoS-Angriffe und IoT-Botnetze die Verfügbarkeit von Unternehmen bedrohen. Der Beitrag erläutert Angriffsarten, technische Zusammenhänge und Maßnahmen zum Schutz von Netzwerken und Online-Diensten.How rented DDoS attacks and IoT botnets threaten business availability. The article explains attack types, the underlying technology and measures to protect networks and online services.
[DE] Die Schwachstelle wird billig, der Stillstand bleibt teuer.
[DE] Die 5 gefährlichsten Sätze in Industrieunternehmen.
[EN] The Minnesota attackers may hold a better backup of your plant than you do.
[EN] The containment paradox: Why your ransomware playbook has the wrong people in charge.
[ES] La paradoja de la contención: por qué su plan contra el ‘ransomware’ pone a las personas equivocadas al mando. Spanische Ausgabe von „The containment paradox“.Spanish edition of “The containment paradox”.
[DE] OT-Sicherheit: Der Fernwartungszugang, den niemand mehr kennt. OT security: the forgotten remote maintenance access that may still provide a hidden path into production.
[DE] Dotcom-Blase und KI-Boom im Vergleich. The dotcom bubble vs. the AI boom: parallels, differences — and three tests for your AI portfolio.
[EN] Agentic AI identity: A 6-stage maturity model for non-human identities.
[DE] „Läuft seit 15 Jahren ohne Zwischenfall“. Running for 15 years without incident: why external service providers are the biggest risk to production networks.
[DE] Wo die souveräne Cloud Sinn macht – und wo nicht. Sovereign cloud, private cloud or hyperscaler: a workload-level decision guide.
[DE] Der blinde Fleck der europäischen Industrie. Opinion: compliant, certified — and vulnerable nonetheless. The reality in many European industrial companies.
[EN] Sovereign cloud won't fix your AI risk — identity governance will.
[EN] Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines.
2025
[KO] CISO의 소프트 스킬, 이제는 없으면 안 되는 '파워 스킬'로. Korean edition: CISO soft skills are now indispensable "power skills".Koreanische Ausgabe: CISO-Soft-Skills sind heute unverzichtbare „Power Skills“.
[EN] The 5 power skills every CISO needs to master in the AI era.
[EN] What keeps CISOs awake at night — and why Zurich might hold the cure.
[EN] OT security: Why it pays to look at open source.
[KO] 컴플라이언스 위기를 막는 가장 확실한 전략, 서드파티 리스크 관리. Korean edition: The most reliable strategy against compliance crises — third-party risk management.Koreanische Ausgabe: Die sicherste Strategie gegen die Compliance-Krise — Third-Party-Risk-Management.
[EN] Third-party risk management: How to avoid compliance disaster.
2024
In der PresseIn the press
OpenAI „hackt“ Hugging Face – eine Analyse — Computerwoche zitiert Sabine Frömling in der News-Analyse vom 23. Juli 2026 als Experten-Autorin und Cybersecurity-Beraterin, neben Analysten und Security-Verantwortlichen von Forrester, KuppingerCole, Acronis, Bitdefender und TrendAI. Ihre Einordnung: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“ — Computerwoche quotes Sabine Frömling in its July 23, 2026 news analysis as an expert author and cybersecurity consultant, alongside analysts and security leaders from Forrester, KuppingerCole, Acronis, Bitdefender and TrendAI. Her assessment: “The real security incident was not the AI, but the sandbox that accidentally had a door to the internet. They released a predator and blamed the fence.”
The Ghost in Your Warehouse — für die Q4-Ausgabe 2026 des MHI Solutions Magazine als OT-Security-Expertin zu Legacy-OT in der Intralogistik interviewt: unsichtbare Altsysteme — Industrie-PCs, Operator-Panels, einzelne alte Windows-Rechner —, die den Materialfluss moderner Läger steuern, aber auf keinem Netzwerkdiagramm auftauchen. Neben Stimmen von Gartner, Beckhoff und Designed Conveyor Systems ordnet Frömling ein, warum das Problem primär organisatorisch statt technisch ist — und warum am Anfang ein belastbares Asset-Inventory steht. (erscheint Q4 2026) — interviewed as an OT security expert on legacy OT in intralogistics for the Q4 2026 issue of MHI Solutions Magazine: the invisible legacy systems — industrial PCs, operator panels, the odd ageing Windows box — that run the material flow of modern warehouses yet appear on no network diagram. Alongside voices from Gartner, Beckhoff and Designed Conveyor Systems, Frömling explains why the problem is primarily organisational rather than technical — and why every hardening effort starts with a reliable asset inventory. (appears Q4 2026)
Doppelbelastung: Projektmitarbeiter unter Druck — Karriere-Porträt der Computerwoche (August 2012) über Frömlings MBA-Forschung zur Doppelbelastung von Mitarbeitern, die Projekte neben der Linientätigkeit stemmen. — a Computerwoche careers feature (August 2012) on Frömling's MBA research into the double burden carried by staff who work projects on top of their line duties.
In KürzeComing soon
Medien & PresseMedia & Press
Wenn Cybersecurity physisch wird.When cybersecurity becomes physical.
Kurzfristig ansprechbar für aktuelle Stellungnahmen, Interviews und Hintergrundgespräche zu industrieller Cybersicherheit und KRITIS-Resilienz.Available at short notice for expert comment, interviews and background briefings on industrial cybersecurity and critical-infrastructure resilience.
Expertin für industrielle Cybersicherheit und KRITIS-ResilienzIndependent expert on industrial cybersecurity and critical-infrastructure resilience
Insbesondere dort, wo Cybervorfälle zu realen Produktions- und Versorgungsausfällen werden. Ich verbinde technische OT-Security mit der organisatorischen Betriebsrealität kritischer Infrastrukturen — unabhängig, herstellerneutral und verständlich für ein nichttechnisches Publikum.Specialising in the point where cyber incidents become physical outages. I connect technical OT security with the operational reality of critical infrastructure — independently, vendor-neutrally and in language that works for non-technical audiences.
Was passiert technisch und organisatorisch in einem Kraftwerk, einer Fabrik, einem Wasserwerk oder Netzbetrieb, wenn Cybersecurity auf physische Betriebsrealität trifft?What happens technically and organisationally inside a power plant, factory, water utility or grid operation when cybersecurity collides with physical operations?
Wozu ich kurzfristig einordnen kannTopics I can explain at short notice
- Cyberangriffe auf Kraftwerke, Produktion, Wasser- und EnergieversorgungCyberattacks affecting power plants, manufacturing, water and energy operations
- Ransomware in OT: Abschalten, isolieren, weiterfahren oder manuell betreiben?Ransomware in OT: shut down, isolate, keep running or switch to manual operation?
- Incident Response, Wiederanlauf und betriebliche Resilienz in industriellen UmgebungenIncident response, recovery and operational resilience in industrial environments
- Fernzugriffe, Altanlagen, Lieferanten und andere typische industrielle AngriffswegeRemote access, legacy systems, suppliers and other common industrial attack paths
- NIS2, KRITIS und Security-Governance — mit Blick auf die tatsächliche WerkhallenrealitätNIS2, critical-infrastructure regulation and security governance — viewed through real shop-floor operations
- KI, Security-Tools und neue Cyberrisiken an der IT/OT-GrenzeAI, security tooling and emerging cyber risks at the IT/OT boundary
Interview- und StatementformateInterview and comment formats
Vom schnellen schriftlichen O-Ton bis zur Live-Schalte. Die Einordnung kann technisch tief gehen oder in wenigen Sätzen für Nachrichtenpublikum heruntergebrochen werden.From a rapid written quote to a live broadcast. The explanation can go deep technically or be distilled into a few clear sentences for a general news audience.
Für die redaktionelle NennungSuggested attribution
Kurz und direkt verwendbar:Short, ready-to-use wording:
Sabine Frömling, Expertin für industrielle Cybersicherheit und KRITIS-ResilienzSabine Frömling, industrial cybersecurity and critical-infrastructure resilience expert
Alternativ ausführlicher: Sabine Frömling, unabhängige IT/OT-Security-Beraterin und Autorin des Springer-Vieweg-Fachbuchs ISMS für die Industrie.Longer alternative: Sabine Frömling, independent IT/OT security consultant and author of the Springer Vieweg book ISMS für die Industrie.
Kurzvita · ca. 40 WörterShort bio · approx. 40 words
Sabine Frömling ist unabhängige Beraterin und Fachautorin für industrielle Cybersicherheit, OT-Security und KRITIS-Resilienz. Sie berät seit vielen Jahren an der Schnittstelle von Informationssicherheit und physischer Betriebsrealität und ist Autorin des Springer-Vieweg-Fachbuchs ISMS für die Industrie.Sabine Frömling is an independent consultant and specialist author on industrial cybersecurity, OT security and critical-infrastructure resilience. Her work focuses on the point where information security meets physical operations. She is the author of the Springer Vieweg book ISMS für die Industrie.
Redaktionsbio · ca. 100 WörterEditorial bio · approx. 100 words
Sabine Frömling ist unabhängige IT/OT-Security-Beraterin und Fachautorin mit Schwerpunkt auf industrieller Cybersicherheit und KRITIS-Resilienz. Sie arbeitet an der Schnittstelle zwischen Cybervorfällen, Anlagenbetrieb und physischen Auswirkungen — insbesondere in Energie, Fertigung und anderen industriellen Umgebungen. Ihre Beiträge erscheinen regelmäßig bei CSO Online, Computerwoche, CIO.de, <kes>, it-daily und iX. Sie ist Autorin des bei Springer Vieweg erschienenen Fachbuchs ISMS für die Industrie – Der Praxisratgeber.Sabine Frömling is an independent IT/OT security consultant and specialist author focused on industrial cybersecurity and critical-infrastructure resilience. Her work examines the point where cyber incidents meet plant operations and physical consequences, particularly in energy, manufacturing and other industrial environments. Her articles appear regularly in CSO Online, Computerwoche, CIO.de, <kes>, it-daily and iX. She is the author of the Springer Vieweg book ISMS für die Industrie – Der Praxisratgeber.
Media-KitMedia kit
Kurzprofil, Kernthemen, zitierfähige Thesen, Interviewfragen, Publikationen und Kontaktdaten kompakt auf zwei Seiten.A compact two-page overview with profile, core topics, quotable positions, interview questions, publications and contact details. The PDF is currently available in German.
PressefotoPress photo
Das aktuelle Portrait kann für redaktionelle Berichterstattung verwendet werden. Bitte den Bildnachweis „Sabine Frömling“ verwenden, sofern kein abweichender Fotografen-Credit vereinbart wurde.The current portrait may be used for editorial coverage. Please credit “Sabine Frömling” unless a different photographer credit has been agreed.
Hinweis: Für Print oder großformatige Nutzung kann auf Anfrage eine höher aufgelöste Datei bereitgestellt werden.Note: A higher-resolution file can be provided on request for print or large-format use.
Zuletzt als Expertin gefragtRecent expert appearances
Presseanfragen & kurzfristige InterviewsMedia enquiries & short-notice interviews
Für aktuelle Cyberlagen, Expertenstatements und Hintergrundgespräche bitte direkt per E-Mail oder Telefon kontaktieren.For breaking cyber incidents, expert comment or background briefings, contact me directly by email or phone.