Skip to main content

KeenGen

For operators of critical infrastructure

Your redundancy is exemplary.
For the plant.

Geo-redundant control centre, trunked radio with direct mode, a satellite link, segregated networks for plant control. That grew over years, it is well thought through, and it works.

This page is not about that. It is about the layer above it and about a question that is usually still open up there.

 

Operational layer multiply secured

Administrative layer: one vendor

NIS-2: secured communication: required

1 - WHAT YOU HAVE

This is not a page,

that explains redundancy to you.

Anyone who lays out a control centre geo-redundantly, runs a radio link with direct mode as a fallback layer and separates plant control into its own zones needs nobody to explain what resilience means.

That architecture was built under regulatory obligations, it gets audited, and it has proven itself. When a utility was attacked over the past few years, supply almost always kept running Precisely because of it.

The point of this page is a different one: that redundancy was built for the plant. Not for the processes that keep the business running.

2 - THE ASYMMETRY

The plants runs.

The organisation behind them does not.

This is not a thought experiment. It is the recurring pattern across the documented incidents of recent years.

 

A municipal utility is attacked. Grid control is segregated, supply keeps running throughout — no interruption, no notice to customers required. That is exactly how it was planned, and exactly how it worked.

What took several weeks to return to normal was billing and administration. Which is to say: the maintenance work orders, the evidence owed to the regulator, the contract positions with suppliers, the permit procedures with live deadlines.

The plant knows no deadline. The regulator does.

 

Plant and administration are not the only two categories.

Splitting the world into "minute-critical technology" and "day-critical administration" is convenient — and wrong in the middle. Between the two lies a third layer that appears in no plant protection concept and still hurts within hours.

Minute-critical

The plant

Control, telecontrol, fault reporting over radio. Decoupled, multiply secured, survives the failure of the office world. Everything here is done.

 
 

Hour-critical

The operating flow

Dispatch and deployment planning, shift and standby handovers, clearances and switching orders, admission and assignment, material calls for work in progress. Neither plant nor administration — and usually on the same platform as email.

 

Day-critical

The administration

Maintenance planning, procurement, permits, documentation, regulatory reporting. None of it urgent by the minute — and all of it urgent by the day.

 

The middle layer is the awkward one, because it sits cleanly in nobody's remit. To the OT side it is paperwork, to the IT side it is a business application, and in the emergency plan it appears under "IT recovery" with no target time of its own. If you want to test whether this page describes your organisation, that is the place: open your emergency manual and check whether the hour-critical layer has a recovery time of its own.

And then comes the backlog. What accumulated over weeks without systems has to be entered afterwards — by the same people who are simultaneously working through what was left undone.

3 - WHY THIS COULD NOT BE SOLVED BEFORE

For voice there is a second path.

For context there was none.

The gap is not an oversight. It exists because for this one problem there simply was no suitable instrument.

 

Radio carries voice, not documents

A trunked radio link is built for short, immediate voice communication and is unbeatable at it. It does not transport a contract position or a revision drawing.

Satellite solves the line, not the content

When connectivity is missing, an independent link helps. When the platform at the other end is unreachable, it does not — the line then leads nowhere.

 

Backup restores data, not processes

A restore brings files back, after hours or days, into a system that is not currently running. Which version applied and who committed to what sits in the structure — not in the recovered bytes.

 

A second tenant shares the same fate

Two environments at the same vendor share that vendor's outages, its identity service and its legal jurisdiction. By the criteria you apply to your OT, that would not count as redundancy.

You have built a solution for every requirement that could be solved. This one could not be, until now.

4 - WHAT IS POSSIBLE NOW

The same thinking as in your OT.

Just one layer up.

What you have long done for plant control — keeping a second, independent path available that is unaffected by the failure of the first — can be applied to the administrative layer. Including the content, not just the connection.

 

A second environment runs alongside. Chats, channels, files and calendars are taken over continuously, as they arise. No standby that has to be started first — the same principle by which your radio link is not built at the moment the fire breaks out. That is handled by KeenAct.

01 — THE FOUNDATION

Your identity stays yours.

Die Anmeldung, die nicht am ausgefallenen Verzeichnis hängt, über staatlichen Identitätsdienst, eigenes Verzeichnis oder hinterlegte Zugangsdaten.

02 — THE COMMUNICATION

One client. Every channel.

Der Client, in dem Chat, Dateien, Kalender und Konferenzen zusammenlaufen. Im Ereignisfall dieselbe Oberfläche wie im Alltag.

03 — THE CONTINUITY

Stay operational, whatever fails.

Die Spiegelung, die Ihre Vorgänge in der zweiten Umgebung aktuell hält, und nach dem Vorfall zurückspielt.

5 - THE UNCOMFORTABLE QUESTION

Mirroring creates a second target.

That has to be discussed.

A live copy of your processes is by definition worth attacking. Anyone who talks only about availability at this point has not answered the question, only postponed it. Four points decide whether the second environment improves your position or worsens it.

The scope

What gets mirrored is what you define

Not the entire tenant. You determine which teams, channels and file stores are taken over — typically the areas that carry the business, not every project folder from the past ten years. The narrower the scope, the smaller the copy and the less exists in two places in the worst case.

The separation

Its own administration, its own way in

The second environment has its own administrators and a sign-in that does not depend on the primary platform's directory. That is exactly what makes it usable during an outage — and it also means an account carried over from the first world holds no rights there automatically. Administer both with the same credentials and you have given the redundancy away again.

The worst case

An encryption wave does not travel with it

The takeover is not a synchronisation in the sense of "both sides always identical". Deletions and overwrites are recorded as events in the second environment; earlier states remain and can be recovered. That is the difference between mirroring and a folder sync — and the reason a folder sync would be no answer here.

The visibility

Not a place with less telemetry

Access, sign-ins and administrative changes are logged and can be forwarded to your existing SIEM. A second environment your monitoring cannot see into would not be a gain in resilience but a blind spot.

That leaves the point that cannot be argued away: a second environment is a second target. The question is not whether — but whose it is. In the operating models that come into question for operators under strict obligations, it stands in your data centre or fully air-gapped with no outward connection.

You are not trading one risk for a new one, but an externally managed risk for one you manage yourself.

A drill that does not stop the business can be repeated until the result is boring. That is exactly the goal.

7 - THE COMPLIANCE SIDE

NIS-2 names secured communication

explicitly.

For the plant layer your evidence is in place. For the communication layer, most organisations point to alerting and radio — which only partly meets the requirement.

 

This overview maps functions to requirements and does not replace legal review in the individual case. What governs is the wording of the legal acts and the respective national implementation.

Let's talk!

Send us a message - we're looking forward to hearing from you.

Not a fan of forms? Just send us an email: office@keengen.eu

8 - FREQUENTLY ASKED QUESTIONS

We have trunked radio, satellite and a geo-redundant control centre. What is missing?

For voice and alerting, nothing. Those means are built for immediate, short communication and excellent at it. What they do not carry are processes: the current maintenance order, the revision drawing, the contract position, the record of when what went to the regulator. That is not a criticism of your architecture — it was never its job.

No. The solution applies exclusively to the administrative layer. There is no coupling to plant control, no new crossing between zones and no additional path into your segregated networks. The separation you have built stays untouched.

It does — that is not a matter of interpretation, and section 05 covers it in detail. What matters is the comparison: today your entire administrative layer sits in one place that is both the single point of failure and the single point of attack. A second location with a narrow scope, its own administration and its own logging does not double the risk, it divides it — the same reasoning that underlies your OT zoning.

That is the right question to ask someone arguing about vendor dependency. The answer lies in the operating model: in the models that come into question for operators under strict obligations, the second environment runs in your infrastructure and the content sits in your storage. The identity layer provisions into standard directories, the client speaks open protocols. That keeps the vendor out of the availability path — a failure on our side ends further development, not your operation. Whatever needs securing beyond that belongs in the tender documents and can be settled there contractually.

Conversations are end-to-end encrypted. Administration manages access and policy; it cannot read content. That applies in every operating model, including the air-gapped one — more on this under KeenCollab.

You decide per user across three tiers. In practice a small group needs the full tier — crisis team, standby duty, everyone with confidential conversations. The decisive one is the middle tier: the many who are not being directed during an incident but have to carry on with the work in front of them.

Nothing. No system is switched off and no plant is touched. The sign-in is rerouted to the alternative source and switched back afterwards. That is why the drill can be repeated during normal operation instead of once a year in a maintenance window.

The service can be described as a tiered model and is therefore tenderable. Because there is no data move and no replacement of an incumbent system, the part that usually complicates such procedures falls away: dependency on the legacy vendor during the changeover.

That depends on your data volume and cannot honestly be answered before a stocktake. More important for planning anyway: none of the phases has a cut-over date. Operations continue throughout, including while the mirror is still building up.

Usually at the question such strategies leave open longest: communication. Line-of-business applications can be moved step by step because they are clearly bounded. Communication is everywhere at once — identity, chat, mail, files and telephony all hang together. Which is exactly why it sits at the end of so many roadmaps. Running in parallel reverses that order.