Wien Energie & IKARUS / HarfangLab
An IKARUS success story.
An IKARUS success story.

As one of Austria’s largest regional energy suppliers, Wien Energie reliably provides energy to around two million people as well as approximately 230,000 commercial and industrial facilities. Security of supply and climate protection are top priorities. With revenue of €3,347.1 million and 2,424 employees (as of 2024), the company ranks among Austria’s 30 highest-revenue businesses.
Energy production is based on a diversified mix of renewable and efficient technologies, including solar, wind and hydropower, biomass, waste-to-energy and combined heat and power generation. However, the increasing digitalization of energy generation and distribution is also raising cybersecurity requirements – particularly in the field of critical infrastructure.
The trust of customers in the security and availability of energy supplies is essential to Wien Energie. Accordingly, its security strategy encompasses both the protection of personal data and the integrity and availability of operational systems and process data.
The primary focus is on the protection objectives of availability, integrity and confidentiality (the CIA triad), with availability taking top priority in the OT environment. In addition, the requirements arising from NIS2 are becoming increasingly important. Wien Energie therefore follows a risk-based approach to continuously enhance cyber resilience, the traceability of security measures, and the ability to detect threats at an early stage. This includes network segmentation, system hardening and continuous monitoring of security-relevant events.
A key element of the security architecture is the consistent separation of IT and OT systems. While conventional IT systems are centrally managed, the OT environment is logically and physically segmented.
The solution from IKARUS, combined with HarfangLab, is specifically deployed in OT network segments with particularly high protection requirements, where it complements existing security measures.
The industrial control systems (ICS) within our OT environment are considered particularly critical and therefore require special protection.
“Ensuring and maintaining continuous plant availability is our top priority,” explains Philipp Lellek, Team Lead Cybersecurity OT.
The partnership with IKARUS Security Software and HarfangLab emerged as part of a structured selection process. Wien Energie evaluated several solutions and providers to identify the one best suited to the specific requirements of OT environments.
Independent and officially recognized assessments were an important factor for Wien Energie. Particularly in the context of critical infrastructure, established certifications and evaluations make it easier to assess and classify a solution while also creating additional confidence in its capabilities. The ANSSI CSPN and BSI certifications were viewed particularly positively. Participation in the MITRE ATT&CK Evaluations also provided valuable transparency regarding the solution’s detection and analysis capabilities.
Digital sovereignty was another important consideration. The solution’s fully European approach to development, support and operations, combined with the option of purely local deployment without operational dependency on cloud services, aligned well with Wien Energie’s requirements.
The implemented solution offers several technical differentiators specifically tailored to the requirements of OT environments:
A key criterion is the solution’s full offline capability. In isolated network segments without permanent Internet connectivity, threat detection and analysis must be able to operate autonomously.
The solution also provides a high level of transparency in alert generation. Security events are not merely reported; they are contextualized and presented in a comprehensible manner, including the underlying detection logic.
Another advantage is its flexibility in the context of incident response. If required, the solution can be rapidly deployed to additional systems and is actively integrated into security exercises. This helps ensure that a rapid and coordinated response is possible in the event of a real incident.
From the outset, the collaboration between Wien Energie and its partners was characterized by a high level of professionalism. Requirements were clearly defined and efficiently implemented during the initial coordination phase.
Particularly noteworthy were the structured onboarding process, technical support during ongoing operations, and the partners’ rapid response to inquiries. “The support, onboarding and ongoing assistance have been fantastic,” says P. Lellek. The partner’s local presence also enabled close collaboration, including on-site visits to facilities such as the Simmering power plant and direct coordination with operational personnel.
The next stage of development will focus on further automation of response mechanisms. The goal is to proactively initiate measures based on defined thresholds or anomalies – for example, through the automated isolation of affected jump systems.
At the same time, the continuous optimization and fine-tuning of detection logic will be advanced in order to further improve the balance between sensitivity and precision.
In this way, Wien Energie is continuously developing its existing OT security architecture and strengthening its resilience against future technological and regulatory challenges.
Scroll to top