SABINE FRÖMLING CONSULTING · OT-SECURITY · NIS2 · ISO 27001SABINE FRÖMLING CONSULTING · OT SECURITY · NIS2 · ISO 27001
SPRINGER VIEWEG — 1. AUFLAGE — SEPTEMBER 2026SPRINGER VIEWEG — GERMAN EDITION — SEPTEMBER 2026
ISMS für die Industrie
Der Praxisratgeber
Der Praxisratgeber für ein Informationssicherheits-Managementsystem, das den Kontakt mit dem Shopfloor übersteht — von ISO 27001 und NIS2 bis zur gelebten OT-Security. Jedes Kernkapitel verbindet die Norm mit einer Dokumentenvorgabe und einem OT-Praxis-Transfer.The German-language practitioner's guide to building an information security management system that survives contact with the shop floor — from ISO 27001 and NIS2 to hands-on OT security. Every core chapter pairs the standard with a document blueprint and an OT practice transfer.

Jetzt vorbestellen:Pre-order now: Springer · Amazon · Hugendubel · Lehmanns · Thalia · Dussmann · buecher.de · Beck-Shop
Das BuchThe book
Methode statt Papierwerk.Method, not paperwork.
Industrieunternehmen scheitern an der Informationssicherheit nicht am Mangel an Normen — sie scheitern an der Lücke zwischen Norm und Anlage. Dieser Ratgeber schließt sie mit einem konsistenten Drei-Säulen-Muster in jedem Kernkapitel:Industrial companies don't fail at information security for lack of standards — they fail in the gap between the standard and the plant. This guide closes that gap with a consistent three-pillar pattern in every core chapter:
I.
NormStandard
Was ISO/IEC 27001, IEC 62443 und NIS2 tatsächlich fordern — gelesen durch die industrielle Brille, nicht die des Rechenzentrums.What ISO/IEC 27001, IEC 62443 and NIS2 actually require — read through an industrial lens, not a data-centre one.
II.
DokumentenvorgabeDocument blueprint
Eine konkrete Struktur für das Nachweisdokument: Scope, Richtlinien, SoA, Risikoregister und mehr — bereit zur Anpassung.A concrete structure for the deliverable that proves it: scope, policies, SoA, risk register and more — ready to adapt.
III.
OT-Praxis-TransferOT practice transfer
Wo IT-Logik in der Fertigung bricht — und was stattdessen funktioniert, von Patch-Fenstern bis Safety-Verriegelungen.Where IT logic breaks on the shop floor — and what works instead, from patch windows to safety interlocks.
Geschrieben fürWritten for CISOs und Informationssicherheitsbeauftragte, ISMS- und Compliance-Manager, OT- und Automatisierungsingenieure, Auditoren und Berater.CISOs and information security officers, ISMS and compliance managers, OT and automation engineers, auditors and consultants.
Systematisch steuern und belastbar nachweisen.ISO 27001
Govern systematically and build reliable evidence.
Verantwortung, Risiko und Umsetzung zusammenbringen.NIS2
Connect accountability, risk and implementation.
InhaltsverzeichnisTable of contents
Teil I — Methodik und GrundlagenPart I — Method and foundations
Teil II — Praxis-ToolboxPart II — Practice toolbox
Gliederung gemäß aktuellem Stand; Details können sich bis zum Erscheinen geringfügig ändern.The book is written in German. Chapter titles are shown here in English translation.
Companion-Tools
Sechs kostenlose Tools. Ohne Anmeldung.Six free tools. English mode, no sign-up.
Jedes Tool vertieft ein Kapitel des Ratgebers: browserbasiert, herstellerneutral und workshoptauglich. Kapitelnummern verweisen auf die zugehörigen Abschnitte des Buches; alle Tools sind zweisprachig (DE/EN).Each tool deepens one chapter of the guide: browser-based, vendor-neutral and ready to use in workshops. Chapter numbers reference the corresponding sections of the book; all links below open the English versions.
Kap. 3.5ch. 3.5
Crown-Jewels-CompanionCrown Jewels Companion
Die kritischsten OT-Assets methodisch identifizieren und priorisieren — Begleiter zur Kronjuwelen-Analyse.Methodically identify and prioritise the most critical OT assets — companion to the crown-jewels analysis.
Kap. 8.4ch. 8.4
OT-Tabletop-GeneratorOT Tabletop Generator
Realistische Tabletop-Übungsszenarien für das OT-Vorfallmanagement erzeugen — den Ernstfall trainieren, bevor er eintritt.Generate realistic tabletop exercise scenarios for OT incident management — train for the emergency before it happens.
Kap. 9ch. 9
No-Touch-RegisterNo-Touch Register
Containment-Governance für OT-Vorfälle: dokumentieren, welche Systeme niemals automatisch isoliert oder abgeschaltet werden dürfen.Containment governance for OT incidents: record which systems must never be automatically isolated or shut down.
Kap. 22ch. 22
OT-Fernzugriffs-KriterienkompassOT Remote Access Compass
Anforderungen an sicheren Fernzugriff definieren und Lösungskandidaten strukturiert bewerten — entlang IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 und NIS2.Define requirements for secure remote access and assess candidate solutions in a structured way — along IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 and NIS2.
Kap. 22.2ch. 22.2
JIT-Fernwartungs-FahrplanJIT Remote Maintenance Roadmap
Just-in-Time-Fernwartung entlang des Vier-Stufen-Modells planen: Zugriff nur bei Bedarf — nachvollziehbar und zeitlich begrenzt.Plan just-in-time remote maintenance along the four-stage model: access only when needed — traceable and time-boxed.
Resilienzresilience
Island-Mode-72h-StresstestIsland Mode 72h Stress TestNEUNEW
Ein Testprogramm für die Frage, ob kritische Prozesse 72 Stunden autark laufen können — von Credential-Caches bis Offline-Backups.A test programme for whether critical processes can run autonomously for 72 hours — from credential caches to offline backups.
Alle Tools sind offen auf GitHub veröffentlicht und laufen vollständig im Browser — es verlassen keine Daten Ihren Rechner.All tools are published openly on GitHub and run entirely in the browser — no data leaves your machine.
FachbeiträgeArticles
Publiziert auf drei Kontinenten.Published across three continents.
Regelmäßige Beiträge zu Cybersecurity, OT-Governance und Compliance für Foundry-Medien — CSO Online (englisch und deutsch), Computerwoche und CIO.de, syndiziert an ITWorld Korea — sowie für die <kes>, die Fachzeitschrift für Informationssicherheit. Die Sprache jedes Beitrags ist gekennzeichnet.Regular contributions on cybersecurity, OT governance and compliance for Foundry outlets — CSO Online (English and German), Computerwoche and CIO.de, syndicated to ITWorld Korea — and for <kes>, the German information security journal. The language of each piece is tagged.
2026
[EN] The containment paradox: Why your ransomware playbook has the wrong people in charge. NEUNEWEST
[DE] OT-Sicherheit: Der Fernwartungszugang, den niemand mehr kennt. OT security: the forgotten remote maintenance access that may still provide a hidden path into production.
[DE] Dotcom-Blase und KI-Boom im Vergleich. The dotcom bubble vs. the AI boom: parallels, differences — and three tests for your AI portfolio.
[EN] Agentic AI identity: A 6-stage maturity model for non-human identities.
[DE] „Läuft seit 15 Jahren ohne Zwischenfall“. Running for 15 years without incident: why external service providers are the biggest risk to production networks.
[DE] Wo die souveräne Cloud Sinn macht – und wo nicht. Sovereign cloud, private cloud or hyperscaler: a workload-level decision guide.
[DE] Der blinde Fleck der europäischen Industrie. Opinion: compliant, certified — and vulnerable nonetheless. The reality in many European industrial companies.
[EN] Sovereign cloud won't fix your AI risk — identity governance will.
[EN] Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines.
2025
[KO] CISO의 소프트 스킬, 이제는 없으면 안 되는 '파워 스킬'로. Korean edition: CISO soft skills are now indispensable "power skills".Koreanische Ausgabe: CISO-Soft-Skills sind heute unverzichtbare „Power Skills“.
[EN] The 5 power skills every CISO needs to master in the AI era.
[EN] What keeps CISOs awake at night — and why Zurich might hold the cure.
[EN] OT security: Why it pays to look at open source.
[KO] 컴플라이언스 위기를 막는 가장 확실한 전략, 서드파티 리스크 관리. Korean edition: The most reliable strategy against compliance crises — third-party risk management.Koreanische Ausgabe: Die sicherste Strategie gegen die Compliance-Krise — Third-Party-Risk-Management.
[EN] Third-party risk management: How to avoid compliance disaster.
2024
In der PresseIn the press
OpenAI „hackt“ Hugging Face – eine Analyse — Computerwoche zitiert Sabine Frömling in der News-Analyse vom 23. Juli 2026 als Experten-Autorin und Cybersecurity-Beraterin, neben Analysten und Security-Verantwortlichen von Forrester, KuppingerCole, Acronis, Bitdefender und TrendAI. Ihre Einordnung: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“ — Computerwoche quotes Sabine Frömling in its July 23, 2026 news analysis as an expert author and cybersecurity consultant, alongside analysts and security leaders from Forrester, KuppingerCole, Acronis, Bitdefender and TrendAI. Her assessment: “The real security incident was not the AI, but the sandbox that accidentally had a door to the internet. They released a predator and blamed the fence.”
The Ghost in Your Warehouse — für die Q4-Ausgabe 2026 des MHI Solutions Magazine als OT-Security-Expertin zu Legacy-OT in der Intralogistik interviewt: unsichtbare Altsysteme — Industrie-PCs, Operator-Panels, einzelne alte Windows-Rechner —, die den Materialfluss moderner Läger steuern, aber auf keinem Netzwerkdiagramm auftauchen. Neben Stimmen von Gartner, Beckhoff und Designed Conveyor Systems ordnet Frömling ein, warum das Problem primär organisatorisch statt technisch ist — und warum am Anfang ein belastbares Asset-Inventory steht. (erscheint Q4 2026) — interviewed as an OT security expert on legacy OT in intralogistics for the Q4 2026 issue of MHI Solutions Magazine: the invisible legacy systems — industrial PCs, operator panels, the odd ageing Windows box — that run the material flow of modern warehouses yet appear on no network diagram. Alongside voices from Gartner, Beckhoff and Designed Conveyor Systems, Frömling explains why the problem is primarily organisational rather than technical — and why every hardening effort starts with a reliable asset inventory. (appears Q4 2026)
Doppelbelastung: Projektmitarbeiter unter Druck — Karriere-Porträt der Computerwoche (August 2012) über Frömlings MBA-Forschung zur Doppelbelastung von Mitarbeitern, die Projekte neben der Linientätigkeit stemmen. — a Computerwoche careers feature (August 2012) on Frömling's MBA research into the double burden carried by staff who work projects on top of their line duties.
In KürzeComing soon