SABINE FRÖMLING CONSULTING · OT-SECURITY · NIS2 · ISO 27001SABINE FRÖMLING CONSULTING · OT SECURITY · NIS2 · ISO 27001

SPRINGER VIEWEG — 1. AUFLAGE — SEPTEMBER 2026SPRINGER VIEWEG — GERMAN EDITION — SEPTEMBER 2026

ISMS für die Industrie

Der Praxisratgeber

Der Praxisratgeber für ein Informationssicherheits-Managementsystem, das den Kontakt mit dem Shopfloor übersteht — von ISO 27001 und NIS2 bis zur gelebten OT-Security. Jedes Kernkapitel verbindet die Norm mit einer Dokumentenvorgabe und einem OT-Praxis-Transfer.The German-language practitioner's guide to building an information security management system that survives contact with the shop floor — from ISO 27001 and NIS2 to hands-on OT security. Every core chapter pairs the standard with a document blueprint and an OT practice transfer.

Buchcover: ISMS für die Industrie – Der Praxisratgeber von Sabine Frömling, Springer Vieweg
Springer Vieweg · 1. Auflage · September 2026Springer Vieweg · 1st edition · September 2026

Jetzt vorbestellen:Pre-order now: Springer · Amazon · Hugendubel · Lehmanns · Thalia · Dussmann · buecher.de · Beck-Shop

NORMEN & FRAMEWORKSFRAMEWORKS ISO/IEC 27001:2022 IEC 62443 NIS2 / KRITIS BSI IT-Grundschutz NIST CSF 2.0

Das BuchThe book

Methode statt Papierwerk.Method, not paperwork.

Industrieunternehmen scheitern an der Informationssicherheit nicht am Mangel an Normen — sie scheitern an der Lücke zwischen Norm und Anlage. Dieser Ratgeber schließt sie mit einem konsistenten Drei-Säulen-Muster in jedem Kernkapitel:Industrial companies don't fail at information security for lack of standards — they fail in the gap between the standard and the plant. This guide closes that gap with a consistent three-pillar pattern in every core chapter:

I.

NormStandard

Was ISO/IEC 27001, IEC 62443 und NIS2 tatsächlich fordern — gelesen durch die industrielle Brille, nicht die des Rechenzentrums.What ISO/IEC 27001, IEC 62443 and NIS2 actually require — read through an industrial lens, not a data-centre one.

II.

DokumentenvorgabeDocument blueprint

Eine konkrete Struktur für das Nachweisdokument: Scope, Richtlinien, SoA, Risikoregister und mehr — bereit zur Anpassung.A concrete structure for the deliverable that proves it: scope, policies, SoA, risk register and more — ready to adapt.

III.

OT-Praxis-TransferOT practice transfer

Wo IT-Logik in der Fertigung bricht — und was stattdessen funktioniert, von Patch-Fenstern bis Safety-Verriegelungen.Where IT logic breaks on the shop floor — and what works instead, from patch windows to safety interlocks.

Geschrieben fürWritten for CISOs und Informationssicherheitsbeauftragte, ISMS- und Compliance-Manager, OT- und Automatisierungsingenieure, Auditoren und Berater.CISOs and information security officers, ISMS and compliance managers, OT and automation engineers, auditors and consultants.

Verwandte, aber nicht identische Schutzziele: IT fokussiert Vertraulichkeit, Integrität und Verfügbarkeit; OT zusätzlich die Sicherheit von Mensch, Anlage und physischem Prozess.Related, but not identical security objectives: IT focuses on confidentiality, integrity and availability; OT also protects people, plant operations and the physical process.
ISO 27001
Systematisch steuern und belastbar nachweisen.
ISO 27001
Govern systematically and build reliable evidence.
NIS2
Verantwortung, Risiko und Umsetzung zusammenbringen.
NIS2
Connect accountability, risk and implementation.

InhaltsverzeichnisTable of contents

Teil I — Methodik und GrundlagenPart I — Method and foundations

Warum dieses Buch? Ein Weckruf an die IndustrieWhy this book? A wake-up call to industry1
Rahmenbedingungen und GovernanceFramework conditions and governance2
Risikomanagement: Das Gehirn des ISMSRisk management: the brain of the ISMS3
Operative Umsetzung: Die ControlsOperational implementation: the controls4
OT-Security-Governance und IEC 62443OT security governance and IEC 624435
Safety-Security-Co-EngineeringSafety–security co-engineering6
Der menschliche FaktorThe human factor7
Krisenkommunikation und VorfallmanagementCrisis communication and incident management8
Incident Response Governance: Wer darf was abschalten?Incident response governance: who may shut down what?9
Umsetzungs-Roadmap: Vom ISMS-Plan zur ISMS-RealitätImplementation roadmap: from ISMS plan to ISMS reality10
KRITIS, NIS2 und sektorale BesonderheitenKRITIS, NIS2 and sector specifics11

Teil II — Praxis-ToolboxPart II — Practice toolbox

ISMS-DokumentenhandbuchISMS document handbook12
IT-Grundschutz mit OT-FokusGerman IT-Grundschutz with OT focus13
Cyber-Sicherheits-Check OTCyber security check OT14
Kombinierte OT-SicherheitschecklisteCombined OT security checklist15
OT-Architektur und KommunikationOT architecture and communication16
Das fünfstufige OT-Audit-ModellThe five-stage OT audit model17
BSI-Werkzeuge für SchwachstellenmanagementBSI tools for vulnerability management18
OT-SOC: Betrieb, Use Cases und IntegrationOT SOC: operations, use cases and integration19
OT-Penetrationstests und Purple TeamingOT penetration testing and purple teaming20
OT-Forensik: Wiederherstellung und Beweissicherung nach VorfällenOT forensics: recovery and evidence preservation21
SCADA-ZugriffsmanagementSCADA access management22
AI-Workloads in OT-UmgebungenAI workloads in OT environments23
Backup und Disaster RecoveryBackup and disaster recovery24
LieferkettensicherheitSupply chain security25
DSGVO und Betriebsrat in der OT: Werkzeuge und VorlagenGDPR and works council in OT: tools and templates26
ReifegradmessungMaturity measurement27
Fallstudie: Cybervorfall in einem mittelständischen SensorherstellerCase study: cyber incident at a mid-sized sensor manufacturer28

Gliederung gemäß aktuellem Stand; Details können sich bis zum Erscheinen geringfügig ändern.The book is written in German. Chapter titles are shown here in English translation.


Companion-Tools

Sechs kostenlose Tools. Ohne Anmeldung.Six free tools. English mode, no sign-up.

Jedes Tool vertieft ein Kapitel des Ratgebers: browserbasiert, herstellerneutral und workshoptauglich. Kapitelnummern verweisen auf die zugehörigen Abschnitte des Buches; alle Tools sind zweisprachig (DE/EN).Each tool deepens one chapter of the guide: browser-based, vendor-neutral and ready to use in workshops. Chapter numbers reference the corresponding sections of the book; all links below open the English versions.

Von der Governance in die Werkhalle: Sicherheitskontrollen, Anlagenübersicht und praktische Umsetzung im Betrieb.From governance into the plant: security controls, asset visibility and practical implementation in operations.

Kap. 3.5ch. 3.5

Crown-Jewels-CompanionCrown Jewels Companion

Die kritischsten OT-Assets methodisch identifizieren und priorisieren — Begleiter zur Kronjuwelen-Analyse.Methodically identify and prioritise the most critical OT assets — companion to the crown-jewels analysis.

Tool öffnen →Open tool →

Kap. 8.4ch. 8.4

OT-Tabletop-GeneratorOT Tabletop Generator

Realistische Tabletop-Übungsszenarien für das OT-Vorfallmanagement erzeugen — den Ernstfall trainieren, bevor er eintritt.Generate realistic tabletop exercise scenarios for OT incident management — train for the emergency before it happens.

Tool öffnen →Open tool →

Kap. 9ch. 9

No-Touch-RegisterNo-Touch Register

Containment-Governance für OT-Vorfälle: dokumentieren, welche Systeme niemals automatisch isoliert oder abgeschaltet werden dürfen.Containment governance for OT incidents: record which systems must never be automatically isolated or shut down.

Tool öffnen →Open tool →

Kap. 22ch. 22

OT-Fernzugriffs-KriterienkompassOT Remote Access Compass

Anforderungen an sicheren Fernzugriff definieren und Lösungskandidaten strukturiert bewerten — entlang IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 und NIS2.Define requirements for secure remote access and assess candidate solutions in a structured way — along IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 and NIS2.

Tool öffnen →Open tool →

Kap. 22.2ch. 22.2

JIT-Fernwartungs-FahrplanJIT Remote Maintenance Roadmap

Just-in-Time-Fernwartung entlang des Vier-Stufen-Modells planen: Zugriff nur bei Bedarf — nachvollziehbar und zeitlich begrenzt.Plan just-in-time remote maintenance along the four-stage model: access only when needed — traceable and time-boxed.

Tool öffnen →Open tool →

Resilienzresilience

Island-Mode-72h-StresstestIsland Mode 72h Stress TestNEUNEW

Ein Testprogramm für die Frage, ob kritische Prozesse 72 Stunden autark laufen können — von Credential-Caches bis Offline-Backups.A test programme for whether critical processes can run autonomously for 72 hours — from credential caches to offline backups.

Tool öffnen →Open tool →

Alle Tools sind offen auf GitHub veröffentlicht und laufen vollständig im Browser — es verlassen keine Daten Ihren Rechner.All tools are published openly on GitHub and run entirely in the browser — no data leaves your machine.


FachbeiträgeArticles

Publiziert auf drei Kontinenten.Published across three continents.

Regelmäßige Beiträge zu Cybersecurity, OT-Governance und Compliance für Foundry-Medien — CSO Online (englisch und deutsch), Computerwoche und CIO.de, syndiziert an ITWorld Korea — sowie für die <kes>, die Fachzeitschrift für Informationssicherheit. Die Sprache jedes Beitrags ist gekennzeichnet.Regular contributions on cybersecurity, OT governance and compliance for Foundry outlets — CSO Online (English and German), Computerwoche and CIO.de, syndicated to ITWorld Korea — and for <kes>, the German information security journal. The language of each piece is tagged.

2026

[EN] The containment paradox: Why your ransomware playbook has the wrong people in charge. CSO Online, 27. Juli 2026.CSO Online, July 27, 2026.NEUNEWEST

[DE] OT-Sicherheit: Der Fernwartungszugang, den niemand mehr kennt. Computerwoche, 20. Juli 2026.Computerwoche, July 20, 2026.OT security: the forgotten remote maintenance access that may still provide a hidden path into production.

[DE] Dotcom-Blase und KI-Boom im Vergleich. CIO.de, 10. Juli 2026.CIO.de, July 10, 2026.The dotcom bubble vs. the AI boom: parallels, differences — and three tests for your AI portfolio.

[EN] Agentic AI identity: A 6-stage maturity model for non-human identities. CSO Online, 9. Juli 2026.CSO Online, July 9, 2026.

[DE] „Läuft seit 15 Jahren ohne Zwischenfall“. <kes> Informationssicherheit, 7. Juli 2026.<kes> Informationssicherheit, July 7, 2026.Running for 15 years without incident: why external service providers are the biggest risk to production networks.

[DE] Wo die souveräne Cloud Sinn macht – und wo nicht. Computerwoche, 30. Juni 2026.Computerwoche, June 30, 2026.Sovereign cloud, private cloud or hyperscaler: a workload-level decision guide.

[DE] Der blinde Fleck der europäischen Industrie. Computerwoche, 26. Juni 2026.Computerwoche, June 26, 2026.Opinion: compliant, certified — and vulnerable nonetheless. The reality in many European industrial companies.

[EN] Sovereign cloud won't fix your AI risk — identity governance will. CSO Online, 15. Juni 2026.CSO Online, June 15, 2026.

[EN] Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines. CSO Online, 22. Mai 2026.CSO Online, May 22, 2026.

[EN] The OT security time bomb: Why legacy industrial systems are the biggest cyber risk nobody wants to fix. CSO Online, 10. März 2026.CSO Online, March 10, 2026.

2025

[KO] CISO의 소프트 스킬, 이제는 없으면 안 되는 '파워 스킬'로. ITWorld Korea, 16. Dezember 2025.ITWorld Korea, December 16, 2025.Korean edition: CISO soft skills are now indispensable "power skills".Koreanische Ausgabe: CISO-Soft-Skills sind heute unverzichtbare „Power Skills“.

[EN] The 5 power skills every CISO needs to master in the AI era. CSO Online, 15. Dezember 2025.CSO Online, December 15, 2025.

[EN] What keeps CISOs awake at night — and why Zurich might hold the cure. CSO Online, 24. November 2025.CSO Online, November 24, 2025.

[EN] OT security: Why it pays to look at open source. CSO Online, 11. September 2025.CSO Online, September 11, 2025.

[KO] 컴플라이언스 위기를 막는 가장 확실한 전략, 서드파티 리스크 관리. ITWorld Korea, 4. Juli 2025.ITWorld Korea, July 4, 2025.Korean edition: The most reliable strategy against compliance crises — third-party risk management.Koreanische Ausgabe: Die sicherste Strategie gegen die Compliance-Krise — Third-Party-Risk-Management.

[EN] Third-party risk management: How to avoid compliance disaster. CSO Online, 3. Juli 2025.CSO Online, July 3, 2025.

[DE] OT-Security: Warum der Blick auf Open Source lohnt. CSO Online (deutsch), 15. April 2025.CSO Online (German), April 15, 2025.

2024

[DE] Third Party Risk Management: So vermeiden Sie Compliance-Unheil. CSO Online (deutsch), 6. August 2024.CSO Online (German), August 6, 2024.

In der PresseIn the press

OpenAI „hackt“ Hugging Face – eine Analyse — Computerwoche zitiert Sabine Frömling in der News-Analyse vom 23. Juli 2026 als Experten-Autorin und Cybersecurity-Beraterin, neben Analysten und Security-Verantwortlichen von Forrester, KuppingerCole, Acronis, Bitdefender und TrendAI. Ihre Einordnung: „Der eigentliche Sicherheitsvorfall war nicht die KI – sondern die Sandbox, die aus Versehen eine Tür zum Internet hatte. Man hat ein Raubtier freigelassen und dem Zaun die Schuld gegeben.“ — Computerwoche quotes Sabine Frömling in its July 23, 2026 news analysis as an expert author and cybersecurity consultant, alongside analysts and security leaders from Forrester, KuppingerCole, Acronis, Bitdefender and TrendAI. Her assessment: “The real security incident was not the AI, but the sandbox that accidentally had a door to the internet. They released a predator and blamed the fence.”

The Ghost in Your Warehouse — für die Q4-Ausgabe 2026 des MHI Solutions Magazine als OT-Security-Expertin zu Legacy-OT in der Intralogistik interviewt: unsichtbare Altsysteme — Industrie-PCs, Operator-Panels, einzelne alte Windows-Rechner —, die den Materialfluss moderner Läger steuern, aber auf keinem Netzwerkdiagramm auftauchen. Neben Stimmen von Gartner, Beckhoff und Designed Conveyor Systems ordnet Frömling ein, warum das Problem primär organisatorisch statt technisch ist — und warum am Anfang ein belastbares Asset-Inventory steht. (erscheint Q4 2026) — interviewed as an OT security expert on legacy OT in intralogistics for the Q4 2026 issue of MHI Solutions Magazine: the invisible legacy systems — industrial PCs, operator panels, the odd ageing Windows box — that run the material flow of modern warehouses yet appear on no network diagram. Alongside voices from Gartner, Beckhoff and Designed Conveyor Systems, Frömling explains why the problem is primarily organisational rather than technical — and why every hardening effort starts with a reliable asset inventory. (appears Q4 2026)

Doppelbelastung: Projektmitarbeiter unter Druck — Karriere-Porträt der Computerwoche (August 2012) über Frömlings MBA-Forschung zur Doppelbelastung von Mitarbeitern, die Projekte neben der Linientätigkeit stemmen. — a Computerwoche careers feature (August 2012) on Frömling's MBA research into the double burden carried by staff who work projects on top of their line duties.

In KürzeComing soon

AUSGABE 5ISSUE 5Die unterschätzte Achillesferse der OT: das Dienstleister-Vertrauen — IT-SICHERHEIT, Print-Ausgabe 5 — IT-SICHERHEIT, print issue no. 5
AUSGABE 5ISSUE 5Machen heißt nicht Dürfen – warum Compliance in der Realität scheitert — <kes>, Print-Ausgabe 5 — <kes>, print issue no. 5
IN VORBEREITUNGIN PREPARATIONVom Feuerwehrmann zum Vertrauensarchitekten – wie sich die CISO-Rolle neu erfindet — IT-SICHERHEIT, Print — IT-SICHERHEIT, print edition
IN VORBEREITUNGIN PREPARATIONDas ISMS schützt Daten – aber wer schützt Menschen vor KI-Entscheidungen? — <kes> online — <kes> online
Sabine Frömling

Über die AutorinAbout the author

Sabine Frömling

Unabhängige Beraterin für IT/OT-Security und Compliance in Berlin. IT-Beratung seit 2008, seit 2020 mit dediziertem Fokus auf OT- und Industrie-Cybersecurity: mehr als 60 Projekte in 11 Ländern und über 25 Cybersecurity-Programme in Energie, Fertigung, Pharma und Finanzwesen.Independent IT/OT security and compliance consultant based in Berlin. Consulting since 2008, with a dedicated OT and industrial cybersecurity focus since 2020: more than 60 projects in 11 countries and over 25 cybersecurity programmes across energy, manufacturing, pharmaceuticals and financial services.

Sie hält einen MBA; ihre Beiträge erscheinen in Foundry-Titeln wie CSO Online, Computerwoche, CIO.de und ITWorld Korea sowie in der <kes>, der Fachzeitschrift für Informationssicherheit.She holds an MBA, and her writing appears across Foundry titles including CSO Online, Computerwoche, CIO.de and ITWorld Korea, as well as in <kes>, the German information security journal.

SCHWERPUNKTEFOCUS — ISO/IEC 27001 · IEC 62443 · NIS2 / KRITIS · OT-SECURITY-GOVERNANCE · ISMS-AUDITS