SPRINGER VIEWEG — GERMAN EDITION — SEPTEMBER 2026

ISMS für die Industrie

Der Praxisratgeber

The German-language practitioner's guide to building an information security management system that survives contact with the shop floor — from ISO 27001 and NIS2 to hands-on OT security. Every core chapter pairs the standard with a document blueprint and an OT practice transfer.

Fig. 1 — cover draft; final Springer artwork to follow.

ISO/IEC 27001:2022 IEC 62443 NIS2 / KRITIS BSI IT-Grundschutz NIST CSF 2.0

The book

Method, not paperwork.

Industrial companies don't fail at information security for lack of standards — they fail in the gap between the standard and the plant. This guide closes that gap with a consistent three-pillar pattern in every core chapter:

I.

Standard

What ISO/IEC 27001, IEC 62443 and NIS2 actually require — read through an industrial lens, not a data-centre one.

II.

Document blueprint

A concrete structure for the deliverable that proves it: scope, policies, SoA, risk register and more — ready to adapt.

III.

OT practice transfer

Where IT logic breaks on the shop floor — and what works instead, from patch windows to safety interlocks.

Written for CISOs and information security officers, ISMS and compliance managers, OT and automation engineers, auditors and consultants.

Table of contents

Part I — Method and foundations

Why this book? A wake-up call to industry1
Framework conditions and governance2
Risk management: the brain of the ISMS3
Operational implementation: the controls4
OT security governance and IEC 624435
Safety–security co-engineering6
The human factor7
Crisis communication and incident management8
Incident response governance: who may shut down what?9
Implementation roadmap: from ISMS plan to ISMS reality10
KRITIS, NIS2 and sector specifics11

Part II — Practice toolbox

ISMS document handbook12
German IT-Grundschutz with OT focus13
Cyber security check OT14
Combined OT security checklist15
OT architecture and communication16
The five-stage OT audit model17
BSI tools for vulnerability management18
OT SOC: operations, use cases and integration19
OT penetration testing and purple teaming20
OT forensics: recovery and evidence preservation21
SCADA access management22
AI workloads in OT environments23
Backup and disaster recovery24
Supply chain security25
GDPR and works council in OT26
Maturity measurement27
Case study: cyber incident at a sensor manufacturer28

The book is written in German. Chapter titles are shown here in English translation.


Companion tools

Six free tools. English mode, no sign-up.

Each tool deepens one chapter of the guide: browser-based, vendor-neutral and ready to use in workshops. Chapter numbers reference the corresponding sections of the book; all links below open the English versions.

ch. 3.5

Crown Jewels Companion

Methodically identify and prioritise the most critical OT assets — companion to the crown-jewels analysis.

Open tool →

ch. 8.4

OT Tabletop Generator

Generate realistic tabletop exercise scenarios for OT incident management — train for the emergency before it happens.

Open tool →

ch. 9

No-Touch Register

Containment governance for OT incidents: record which systems must never be automatically isolated or shut down.

Open tool →

ch. 22

OT Remote Access Compass

Define requirements for secure remote access and assess candidate solutions in a structured way — along IEC 62443-3-3, ISO/IEC 27001, NIST CSF 2.0 and NIS2.

Open tool →

ch. 22.2

JIT Remote Maintenance Roadmap

Plan just-in-time remote maintenance along the four-stage model: access only when needed — traceable and time-boxed.

Open tool →

resilience

Island Mode 72h Stress TestNEW

A test programme for whether critical processes can run autonomously for 72 hours — from credential caches to offline backups.

Open tool →

All tools are published openly on GitHub and run entirely in the browser — no data leaves your machine.


Articles

Published across three continents.

Regular contributions on cybersecurity, OT governance and compliance for Foundry outlets — CSO Online in English and German, syndicated to ITWorld Korea. The language of each piece is tagged.

2026

[EN] Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines. CSO Online, May 22, 2026.

[EN] The OT security time bomb: Why legacy industrial systems are the biggest cyber risk nobody wants to fix. CSO Online, March 10, 2026.

2025

[KO] CISO의 소프트 스킬, 이제는 없으면 안 되는 '파워 스킬'로. ITWorld Korea, December 16, 2025.Korean edition: CISO soft skills are now indispensable "power skills".

[EN] The 5 power skills every CISO needs to master in the AI era. CSO Online, December 15, 2025.

[EN] What keeps CISOs awake at night — and why Zurich might hold the cure. CSO Online, November 24, 2025.

[EN] OT security: Why it pays to look at open source. CSO Online, September 11, 2025.

[KO] 컴플라이언스 위기를 막는 가장 확실한 전략, 서드파티 리스크 관리. ITWorld Korea, July 4, 2025.Korean edition: The most reliable strategy against compliance crises — third-party risk management.

[EN] Third-party risk management: How to avoid compliance disaster. CSO Online, July 3, 2025.

[DE] IAM 2025: Diese 10 Trends entscheiden über Ihre Sicherheitsstrategie. CSO Online (German), May 13, 2025.

[DE] OT-Security: Warum der Blick auf Open Source lohnt. CSO Online (German), April 15, 2025.

2024

[DE] Was ist Cyber Threat Intelligence? CSO Online (German), September 5, 2024.

[DE] IoT-Devices: Security-Herausforderungen und Lösungen. CSO Online (German), August 9, 2024.

[DE] Third Party Risk Management: So vermeiden Sie Compliance-Unheil. CSO Online (German), August 6, 2024.

[DE] ISMS nach ISO 27001: Anforderungen und Umsetzung. CSO Online (German), July 29, 2024.

[DE] OT-Security: So schützen Sie Ihre Industrieanlagen. CSO Online (German), January 12, 2024.

In the press

Doppelbelastung: Projektmitarbeiter unter Druck — a Computerwoche careers feature (August 2012) on Frömling's MBA research into the double burden carried by staff who work projects on top of their line duties.

Upcoming on CSO Online: sovereign cloud strategy, non-human identities, and the containment paradox.

About the author

Sabine Frömling

Independent IT/OT security and compliance consultant based in Berlin. Consulting since 2008, with a dedicated OT and industrial cybersecurity focus since 2020: more than 50 projects in 11 countries and over 25 cybersecurity programmes across energy, manufacturing, pharmaceuticals and financial services.

She holds an MBA, and her writing appears across Foundry titles including CSO Online, Computerwoche, CIO.de and ITWorld Korea.

FOCUS — ISO/IEC 27001 · IEC 62443 · NIS2 / KRITIS · OT SECURITY GOVERNANCE · ISMS AUDITS

LinkedIn GitHub ORCID froemling.consulting