All work
Deep dive · Compliance

Implementing the IKT-Minimalstandard

Swiss critical infrastructureNCSC / BACSNIST CSF

The IKT-Minimalstandard (Switzerland's ICT minimum standard for critical infrastructure) defines over 100 concrete measures for raising cyber-resilience. For operators of energy, water, gas and district-heating networks, the hard part is not agreeing it matters. It is implementing it: existing networks have to be documented, segmentation has to be proven, security measures have to be evidenced, often with limited resources and under audit time pressure.

"The Lightweight Network Explorer is, for us, an important foundation for implementing the IKT-Minimalstandard for critical infrastructure."
Markus Weber – Head of IT, Swissgas AG

What is the IKT-Minimalstandard?

The IKT-Minimalstandard is a recommendation from the BACS (Switzerland's Federal Office for Cyber Security, formerly the NCSC) for improving cyber-resilience. It is built on the NIST Cybersecurity Framework, and covers its five core functions: Identify, Protect, Detect, Respond and Recover. There are also sector-specific versions, tailored to electricity, district heating, water and gas.

Regulatory bindingness

For the electricity sector, the IKT-Minimalstandard has been mandatory since 1 July 2024. For gas suppliers, it has been binding since 1 July 2025. Further sectors may follow.

How our tools map to the NIST framework

The five NIST functions are not abstract for a utility: each one corresponds to work that has to be done and evidenced. This is where narrowin's tools come in:

ID

Identify

Develop an organisation-wide understanding for managing cybersecurity risk.

Network Explorer – asset discovery, inventory, dependency mapping
PR

Protect

Implement the safeguards that keep critical services running.

OT Connect – segmentation, encryption, zero-touch provisioning
DE

Detect

Identify cybersecurity events as they happen.

Lightweight IDS – anomaly detection, config-drift alerts
RS

Respond

React to a detected cybersecurity incident.

Network Explorer – fast search, impact analysis, topology context
RC

Recover

Maintain resilience plans and restore what an incident affected.

Config backup & restore – documented baselines
The Network Explorer – automatic discovery and documentation of an OT network
Network Explorer: automatic discovery and documentation, the evidence base the standard asks for

The challenge: compliance without a full-time team

Most Swiss utilities (and especially smaller and mid-sized power, water and district-heating operators) have no dedicated compliance team. Implementing the IKT-Minimalstandard competes directly with the day-to-day job of keeping the lights on. Four problems recur:

Challenge

Documentation gaps

Network plans are outdated or incomplete. Nobody knows exactly which device is connected where.

Challenge

Time pressure before audits

Weeks of manual work to pull network documentation together for a review.

Challenge

Missing visibility

OT networks have grown over the years. Segmentation exists on paper, but not in reality.

Challenge

Lack of resources

No budget for expensive enterprise tools, and no time for months-long implementation projects.

The approach: lightweight tools, fast deployment

narrowin's tools were built specifically for utilities: fast deployment in hours rather than weeks, no sensors or SPAN ports, and immediate results. Four of them carry most of the IKT-Minimalstandard work:

Tool

Network Explorer

Automatic network discovery and documentation: asset inventory, topology visualisation, config backup.

Tool

OT Connect

Secure connectivity for outstations: substations, smart meters, district heating. Zero-touch provisioning, WireGuard encryption, central policies.

Tool

Lightweight IDS

Anomaly detection for OT networks, spotting unusual communication without heavy sensor infrastructure.

Tool

Network Assessment

A professional stocktake as the starting point: documentation, gap analysis and a concrete plan of measures.

Recommended entry point

Not sure where you stand? A Network Assessment gives you a complete picture of your infrastructure in days: documentation, a gap analysis and concrete recommendations against the IKT-Minimalstandard.

The Network Assessment →

Frequently asked

How long does implementation take?
With these tools, the documentation requirements of the IKT-Minimalstandard can be met in days rather than months. The Network Explorer is ready to use in about two hours; a full assessment of an infrastructure typically takes one to two weeks. Implementing all 100-plus measures is a longer-term project, but you have a solid baseline almost immediately.
Does it work with our existing infrastructure?
Yes. The tools work across vendors: Cisco, Aruba, HPE, Moxa, Hirschmann, Siemens and many others. No agents, no sensors and no SPAN ports are needed. The Network Explorer uses standard protocols (SNMP, SSH) and integrates into existing environments without changes to the infrastructure.
What is the best way to start?
We recommend a Network Assessment as the entry point. It gives you a complete picture of your current situation, identifies the gaps against the IKT-Minimalstandard, and produces concrete recommendations. Alternatively, you can start directly with a demo of the Network Explorer.
Where do I find the official documentation?
The official documentation for the IKT-Minimalstandard is published by the Federal Office for Cyber Security (BACS) at ncsc.admin.ch.
← All work