Modern district-heating networks are turning into intelligent energy systems, with OT infrastructure that grows fast. narrowin's SD-WAN design connects producers, storage and transfer stations over a highly available, segmented and end-to-end encrypted communication architecture: for secure operation, high resilience, and scaling from 50 to several hundred sites.
Why district heating is scaling now
District heating is a central building block of the heat transition. It allows renewable sources (geothermal, solar thermal) to be integrated, lets waste heat from industry and data centres be reused, and makes large-scale heat pumps efficient to run. Combined with heat storage and intelligent control, it smooths load peaks, absorbs surplus electricity through power-to-heat, and cuts emissions sharply.
Politically the driver is decarbonisation and supply security; ecologically it is waste-heat use and efficiency. Either way, modern heat networks are becoming low-temperature, flexible systems: heavily networked, data-driven, and built for dynamic operation.
Networking as the efficiency lever
Digitalisation is what separates a "heat-delivering pipe" from an "intelligent energy system." Sensors, actuators and telemetry raise transparency and controllability across the whole chain: from generation, through storage, to decentralised transfer stations. Four elements carry that:
Real-time transparency
Temperature, pressure, flow, return temperatures, heat-pump COP and storage states, visible as they happen.
Forecasting & optimisation
Digital twins, weather and load forecasts, and predictive control.
Sector coupling
Power-to-heat, grid-supportive operation, and participation in flexibility markets.
Security by design
Protecting the OT infrastructure as critical energy supply: industry security standards, hardening, monitoring, incident response.
Regulatory requirements
A district-heating network does not sit outside regulation. The exact obligations differ by country, and a design has to satisfy both the German and the Swiss frameworks.
District-heating operators count as critical infrastructure (KRITIS) when their generation plants or networks provide at least 500 MW of installed heat output, or supply more than 300,000 people. Above that threshold, the BSI Act and the BSI-Kritisverordnung apply: implementation of the recognised industry-specific security standard B3S Fernwärme, security proofs to the BSI every two years, a designated IT security officer, and mandatory reporting of significant disruptions. Below the thresholds there is no legal KRITIS obligation, but the B3S can still be used as a best-practice security baseline.
The B3S Fernwärme sets out specific principles for the network architecture:
Least privilege: users and components hold only the rights they need for their function.
Defence in depth: threats are mitigated by complementary controls at several system levels, not one measure.
Redundancy: a suitable redundant design compensates for the failure of individual components.
Protection, detection, response: controls are implemented to raise protection, improve detection, and strengthen the response to security events.
Zone-model trust: a zone does not trust an adjacent zone without general safeguards; access across a boundary requires authentication.
CHSwitzerland – IKT-MinimalstandardRecommended best practice · NIST-based · 5 areas
In Switzerland, the IKT-Minimalstandard for district heating and cooling, issued by the National Cyber Security Centre (NCSC), applies as a recommendation. Its aim is to raise the cyber-resilience of thermal networks. It follows the NIST framework (Identify, Protect, Detect, Respond, Recover) and comprises over 100 concrete measures. It is not mandatory, but is recommended as best practice and is tailored specifically to thermal networks. It covers five areas:
Governance & risk analysis: a management framework with risk assessment and protection strategies.
Segmentation & defence in depth: clear separation of the ICS/SCADA, enterprise and perimeter networks.
Access control & awareness: authorised access, training and staff awareness.
Monitoring & incident response: continuous monitoring, detection and response.
Recovery & improvement: recovery plans and continuous improvement.
For a district-heating network to be run economically and reliably, the network infrastructure must be secure, performant, scalable and cost-aware. A good design avoids unnecessary operational overhead and supports efficient operating processes:
Automation: zero-touch provisioning, central policy management and infrastructure-as-code remove manual steps.
A unified architecture: standardised site profiles and templates minimise planning and integration effort.
Resource efficiency: choosing the right technology, such as targeted 4G/5G as backup, avoids over-dimensioning.
Easy extensibility: the design absorbs new sites and use cases (e-mobility, solar loggers) without complex rebuilds.
Monitoring & transparency: central oversight and clear KPIs keep operating and maintenance costs predictable.
Our SD-WAN design
narrowin's SD-WAN design connects outstations, producers, storage and control centres over one highly available, segmented and end-to-end encrypted communication architecture. The goal: secure operation, high resilience and easy scaling, from 50 to several hundred sites, on one consistent setup.
The network plan, schematic: one setup carries fibre and 4G/5G sites alike, from HQ out to each heating station
Architecture principles
Connectivity
Flexible connections
One design uses fibre where it exists and adds 4G/5G as a primary or secondary carrier: new-build, existing, or temporary sites.
Availability
Redundancy & failover
A dual-uplink design with health checks and automated failover, for fast convergence.
Encryption
Modern encryption
WireGuard between sites: end-to-end encryption, modern cryptography, minimal overhead.
Segmentation
Layer-3 separation
Site and function segments are L3-separated; east-west traffic runs through central security policies, limiting lateral movement and blast radius.
Security
Centralised security
Central policies, central logging, and a central path to connect an IDS or SOC: syslog, NetFlow, anomaly detection.
Scale
Scalability & automation
Central management, a template per site type, and zero-touch provisioning for fast rollouts.
Automation with the site generator
Scaling a district-heating network needs efficient processes. The site generator automates configuration creation completely: the customer enters only a site name; everything else is generated automatically. The system produces the full router configuration, IP addressing, WireGuard keys, firewall rules and VLAN assignments.
A new outstation, transfer station or generation site can be configuration-ready within minutes, without manual effort, without a source of errors, and with guaranteed consistency across every site.
The site generator: each WAN site generated from a template, with its tunnel, addressing and deployment state tracked centrally
Why the approach is cost-effective
Affordable, proven hardware: no expensive special-purpose devices needed at the outstations.
Central security services: encryption, policies and monitoring run centrally, instead of a scattered landscape of licences and appliances.
High automation: zero-touch provisioning and templates cut rollout and operating effort sharply.
No unnecessary add-on licences: the basics (WireGuard/VPN, segmentation) without proprietary upgrades.
"The consistent segmentation and central management make the network secure and manageable. Thanks to zero-touch provisioning and the template-based architecture, it scales with the expansion of the heat networks."
Paul Kempf · Managing Director, Zweckverband Breitbandversorgung Landkreis Lörrach
Frequently asked
How does out-of-band (OOB) remote site management work?
When a technician goes on site, they can attach a pre-configured device that immediately establishes a remote tunnel for troubleshooting and debugging, independent of the site's normal connectivity.
Which encryption is used?
WireGuard, with modern cryptography, for fast and secure tunnels between sites.
How is segmentation done?
Consistent Layer-3 separation by site and function role, micro-segmentation, central east-west policies, and DMZ zones for telemetry and remote access.
How does the design scale?
Through a template per site type, a config generator and central management: from 10 to more than 1,000 sites on the same design.
What does the B3S Fernwärme actually require?
The recognised industry-specific security standard describes organisational and technical minimum measures: network zoning, access controls, logging, vulnerability management, contingency plans, and regular security proofs.