All work
Deep dive · OT Connect

SD-WAN design for district-heating networks

B3S FernwärmeIKT-MinimalstandardWireGuardZero-touch

Modern district-heating networks are turning into intelligent energy systems, with OT infrastructure that grows fast. narrowin's SD-WAN design connects producers, storage and transfer stations over a highly available, segmented and end-to-end encrypted communication architecture: for secure operation, high resilience, and scaling from 50 to several hundred sites.

Why district heating is scaling now

District heating is a central building block of the heat transition. It allows renewable sources (geothermal, solar thermal) to be integrated, lets waste heat from industry and data centres be reused, and makes large-scale heat pumps efficient to run. Combined with heat storage and intelligent control, it smooths load peaks, absorbs surplus electricity through power-to-heat, and cuts emissions sharply.

Politically the driver is decarbonisation and supply security; ecologically it is waste-heat use and efficiency. Either way, modern heat networks are becoming low-temperature, flexible systems: heavily networked, data-driven, and built for dynamic operation.

Networking as the efficiency lever

Digitalisation is what separates a "heat-delivering pipe" from an "intelligent energy system." Sensors, actuators and telemetry raise transparency and controllability across the whole chain: from generation, through storage, to decentralised transfer stations. Four elements carry that:

Real-time transparency

Temperature, pressure, flow, return temperatures, heat-pump COP and storage states, visible as they happen.

Forecasting & optimisation

Digital twins, weather and load forecasts, and predictive control.

Sector coupling

Power-to-heat, grid-supportive operation, and participation in flexibility markets.

Security by design

Protecting the OT infrastructure as critical energy supply: industry security standards, hardening, monitoring, incident response.

Regulatory requirements

A district-heating network does not sit outside regulation. The exact obligations differ by country, and a design has to satisfy both the German and the Swiss frameworks.

DE Germany – KRITIS & B3S Fernwärme KRITIS thresholds · B3S Fernwärme · 5 principles

District-heating operators count as critical infrastructure (KRITIS) when their generation plants or networks provide at least 500 MW of installed heat output, or supply more than 300,000 people. Above that threshold, the BSI Act and the BSI-Kritisverordnung apply: implementation of the recognised industry-specific security standard B3S Fernwärme, security proofs to the BSI every two years, a designated IT security officer, and mandatory reporting of significant disruptions. Below the thresholds there is no legal KRITIS obligation, but the B3S can still be used as a best-practice security baseline.

The B3S Fernwärme sets out specific principles for the network architecture:

  • Least privilege: users and components hold only the rights they need for their function.
  • Defence in depth: threats are mitigated by complementary controls at several system levels, not one measure.
  • Redundancy: a suitable redundant design compensates for the failure of individual components.
  • Protection, detection, response: controls are implemented to raise protection, improve detection, and strengthen the response to security events.
  • Zone-model trust: a zone does not trust an adjacent zone without general safeguards; access across a boundary requires authentication.
B3S Fernwärme (PDF, German)
CH Switzerland – IKT-Minimalstandard Recommended best practice · NIST-based · 5 areas

In Switzerland, the IKT-Minimalstandard for district heating and cooling, issued by the National Cyber Security Centre (NCSC), applies as a recommendation. Its aim is to raise the cyber-resilience of thermal networks. It follows the NIST framework (Identify, Protect, Detect, Respond, Recover) and comprises over 100 concrete measures. It is not mandatory, but is recommended as best practice and is tailored specifically to thermal networks. It covers five areas:

  • Governance & risk analysis: a management framework with risk assessment and protection strategies.
  • Segmentation & defence in depth: clear separation of the ICS/SCADA, enterprise and perimeter networks.
  • Access control & awareness: authorised access, training and staff awareness.
  • Monitoring & incident response: continuous monitoring, detection and response.
  • Recovery & improvement: recovery plans and continuous improvement.
IKT-Minimalstandard Fernwärme (PDF, German)

Operational requirements

For a district-heating network to be run economically and reliably, the network infrastructure must be secure, performant, scalable and cost-aware. A good design avoids unnecessary operational overhead and supports efficient operating processes:

Our SD-WAN design

narrowin's SD-WAN design connects outstations, producers, storage and control centres over one highly available, segmented and end-to-end encrypted communication architecture. The goal: secure operation, high resilience and easy scaling, from 50 to several hundred sites, on one consistent setup.

Schematic network plan – headquarters connected to district-heating outstations over a segmented SD-WAN
The network plan, schematic: one setup carries fibre and 4G/5G sites alike, from HQ out to each heating station

Architecture principles

Connectivity

Flexible connections

One design uses fibre where it exists and adds 4G/5G as a primary or secondary carrier: new-build, existing, or temporary sites.

Availability

Redundancy & failover

A dual-uplink design with health checks and automated failover, for fast convergence.

Encryption

Modern encryption

WireGuard between sites: end-to-end encryption, modern cryptography, minimal overhead.

Segmentation

Layer-3 separation

Site and function segments are L3-separated; east-west traffic runs through central security policies, limiting lateral movement and blast radius.

Security

Centralised security

Central policies, central logging, and a central path to connect an IDS or SOC: syslog, NetFlow, anomaly detection.

Scale

Scalability & automation

Central management, a template per site type, and zero-touch provisioning for fast rollouts.

Automation with the site generator

Scaling a district-heating network needs efficient processes. The site generator automates configuration creation completely: the customer enters only a site name; everything else is generated automatically. The system produces the full router configuration, IP addressing, WireGuard keys, firewall rules and VLAN assignments.

A new outstation, transfer station or generation site can be configuration-ready within minutes, without manual effort, without a source of errors, and with guaranteed consistency across every site.

The site generator – a list of generated WAN sites with templates, tunnels and deployment status
The site generator: each WAN site generated from a template, with its tunnel, addressing and deployment state tracked centrally

Why the approach is cost-effective

"The consistent segmentation and central management make the network secure and manageable. Thanks to zero-touch provisioning and the template-based architecture, it scales with the expansion of the heat networks."
Paul Kempf · Managing Director, Zweckverband Breitbandversorgung Landkreis Lörrach

Frequently asked

How does out-of-band (OOB) remote site management work?
When a technician goes on site, they can attach a pre-configured device that immediately establishes a remote tunnel for troubleshooting and debugging, independent of the site's normal connectivity.
Which encryption is used?
WireGuard, with modern cryptography, for fast and secure tunnels between sites.
How is segmentation done?
Consistent Layer-3 separation by site and function role, micro-segmentation, central east-west policies, and DMZ zones for telemetry and remote access.
How does the design scale?
Through a template per site type, a config generator and central management: from 10 to more than 1,000 sites on the same design.
What does the B3S Fernwärme actually require?
The recognised industry-specific security standard describes organisational and technical minimum measures: network zoning, access controls, logging, vulnerability management, contingency plans, and regular security proofs.
← All work