This page summarizes the regulatory framework and affected sectors regarding drone protection for critical infrastructure. It defines what constitutes critical infrastructure, which legal requirements apply, and what is important for each sector. Drone-related protection – detection , defense , and situational awareness – can be found on our KRITIS overview page .
What is considered critical infrastructure
Critical infrastructure (KRITIS) refers to facilities and installations whose failure or disruption would have significant consequences for public services, public safety, or the community—such as in the energy, water, transportation, healthcare, or logistics sectors. For these operators, unauthorized drone flights are not only a nuisance but also pose a risk to security and operational continuity.
Regulatory Framework
The protection of critical infrastructure is increasingly mandated by law.
KRITIS Framework Act
The KRITIS Framework Act consolidates the requirements for the physical protection of critical infrastructure and requires operators to conduct risk assessments and implement appropriate protective measures—including the airspace above the facility.
NIS2
The NIS2 Directive addresses the cybersecurity and information security of critical and important facilities. Drone protection and IT security are intertwined in cases where detection and control center systems themselves are part of the infrastructure that requires protection.
Industry-Specific Requirements
In addition, each sector has its own set of regulations and supervisory structures, which must be incorporated into a protection plan.
Sectors in Detail
Each sector has its own assets to protect, terrain features, and escalation pathways.
Energy and Grid Operations
Substations, power plants, and grid nodes with extensive perimeters and high importance to the power supply.
Water and Wastewater
Extraction, processing, and distribution—often involving dispersed locations with sensitive plant areas.
Transportation and Traffic
Airports, airfields, and transportation hubs where drones pose a direct threat to operations.
Health
Hospitals and healthcare facilities with high security requirements for operations and privacy.
Ports and Logistics
Extensive areas with heavy traffic of goods and people and complex responsibilities.
A Four-Step Process
We develop security concepts in a structured manner: first, risk and site analysis; second, detection and situational awareness; third, processes, roles, and alert chains; and fourth, testing, documentation, and auditing. This results in a security system that is predictable, legally compliant, and verifiable.
Contact us at +49 421 34 14 94 or brm@brm.de .